It is one closed loop — see, understand, prevent, respond, learn — running at machine speed over a single graph of everything an organisation owns, with humans owning the judgement. Israel has built nearly every part. Nobody has assembled the machine.
ENSI research — built on a library of 115 primary documents and 52 company dossiers.
The argument, before the list
In 2024 a team at the University of Illinois gave a tool-using GPT-4 agent the public advisories for fifteen real, recently disclosed vulnerabilities. It exploited 87% of them, at an average cost of about $3.52 a run, against an estimated $25 of an expert’s time. Without the advisory text its success rate fell to 7% (Fang et al 2024). The danger sits in the gap between the moment a weakness is published and the moment it is fixed. Every advisory is now, in effect, a set of instructions a machine can follow. Zafran, an Israeli exposure-management company, counts about 130 new CVEs a day and says roughly one in three is weaponised on the day it is disclosed. Dream Security has analysed a four-day, fully autonomous AI-agent intrusion into Asian government agencies that ran up to eight sub-agents at once. Anthropic’s Mythos model has shown autonomous zero-day discovery and exploit chaining. Offence has started to automate. Defence organised as a procurement list cannot keep up with it.
The usual response is to buy the best tool in each category, then another console for whatever came out last quarter. That produces coverage without comprehension. Look at the fifty companies in this series by the job each one does in a working defence, rather than by the category it sells in, and they form something else: a parts list for a single machine. Three independent bodies of work describe that machine in almost the same terms: NATO’s reference architecture for autonomous cyber-defence agents, co-written with Masaryk University in Brno (Kott et al 2019), the BAE Systems survey of deep reinforcement learning for Dstl (Palmer et al 2024), and the finalists of DARPA’s AI Cyber Challenge (Zhang et al 2026). All three arrive at the same design: sensors feed a graph-based world model of the estate, planning agents choose actions, actuators isolate, patch and re-route, the system learns from outcomes, and a human supervisor owns judgement and accountability.
Israel’s fifty companies map onto that loop almost one to one. Armis, Axonius and Claroty see devices; Cyera and Varonis see data; CyberArk, Silverfort and Astrix see identities; Apiiro, Cycode and Legit see code. Wiz and XM Cyber turn it all into attack paths; Oligo, Upwind and Sweet show which risks are live; Pentera and Cymulate test the defences; Zafran mitigates. Check Point, Cato, Zero Networks, Island and Waterfall prevent by design. SentinelOne, Torq and 7AI respond; BioCatch and Forter read behaviour; KELA and Sygnia track the adversary; Zenity, Noma, Koi, Irregular and Alice secure AI. Behind them sit the labs at Ben-Gurion, Tel Aviv, Weizmann and the Technion, repeatedly first to name new classes of threat.
Nobody has assembled the machine. The best of these companies each built a graph over one slice of the estate: Wiz’s security graph of cloud resources, Armis’s device knowledge base, Astrix’s identity graph, Apiiro’s Software Graph, Cycode’s Context Intelligence Graph, XM Cyber’s digital twin, and the context graph Torq bought with Jit. Since late 2023 the platforms have tried to join the slices by acquisition: Google bought Wiz, Palo Alto Networks bought CyberArk and Koi, ServiceNow bought Armis, Cisco bought Astrix, and CrowdStrike agreed to buy XM Cyber’s patents and source code. Buying the companies gives a platform a bundle of products. It does not give it the loop. Shlomo Kramer, co-founder of Check Point, Imperva and Cato, put it plainly: “True convergence is not achieved by integrating products under a SASE umbrella.”
Four design laws run through the dossiers and the research, and they organise everything that follows:
Context beats coverage. XM Cyber’s analysis of more than 40 million exposures found fewer than 1% came from CVEs and only 2% sat on the “choke points” where attack paths converge. Zafran says 99% of “critical” vulnerabilities are not exploitable once you account for the controls already in place.
Architecture beats speed where it can. Zero Networks’ Benny Lakunishok: “You can’t outrun AI, but you need to out-architect it.” A one-way optical gateway or default-deny segmentation takes the race away rather than trying to win it.
Autonomy is only as good as its governance. An agent that isolates the wrong production server causes an outage. Machine-learning detectors can be evaded in ways that adversarial training “should have no effect” on (Shamir et al 2019). Humans have to own the rules of engagement.
The loop has to learn. It needs gyms in which to train defensive agents, research pipelines that name the next class of threat before it arrives, and national sharing so that one victim’s lesson protects the next organisation.
