National Cyber Defense Bill – Israel Aligns with Global Standards | Adv. Adiel Klein

The direction is clear: there is a national alignment with international regulations and an understanding that today, cyber defense and information security are an integral part of the business lifecycle.

MaarivAuthor: Adv. Adiel Klein
Source
National Cyber Defense Bill – Israel Aligns with Global Standards | Adv. Adiel Klein
Photo: Maariv / איום הסייבר | צילום: שאטרסטוק

On June 8, 2026, the National Cyber Defense Bill, 2026, was approved in the Knesset plenum in its first reading. Europe has already done this, long ago with the Directive on Security of Network and Information Systems (NIS, NIS2); the UK, Australia, and Canada are also already there. Israel, which is among the most attacked countries in the world in cyber, especially since the outbreak of the "Iron Swords" war, with a sharp increase in the scope and intensity of attacks against civilian entities, has remained until today without a comprehensive national legislative framework in the field. This is about to change — perhaps.

The goal of the future law is first and foremost to bring the issue of awareness of cyber defense to the public and private levels, to create a uniform line for functional continuity in an organization experiencing a cyber incident, and in particular to anchor the National Cyber Directorate (sections 2-4) as the body coordinating national defense against cyber incidents, alongside "sectoral units" (section 5) that will operate under each of the regulators listed in the first and second appendices — from the Ministry of Communications to local authorities.

The core of the law is the concept of the "essential organization" (section 8): any government body and any organization that meets the sectoral criteria in the third appendix — communications, energy, health, water and sewage, transport, chemicals, agriculture, local authorities, and more. The regulator in the sector also has the authority to add or remove an organization from the list individually, in a reasoned decision (section 8(b)).

In the private sector, the question regarding the applicability to "digital service providers and storage services" (item 9 of the third appendix) is surprising in its scope — from cloud providers and data centers, to IT and cyber security services, etc., a total of about 20 different types of services listed in the law. Such a provider will fall under the scope of the law if it provides one of these services and its annual turnover is 40 million NIS or more, or if it employs 50 employees or more, or if it provides a service to the government. Thus, not only technology giants might find themselves inside, but also many companies that do not necessarily see themselves as "critical infrastructure".

The bill includes the obligation of every organization to take appropriate cyber defense measures for its activity. In addition, essential organizations are required to take reasonable measures using international standards, for example — ISO 27001, NIST 800-53, etc. There is also an obligation for immediate reporting of a significant cyber attack (section 11), which also includes exemption paths.

There is a not insignificant price for violating the law: financial sanctions in the hundreds of thousands of shekels for violations determined therein, and in severe cases also criminal liability — and personal exposure for officers who did not supervise as required (sections 44-45).

The National Cyber Directorate stated:

"The National Cyber Defense Bill is intended to increase national resilience and maintain routine in the home front of essential services for the benefit of the citizen, in aspects of cyber defense. The proposal was formulated while balancing operational needs and the continued normal operation of organizations. The law preserves and anchors the decentralized-managed model, and in doing so, powers are granted to sectoral regulators who know the sector in depth, while the Directorate provides professional guidance for cyber defense at the national level. The bill focuses on essential organizations in core sectors as is customary in the European NIS2 directive, and the level of protection relies on recognized international standards that many organizations already meet, alongside the anchoring of dedicated balance and control mechanisms. Alongside all these, the National Cyber Directorate will continue to work to strengthen cyber defense in the Israeli space."

It is possible that the proposal will undergo more changes on the way to legislative approval and there will also be a preparation period for organizations. But the direction is clear — the world of cyber defense and the national understanding of maintaining it are moving up a level. This also joins Amendment 13 to the Privacy Protection Law, which raised awareness of obligations in the worlds of information security. My starting assumption is that there will also be an impact in indirect aspects, including operational, insurance, and possibly also an impact in the worlds of work. In the meantime, the direction is clear — there is a national alignment with international regulations and an understanding that today, cyber defense and information security are an integral part of the business lifecycle.

Adv. Adiel Klein is an expert in the fields of information protection and cyber and serves as an external DPO for organizations.

Related News