Navigating AI Threats and Amendment 13: Insights From Primesec CEO

Primesec CEO Adv. Or Lavi discusses how AI, Amendment 13 to the Privacy Protection Law, and cloud computing are transforming enterprise cybersecurity and privacy in Israel.

YnetAuthor: Economic
Source
Navigating AI Threats and Amendment 13: Insights From Primesec CEO
Photo: Ynet / צילום: יאיר ולר

The cybersecurity and privacy protection landscape has undergone a dramatic transformation in recent years. The combination of artificial intelligence-driven technological breakthroughs and unprecedented regulatory changes—foremost among them the entry into force of Amendment 13 to the Privacy Protection Law—creates a new and complex reality for executives across all sectors. Compounding this is the accelerated development of artificial intelligence, which poses formidable challenges, chief among them the dramatic shortening of attackers' timelines.

"Over the last quarter, we have seen artificial intelligence being weaponized as an attack vector. While we used to have breathing room between the publication of a security update and its installation within an organization, AI has compressed these timelines, allowing attackers to exploit vulnerabilities at record speeds," explains Adv. Or Lavi (50), CEO of Primesec, one of Israel's leading consulting firms in information security, cybersecurity, IT, and privacy protection.

How common are attacks against clients? The Primesec CEO explains that managers and employees with data access use AI tools for data processing, while developers write code utilizing AI that goes unchecked. Without policies or monitoring tools, sensitive corporate data is frequently leaked to search engines and cloud tools, presenting a significant current challenge. "As a result of our proactive operations, these attacks are largely prevented," he notes. "However, just recently we handled an incident where attackers exploited a vulnerability in WordPress, which powers a client's website, stealing public authentication keys. In this case, the impact was relatively minor, but in other instances, it could result in industrial espionage, data theft, or financial loss."

Managing AI as a Core Technological Service

How do you contend with this? "First of all, we stop treating AI as merely a tool employees happened to start using," says Lavi. "From management's perspective, it must be treated as a core technological service managed like any other critical system. Risk management requires mapping which AI tools the organization actually needs, defining policies, assisting in tool selection, and providing enforcement mechanisms. This includes blocking unauthorized tools, advising on proper licensing to ensure data remains within the organization, and managing tokens at the IT and budgetary levels. Sometimes organizations pay thousands of dollars for unvetted licenses simply due to uncontrolled permissions."

Founded by Lavi in 2010, Primesec currently employs approximately 60 people and provides services to over 400 clients in Israel and abroad. The company's core services focus on information and cybersecurity, alongside privacy protection, business continuity consulting, and AI advisory services.

"The company is divided into two main divisions," Lavi says. "One division serves our regular retainer clients, while the other provides project-based or complementary services to entities that already maintain an internal Chief Information Security Officer (CISO) or Privacy Officer, but require specialized professional support. This can include external audits, targeted professional consulting, third-party vendor assessments, and guiding organizations through preparedness processes, certification, and compliance with international standards, including relevant ISO standards in information security and privacy."

Over the past year, Lavi spearheaded a significant managerial shift, transitioning the firm from professional consulting alone to a structured client and project management model. "Through this transition, we drastically improved our response times, the variety and quality of our deliverables, and our overall customer service level. As a result, we grew the company by 20% over the past year in both headcount and client base."

Navigating Amendment 13 and Legal Integration

Another essential domain where Primesec provides support is assisting organizations in complying with Amendment 13 to the Privacy Protection Law. Approved by the Knesset in August 2024, this amendment represents the most comprehensive and significant reform in Israeli privacy law in decades. Its core objective is to update outdated Israeli legislation (dating back to 1981) to the digital age, modern cyber threats, and international standards, imposing financial sanctions on companies failing to comply.

This legal shift also introduces operational challenges, particularly during incidents requiring rapid response. "One element of Amendment 13 concerns fines imposed for failing to meet reporting obligations," Lavi explains. "For instance, there is a requirement for immediate reporting of a security breach in organizations holding data on over 100,000 customers. This demands rapid incident identification, drafting communications, and managing interactions with the Privacy Protection Authority, and sometimes other regulators such as the Capital Market Authority, the Bank of Israel, or the Israel National Cyber Directorate (INCD). Here, our legal background and accumulated experience offer a major advantage in managing incidents correctly. We handled at least 10 to 12 such cases over the past year."

Approximately a quarter of the company's employees are trained lawyers or legal professionals. Lavi himself, holding a bachelor's degree in law and computer science and a master's degree in law with a specialization in computer law, views this synthesis as vital. "Even before Amendment 13, this field involved numerous legal and regulatory elements, whether guidelines from the Bank of Israel, the Capital Market Authority, or the Israel Securities Authority. Legal comprehension is mandatory," he notes. "Contracts require embedding privacy and cybersecurity clauses, alongside website terms of use and privacy policies. This legal background is essential for understanding the issues and delivering expert service. There are not many lawyers who genuinely understand technology, and that is a unique advantage we bring to our clients."

This legal acumen is also reflected in complex litigation support and expert witness opinions for the courts. The immense demand for professional expertise at the intersection of law and technology led Primesec to launch a professional training course for Data Protection Officers (DPOs), open to the public and tailored for professionals seeking up-to-date expertise in an increasingly central organizational domain. One course was conducted last quarter, with another slated to open immediately after the holidays.

The Future of Digital Defense: Beyond Perimeter Security

Looking a decade ahead, Lavi predicts a profound conceptual shift in how organizations protect digital assets. "Threats will always evolve in tandem with technological progress," he clarifies. "The primary challenge for consultants and experts in our field will be identifying emerging technologies and preemptively building correct safeguards. Yet beyond technological solutions, the greatest challenge will be expanding employee and management awareness of genuine risks so they allocate appropriate resources. The solution does not lie solely in technological tools, but primarily in regulations, procedures, and controls imposed on employees and external vendors."

This is driven by how distributed modern organizations have become. "We are currently undergoing a highly accelerated transition toward services reliant on numerous external cloud providers, moving away from localized on-premise data centers," he says. "In such an environment, the most vital challenge in coming years will be mapping and identifying data flows within and outside the organization, traversing various cloud services and AI tools, and applying effective controls throughout data transit and storage. Defense will no longer focus on securing a specific, closed physical network, but on accompanying the data wherever it resides. This is the central challenge awaiting us."

"The goal is not merely helping organizations respond to the next threat, but helping them prepare before it even arrives," Lavi concludes. Focused squarely on this question, Primesec will host its annual client conference, NEXT-GEN 2026, in October. The event will bring together executives and experts to debate the challenges reshaping the worlds of cyber and privacy—from AI and emerging technologies to shifting regulations and organizational preparedness.

Related News