For us, a mid-sized European state (the Czech Republic is our default example), this is an opportunity rather than a shopping list. No state needs fifty companies. It needs to own the loop: the graph, the policies, the training gym, the sharing fabric and the human judgement. It can buy the parts on conditions, which matter because most of the best parts now belong to American platforms, and NÚKIB’s 2026 strategy already names the “shortage of secure and competitive domestic technological alternatives, which deepens dependence on the technologies of foreign rivals” (NÚKIB 2026). There is also a warning at the top of the Israeli system. Before 7 October 2023 an 8200 analyst warned that a Hamas exercise closely followed the eventual attack plan, and her superiors dismissed the analysis as “aspirational” (Wyss, CTC Sentinel 2024). The most advanced loop in the world still fails if the humans at the top of it do not listen.
Summary of main points
The most advanced system is a control loop, not a product. See → understand → prevent → respond → learn, over one graph of assets, identities, data, code and AI agents. NATO’s AICA architecture, the BAE/Dstl survey and DARPA’s AIxCC finalists converge on this design.
Israel’s fifty companies are the parts list. Each of the twenty-four features has an Israeli company or lab among its global leaders; no organisation has assembled all twenty-four.
Offence automated first, and cheaply. An LLM agent exploited 87% of one-day vulnerabilities from advisory text at about $3.52 a run. The decisive metric is now hours from disclosure to mitigation.
Context is the multiplier. Wiz’s “toxic combinations”, XM Cyber’s choke points, Oligo’s function-level reachability and Zafran’s exploitability-in-context each shrink the problem by one or two orders of magnitude.
Prevention by architecture is back. Automated segmentation, enterprise browsers, AI-maintained allow-listing and one-way gateways remove whole attack classes.
The AI era adds a layer. Agents are a new identity, a new supply chain and a new worm surface. Israeli research (Morris II) and companies (Zenity, Noma, Koi, Irregular, Alice) lead it, and platforms bought six AI-security start-ups in about eighteen months.
The national layer is what a state adds. Sector SOCs and sharing (Israel’s “Cyber Dome”), coordinated disclosure, a gym for defensive agents, and protection specified against a named adversary (RAND’s SL1–SL5, co-written by Israel’s Pattern Labs).
Governed autonomy is a feature in its own right. Before October 7, Israeli intelligence let automation replace pushed warnings. Rules of engagement, hand-off and a heard dissenter are part of the machine.
For a Czech-scale state: build the loop, buy the parts, on sovereignty conditions. Most of the best parts now answer to American platforms; the twelve-month roadmap at the end sequences the work.
How the system is organised
The twenty-four features sit in six layers of four, in the order of the loop:
Layer 1 · See everything — 1 live asset intelligence · 2 the data map · 3 the identity fabric · 4 code-to-runtime lineage
Layer 2 · Understand risk — 5 the attack-path twin · 6 runtime truth · 7 continuous adversarial validation · 8 disclosure-to-mitigation within hours
Layer 3 · Prevent by design — 9 the prevention-first converged edge · 10 lateral movement designed out · 11 the governed last mile · 12 crown jewels protected to a named adversary
Layer 4 · Detect and respond at machine speed — 13 autonomous hybrid detection · 14 the agentic SOC · 15 behavioural trust · 16 adversary intelligence and elite response
Layer 5 · Secure the AI era — 17 the agent registry · 18 agent runtime guardrails · 19 the AI supply-chain gate · 20 frontier-model evaluation
Layer 6 · Learn and govern — 21 national collective defence · 22 the research-to-product pipeline · 23 the cyber gym · 24 governed autonomy
Each feature is a capability, not a product, with the same six-part brief: what it is · who proves it (Israeli companies and research, named) · the mechanism · the frontier (today versus 2028) · the agentic engine (which agents run it, what the human owns) · build or buy (for a mid-sized EU state or large enterprise). Company figures come from the dossiers and are often company-reported.
Layer 1 — See everything
Every serious failure in the dossiers begins with something nobody knew existed: an unmanaged device, a forgotten bucket, a service account from 2014, a coding agent a developer installed on a Friday. The first layer is the graph that the other twenty features read from.
1. Live asset intelligence across IT, OT, IoT and medical
What it is. A live inventory of everything that connects (laptops, cloud workloads, SaaS, printers, PLCs, infusion pumps and now AI tools), each with its owner, its controls and its normal behaviour.
Who proves it. Armis built an agentless inventory that tracks about 7 billion devices and sold to ServiceNow for $7.75B. Axonius correlates 1,400+ data sources across 45+ asset classes, flags gaps such as a laptop without EDR or a leaver’s live account, and serves 90+ US federal agencies. Claroty listens passively in industrial and medical protocols, with Siemens, Rockwell and Schneider as investors. Ben-Gurion’s N-BaIoT gave each IoT device its own learned model of normal and caught every test attack at a 0.007 false-positive rate (Meidan et al 2018).
The mechanism. Read network traffic and the tools already deployed rather than installing anything new, then compare each device with a knowledge base drawn from every customer, a data network effect.
The frontier. Today: inventory plus exposure ranking. By 2028: AI tools and agents as first-class assets (Axonius already ships a Claude adapter), and each device’s “predictability” used as a gate on whether it may connect at all (Meidan et al 2018). Unmanaged sensors are already a battlefield: Palestinian Islamic Jihad hacked road cameras for rocket targeting (Freilich, INSS 2024), and in June 2025 Iranian actors used weakly secured Israeli security cameras to adjust missile fire (Sharma, MP-IDSA 2025).
The agentic engine. Discovery agents reconcile sources, chase owners and ticket the gaps. Humans decide which assets are crown jewels and sign off on devices that can never be managed.
Build or buy. Buy: the capability is mature and platforms are absorbing it. Insist on neutrality and full data export, since Armis now belongs to one ITSM vendor. Build the sector-wide inventory of critical OT that no single operator holds.
2. The data map
What it is. Knowing what sensitive data exists, where it lives, which people and machines (now including AI agents) can reach it, and who is actually touching it.
Who proves it. Cyera classifies data by meaning (a contract, source code, a health record) rather than by pattern-matching, produces a usable map in days, and has moved from posture into DLP and, with the ~$1B Oasis purchase completed on 3 September 2026, into identity. It is valued at $12B. Varonis has twenty years of permissions metadata, maps permissions against actual use and removes excess access automatically. Its Agent Intent-Based Access Control (August 2026) governs what AI agents may touch.
The mechanism. Classify by meaning, join the result to the identity graph, and fix automatically. The Varonis dossier puts it bluntly: remediation “is what CISOs pay for.”
The frontier. Today: posture reports and DLP. By 2028: data and identity run as one “trust layer” deciding, request by request, what each agent may read. An AI assistant can surface anything its user is technically allowed to see, so every over-permission becomes a potential AI data leak. As Varonis’s management puts it, “AI and data security cannot be treated as separate problems.”
The agentic engine. Classification agents label; remediation agents revoke stale access and quarantine exposed stores. Human data owners approve changes to business-critical sets, and the data-protection officer owns the legal basis.
Build or buy. Buy the classifier. Build the national classification taxonomy and the handling rules that GDPR and public-sector law require. Price the risk: Cyera’s valuation is reported at about 80 times ARR, Varonis is in reported talks with Proofpoint, and Microsoft bundles Purview.
3. The identity fabric: humans, machines and agents
What it is. Every identity (employee, service account, API key, OAuth grant, certificate, AI agent) is known, owned, least-privileged and granted access just in time, with policy enforced at authentication.
Who proves it. CyberArk created privileged access management and extended least privilege from humans to machines (Venafi) to agents, and now forms Palo Alto’s ~$25B “Idira”. Silverfort sits inside the authentication stream of Active Directory, Entra and Okta, putting MFA in front of command-line admin tools, legacy applications, OT and service accounts. It claims more than 10 billion authentications analysed a day. Astrix named the “non-human identity” category and was bought by Cisco for about $400M. Transmit handles customer identity, fraud and passkeys on one platform.
The mechanism. Silverfort’s founding insight is that attackers mostly don’t break in, they log in, so enforce where every lateral move has to pass. Machine identities already outnumber human ones by an order of magnitude. The 2023 compromise of a Microsoft cloud key reached 22 organisations, including US government agencies.
The frontier. Today: discovery of non-human identities plus a vault. By 2028: runtime authorisation of each agent action. Silverfort bought Fabrix for exactly this, and CrowdStrike paid $627.9M for SGNL. Cisco says only about 24% of organisations can properly guardrail and monitor their agents.
The agentic engine. Agents rotate and revoke stale tokens and propose least-privilege roles. Humans approve privileged access to crown-jewel systems and keep the break-glass keys.
Build or buy. Buy, knowing this is security’s most fought-over category and Israel no longer has an independent anchor in it. Build the policy: how agents acting for citizens and officials are identified, delegated and held to account is a rule only the state can write.
4. Code-to-runtime software lineage
What it is. A living map of repositories, pipelines, dependencies, secrets, APIs and deployments, linked to what runs in production and to whoever owns each fix, now including AI-written code and the agents that write it.
Who proves it. Apiiro‘s Deep Code Analysis flags only “material” changes, such as a new API exposing personal data. Its Guardian Agent rewrites the prompts sent to coding agents so the output fits policy. Its own analysis finds AI coding agents quadruple code volume and expand the attack surface six-fold. Cycode owns its scanners plus a context graph; Legit maps the “software factory”. Checkmarx, in 60% of the Fortune 100, finds only 24–36% of frontier-model code is both secure and functional.
The mechanism. Move from findings to context, then route each task to the cheapest engine that can do it properly. Cycode’s Lior Levy: “the answer isn’t a better model, but a system that decides which one runs where.”
The frontier. Today: aggregated findings ranked by context (ASPM). By 2028: autonomous find, prove and patch. The AIxCC finalists paired proofs of vulnerability with patches at 92% accuracy (Zhang et al 2026), Checkmarx has joined Anthropic’s Project Glasswing, and Legit’s Roni Fuchs predicts vendors will compete on fixing vulnerabilities rather than finding them.
The agentic engine. Threat-modelling, guardian, triage and patch agents work in sequence, and the patch agent proposes a fix only after proving the flaw. Humans own architecture and the merge into crown-jewel systems.
Build or buy. Buy the scanners, which are commoditising. Build a national find-prove-patch capability for the open-source code critical infrastructure depends on. Czech code is already in that supply chain: CZ.NIC’s Knot resolver was patched after Tel Aviv University’s NXNSAttack disclosure (Afek, Bremler-Barr & Shafir 2020).
Layer 2 — Understand risk
Seeing everything produces millions of findings, and a list of millions of findings is not a defence. The second layer turns the graph into a handful of decisions and then acts on them within hours. This is where Israeli companies have done most to redefine the market, because the answer here is a change of method, not better scanning.
5. The attack-path digital twin
What it is. A model of the estate that works out how an attacker could chain small weaknesses (a misconfiguration, a cached credential, an over-permissive role) into a route to a crown jewel, and ranks fixes by how many routes each cuts.
Who proves it. Wiz builds an agentless graph of every workload, identity, network path, secret and data store: a vulnerable container matters only if it is internet-exposed, holds a privileged identity and can reach sensitive data. These “toxic combinations” made its name in Log4Shell, and Google paid $32B. XM Cyber, founded by a former Mossad director and two intelligence-technology chiefs, simulates attacker chains across Active Directory, cloud IAM, Kubernetes and OT without live exploitation. Its study of 40 million+ exposures found 80% came from misconfigurations and credentials, under 1% from CVEs, and only 2% sat on choke points.
The mechanism. A graph data model makes path analysis cheap, whereas competitors built on relational tables produced “long, flat lists”. Defenders see alerts. Attackers see a graph of routes to a target.
The frontier. Today: separate twins for cloud and on-premises. By 2028: one twin across cloud, identity, on-premises, OT and agents: the “world model” of NATO’s AICA architecture, in which planning agents simulate a response before executing it (Kott et al 2019; Palmer et al 2024).
The agentic engine. Path agents re-run on every change; remediation planners group fixes into projects. Humans name the crown jewels and accept residual risk.
Build or buy. Buy the engine, but weigh who owns it: Wiz belongs to Google, and XM Cyber’s European owner has sold its IP to CrowdStrike and licensed it back. Build the national twin of cross-sector dependencies, which no vendor models.
6. Runtime truth
What it is. Evidence from inside running workloads about what actually executes, what talks to the internet and what touches data, so that risk is ranked by what is really happening rather than by which packages happen to be installed.
Who proves it. Oligo‘s eBPF sensor sees which vulnerable function in which library is actually called, claims 90–99% noise reduction, and since April 2026 blocks the offending system call while the application keeps running; its researchers found ShadowRay in AI infrastructure. Upwind built “inside-out” cloud security (valued at about $3.8B, ARR undisclosed). Sweet Security was founded by the IDF’s former CISO after a fruitless six-month search for a real-time cloud detection tool for the army’s move to public cloud. Aqua has done container runtime security since 2015.
The mechanism. Kernel-level telemetry plus a behavioural profile of each library. A library that suddenly spawns a shell is flagged even inside a legitimate process.
The frontier. Today: prioritisation and cloud detection. By 2028: blocking by default, with runtime as the control point for AI agents too (Sweet’s Agentic AI Blocking, July 2026). The test is trust: in the Oligo dossier’s words, “how widely customers let the sensor run, and in blocking mode.”
The agentic engine. Triage agents stitch process, identity, API call and bucket into one attack story. Humans decide, service by service, when monitoring becomes blocking.
Build or buy. Buy. Budget for “sensor fatigue” and outage risk, and require that runtime evidence flows into the shared graph, as Oligo now does into Wiz’s.
7. Continuous adversarial validation
What it is. Attacking yourself safely and continuously to prove which defences actually work. It replaces the annual penetration test, which covers a slice of the estate once a year.
Who proves it. Pentera‘s founder ran a red team in the IDF’s IT branch and judged penetration testing “routine, repetitive and well-defined”. The product runs real exploits safely in production, cuts about 10,000 alerts to 6–8 root causes, sells with a one-day proof of value that ends at domain admin, and passed $100M ARR in 2025. Cymulate simulates attacks across email, web, endpoint, network and cloud for 1,000+ customers, then writes the missing detection rule for the customer’s own SIEM.
The mechanism. Chain weaknesses as an attacker would, report root causes a board can read, and close the loop with a fix, not a finding.
The frontier. Today: scripted campaigns. By 2028: LLM red-team agents. PentestGPT found models strong on sub-tasks but weak over long engagements, and the fix was architectural: separate planning, generation and parsing modules plus an explicit task tree (Deng et al 2024). The dispute is over safety: the AI-native US rival Horizon3.ai now outgrows Pentera, whose CEO argues production networks still need deterministic guardrails.
The agentic engine. Red-team agents plan chains under a task tree, and purple-team agents write the detection that failed. Humans set the rules of engagement and the blast radius.
Build or buy. Buy the platform. Build a national red team, with NÚKIB and the Czech Cyber and Information Warfare Command as natural hosts, that runs it across critical operators to a common standard.
8. Disclosure-to-mitigation within hours
What it is. A closed loop from “an advisory is published” to “exploitation is blocked here”, which runs before the patch lands.
Who proves it. Zafran asks of every finding whether the vulnerable code runs, is reachable, would be blocked by an existing control, and is being exploited, then retunes the EDR, firewall and WAF the customer already owns to cover the “exploitation window”; its Attack Chain Killswitch is built with Google Threat Intelligence. Cato says its automated CVE mitigation protects within 45 minutes. Oligo blocks exploit techniques rather than single CVEs, virtual patching for zero-days and known flaws alike. Radware added “AI Xploit Shield” for safe patching in June 2026.
The mechanism. Mitigate first and patch second, and make controls the customer has already paid for stand in for the patch.
The frontier. Today: days to weeks, a human approving each change. By 2028: hours, because disclosure now amounts to weaponisation (Fang et al 2024), and the AIxCC finalists already find, prove and patch in one loop (Zhang et al 2026). Treat every published advisory as instantly weaponisable.
The agentic engine. Intake, exposure, mitigation and change agents run in sequence. Humans own change windows on crown jewels: an automated change that causes an outage gets blamed on the tool, and cautious customers “keep a human approving every change.”
Build or buy. Buy the engine. Build the national piece: the CERT should publish machine-readable mitigations alongside every advisory so that operators’ agents can act on them within the hour.
Layer 3 — Prevent by design
Detection is a race. Prevention by design removes the race altogether. Israel has the longest record here of any country: the first commercial firewall came out of an 8200 veteran’s work on classified networks in 1993. The four features in this layer share one idea. They remove a whole class of attack rather than getting better at catching it.
9. The prevention-first converged edge
What it is. One enforcement fabric for every user, site and cloud: firewall, web gateway, zero-trust access, DLP, DDoS and API protection, applied in a single pass under one policy and one data lake. By default it blocks rather than alerts.
Who proves it. Check Point invented stateful inspection (FireWall-1, 1993), still competes on blocking rather than detecting, and shares its ThreatCloud feed across 100,000+ customers; its July 2026 AI Network Firewall inspects traffic to and from models and agents. Cato built networking and security as one stack on its own backbone of 70+ points of presence, with $415M+ ARR growing about 42%, three years as a Gartner SASE Leader, and a Prague R&D centre it is tripling. Radware mitigates carrier-grade DDoS on-premises and in the cloud, and reports web DDoS up more than 110% in the first half of 2026.
The mechanism. Convergence: one policy model, one data lake, one upgrade path. Owning the network path also lets the edge replace the WAN budget, so it sells as a saving.
The frontier. Today: SASE and hybrid-mesh firewalls. By 2028: the edge also inspects agent traffic (Check Point with Lakera, Cato with Aim Security) and pushes virtual patches across the whole fleet within the hour (feature 8).
The agentic engine. Policy agents propose rule changes from the graph, and mitigation agents deploy them. Humans own policy intent and exceptions.
Build or buy. Buy. This is the most mature Israeli layer, and one of the few with independent Israeli vendors left. Check vendor health, though: Check Point’s revenue grew just 1% in Q2 2026. Cato’s Prague centre is a local anchor worth cultivating.
10. Lateral movement designed out
What it is. Every machine may talk only to what it needs, and administrative protocols stay closed until a person proves identity just in time. A stolen credential or a compromised laptop then cannot spread.
Who proves it. Zero Networks observes traffic, writes least-privilege rules itself and enforces them without agents, at the network switch for OT devices that cannot run software. It puts MFA at the network layer so that RDP and SSH open only on proof of identity, and since August 2026 applies “least agency” to AI agents. Its 2026 benchmark found 80% of enterprise servers reachable from anywhere on the internal network. Customers report segmentation “in weeks, not years”, with net dollar retention above 120%. Silverfort‘s authentication firewall and CyberArk‘s just-in-time sessions close the identity side.
The mechanism. Default-deny, generated from observed behaviour. Microsegmentation always worked; what killed it was deployment, which meant multi-year, consultant-heavy rollouts and rules nobody maintained. Automation removes that cost.
The frontier. Today: on-premises Windows estates and OT. By 2028: segmentation of AI agents at process level, plus quarantine triggered automatically by detection. Ben-Gurion’s IoT work showed that sub-second detection could stop a launched attack “in less than a second” (Meidan et al 2018).
The agentic engine. Learning agents propose rules from observed flows, and enforcement agents quarantine on signal. Humans approve crown-jewel flows and hold the break-glass keys.
Build or buy. Buy. The vendor is small: a third-party estimate puts its 2025 ARR near $18M, unconfirmed by the company. Plan for it being acquired. For a regulator, segmentation of crown jewels is a control NIS2 supervision can ask to see evidence of.
11. The governed last mile: browser and endpoint
What it is. Control where a person or an agent actually acts on data, in the browser tab and on the laptop: what may be copied, pasted, uploaded, installed or run.
Who proves it. Island created the enterprise browser. Built on Chromium, it governs copy and paste, downloads, printing and screenshots, masks sensitive fields and runs contractor sessions without VDI or VPN, for eight of the world’s ten largest banks and about $200M of founder-stated revenue. Glow revives application allow-listing, which failed for a decade because humans could not keep the lists current: its agents map, score and allow, remove or block every application and AI tool on each endpoint. It claims AI-tool use on corporate devices rose from 15% to 45% in a year.
The mechanism. The browser sees data after decryption, at the moment the user acts. Allow-listing always worked in principle, and agents remove the cost of upkeep that made it impractical.
The frontier. Today: the enterprise browser plus last-mile DLP. By 2028: what Island calls “the control plane for your agentic enterprise”, a single place where both human and agent actions are governed, and default-deny software on every managed device.
The agentic engine. Research agents score every new app and extension, and policy agents decide. Humans own the exception process. The old failure mode still applies: block a developer’s tool once too often and the product gets switched to monitor-only.
Build or buy. Buy. It is a natural fit for public administrations that want to retire VDI for contractors. Check where the reasoning runs, though: Glow’s enforcement decisions use Anthropic and Gemini models accessed through Amazon Bedrock, which raises data-handling questions for regulated buyers.
12. Crown jewels protected to a named adversary
What it is. For the few assets whose compromise would be a national event (grid control, nuclear, water, classified enclaves, AI model weights), security specified against which attacker must be stopped; where the answer is “a state”, the control is physical.
Who proves it. Waterfall‘s optical unidirectional gateways let data physically flow only out of the plant, across more than 1,000 installations. By the company’s reading, gateway-protected sites are exempt from more than 35% of NERC CIP requirements, and France’s ANSSI requires hardware-enforced one-way flow for its most critical systems. RAND and Pattern Labs (now Irregular) defined security levels SL1–SL5 against about 38 attack vectors; SL5 targets the most capable nation-states and, the authors judge, is beyond most organisations today (Nevo et al 2024).
The mechanism. The stakes are physical. In April 2020 IRGC-linked attackers took control of six Israeli water and sewage stations and could have raised chlorine to potentially lethal levels; the INCD’s head called it “a turning point in the history of modern cyber warfare” (Freilich, INSS 2024). So the first design question is “which actor must this asset withstand?”, and where consequences are physical, deterministic controls (”there is no inbound path”) win. Isolation alone fails: more than 17 malicious frameworks have targeted air-gapped networks (Guri 2024), and acoustic leakage defeats Faraday cages (Genkin, Shamir & Tromer 2013).
The frontier. Today: diodes for OT monitoring. By 2028: hardware-enforced remote access (Waterfall’s HERA), signed firmware (Ronen et al 2017) and mutual authentication between engineering stations and PLCs. Technion and TAU researchers showed a rogue station could run injected logic while the PLC displayed the original code, because the engineering station was not authenticated to the PLC and every PLC of a model shared one key pair (Biham et al 2019).
The agentic engine. Deliberately little autonomy inside the enclave: agents watch the one-way feed; humans own every inbound change.
Build or buy. Buy the hardware; European diode makers compete on local certification. Build the national register of crown jewels, with each asset assigned an adversary tier and audited against it.
Layer 4 — Detect and respond at machine speed
Prevention fails some of the time, and when it does the loop has to notice, decide and act faster than an adversary whose tempo is now set by software. The fourth layer is where autonomy earns its keep, and also where it can do the most damage.
13. Autonomous hybrid detection on every endpoint and segment
What it is. Detection that runs where the attack happens, on the device or the network segment, before or as code executes. It combines a learned model of normal behaviour with behavioural models and signatures, and it can contain and roll back without waiting for the cloud or a human.
Who proves it. SentinelOne detects and rolls back ransomware on the device with no cloud round-trip, running one agent on its own data lake at $1.218B ARR. Cynet bundles one agent with 24/7 MDR for firms without a SOC and claims 90% of threats are remediated without human action. In research, Ben-Gurion’s Kitsune learns “normal” traffic without labels on a Raspberry Pi (Mirsky et al 2018), and Bar-Ilan’s DeepSign reached 98.6% accuracy on unseen malware variants in 2015 (David & Netanyahu 2015).
The mechanism. Use both paradigms. Kitsune’s authors recommend running learned detection alongside a signature engine, because signatures cannot see what is new and learned models cannot be trusted on their own.
The frontier. Today: EDR and XDR. By 2028: a learned detector on every segment, wired to automatic isolation. The limit is structural: adversarial examples follow from the geometry, and adversarial training “should have no effect” on them (Shamir et al 2019). ML detection is never the only layer. Deep Instinct’s deep-learning lead lasted about five years.
The agentic engine. On-device agents act within bounded rules. NATO’s reference architecture confines destructive actions to the host the agent sits on (Kott et al 2019). Humans set the rollback and quarantine policy.
Build or buy. Buy: endpoint security is a winner-takes-most market. For small firms, fund NIS2 programmes delivered through managed service providers, the channel Cynet, Coro and Guardz were built for.
14. The agentic SOC, humans on the loop
What it is. AI agents do the tier-1 work (enrichment, triage, investigation, correlation and first response) across the tools the organisation already runs, and hand analysts a case that is already assembled. Humans supervise from “on the loop” rather than approving every step.
Who proves it. Torq claims more than 95% of tier-1 tasks automated and 100 million automations a day, and says it replaces the SOAR or case-management layer in about 70% of deployments; the Jit context graph it bought lets agents judge alerts by business impact. Check Point’s CISO says it handles many internal alerts with no human involvement. 7AI, from Cybereason’s founders, reports 9 million+ investigations and a million+ analyst hours returned; its customer DXC cut tier-1 analyst time by 80%.
The mechanism. The plumbing comes before the intelligence. Torq had an execution engine and integrations when LLMs arrived. The research agrees: orchestrated specialist agents with explicit external state beat one general agent (Deng et al 2024; Zhang et al 2026).
The frontier. Today: autonomous triage. By 2028: federated data with no central SIEM (7AI’s “Federated SIEM”) and multi-agent response built on AICA’s five functions of sensing, planning, acting, collaborating and learning (Kott et al 2019). Hunters is the warning: right about the data-lake SIEM, it lost to the vendors that own endpoint telemetry.
The agentic engine. Triage, investigation, containment and reporting agents do the work. A human incident commander approves destructive actions, and detection engineers curate the agents’ skills.
Build or buy. Buy the agents but own the data layer, normalised to an open schema such as OCSF, so the agents can be swapped. 7AI reads telemetry from the same vendors that are building rival agents.
15. Behavioural trust at the human layer
What it is. Judging whether the person (or agent) behind a session is who they appear to be, and whether they are acting of their own will, from how they behave rather than what they know.
Who proves it. BioCatch reads typing cadence, swipes, phone angle and hesitation (3,000+ signals, a verdict in under 500ms) across 19 billion sessions a month at 350+ banks, catching scams where password, device and customer are all genuine. Its Australian BioCatch Trust network scores receiving accounts across banks without sharing personal data, and Visa is paying $2.4B for the company. Forter runs a cross-merchant identity graph, answers in about a second, pays the chargeback when wrong and treats AI shopping agents as a new identity class. Transmit joins identity, fraud and verification in one flow.
The mechanism. Own a signal nobody else collects, pool it across institutions, and sell to the budget that feels the loss. Impersonation, including real-time deepfakes, is the offensive-AI threat that industry and academia jointly rank highest (Mirsky et al 2021).
The frontier. Today: bank and e-commerce fraud. By 2028: sessions run by agents, where the keystroke signal vanishes. Transmit warns that agents are “blinding” fraud detection; the new problem is telling a legitimate delegated agent from a malicious one.
The agentic engine. Scoring models run in-line and investigator agents map mule networks. Humans own customer-harm decisions and redress.
Build or buy. Buy the engines. Build the national layer: an inter-bank behavioural-sharing consortium convened by the central bank and police, on the BioCatch Trust model, whoever the vendor is.
16. Adversary intelligence and elite response on call
What it is. Knowing who is selling access to your network, which of your credentials have leaked and which exploits are being traded for your software, and having operators who have fought state-grade intrusions ready to take over when the loop fails.
Who proves it. KELA has watched closed forums, markets, Telegram and infostealer logs for more than fifteen years, with analysts inside; by its own count it has indexed 34.1 billion compromised credentials in 2026 alone. Its research on TeamPCP, the group behind the Trivy and Checkmarx compromises, went to Australian police and the FBI, and two men were charged in August 2026. Sygnia, from the Team8 foundry, led the investigation of the $1.5B Bybit theft attributed to Lazarus and exposed “Velvet Ant”, a China-nexus group that hid in a Linux login system for almost a decade.
The mechanism. Intelligence matched to the customer’s own exposure rather than raw feeds, and crisis trust converted into retainers, readiness work and MDR.
The frontier. Today: alerts and retainers. By 2028: intelligence flows straight into the graph, so a leaked credential is revoked and a traded exploit triggers mitigation (feature 8). War sets the bar: in June 2025 SecurityScorecard analysed 250,000 Telegram messages from 178 groups, and wartime defence needs real-time chatter monitoring. Deception belongs here too: in 2015–16 Iranian hackers who “believed that they had succeeded” against Israel’s grid had hit honeypots (Freilich, INSS 2024).
The agentic engine. Collection and triage agents (KELA’s “Digital Cyber Analysts”) do the volume work. Humans own attribution, liaison with law enforcement and crisis command.
Build or buy. Buy the commercial intelligence. Build a national incident-response reserve. Note Singapore’s route: Temasek bought Sygnia outright, and the dossier’s verdict is that the buyer’s route is faster.
Layer 5 — Secure the AI era
AI agents are at once a new class of identity, a new software supply chain and a new worm surface. This is the layer where Israeli research has most clearly named the threat first, and where the platforms moved fastest to buy the answer: in about eighteen months Palo Alto bought Protect AI, SentinelOne bought Prompt Security, Check Point bought Lakera, Cato bought Aim, CrowdStrike bought Pangea and F5 bought CalypsoAI.
17. The agent registry and governance
What it is. A registry of every AI agent the organisation runs, whether homegrown, embedded in SaaS or running on a developer’s laptop. Each entry records the agent’s owner, tools, data, identities, MCP connections and approval status, and policy is applied before the agent is deployed.
Who proves it. Zenity began by governing low-code tools, finding large enterprises averaging nearly 80,000 low-code apps and agents, over 60% of them vulnerable. It now covers Copilot, ChatGPT Enterprise, Gemini, Claude, Cursor and Bedrock, and Gartner has called it “the company to beat” in agent governance. Noma typically finds 10 to 100 times more agents than teams expect, and marks every agent and MCP server Approved, Requires Review or Blocked, with tool-level permissions. Astrix (now Cisco’s), Varonis and Cyera come at the problem from identity and data.
The mechanism. Treat every agent as both a software asset and a non-human identity, and run it through inventory, then posture, then policy.
The frontier. Today: discovery. By 2028: the agent registry is as basic as the asset inventory. The open question is who owns it. Identity vendors argue agents are non-human identities, while AI-security vendors argue they need runtime control. Cisco says only about 24% of organisations can currently put proper guardrails and live monitoring on agents.
The agentic engine. Discovery and posture agents keep the register current. A named human business owner approves each agent’s scope and answers for it.
Build or buy. Buy the tooling. Build the rule: every agent acting for a public body sits in a register with a named, accountable human owner.
18. Agent runtime control and agent-to-agent guardrails
What it is. Controls that follow what an agent actually does, step by step: its tool calls, memory access, control flow and messages to other agents. They allow, modify or block actions before they execute, and stop a malicious instruction spreading from one agent to the next.
Who proves it. The Technion’s Morris II showed prompt-injection “worms” spreading between AI email assistants and exfiltrating data hop by hop, and shipped the defence with the attack: a guardrail with a true-positive rate of 1.0 and a false-positive rate of 0.015 (Cohen, Bitton & Nassi 2024). Zenity inspects each agent step and blocks inline; Sweet ends unauthorised tool calls; Check Point (with Lakera) and Alice guard models at runtime; Salt watches the APIs and MCP servers agents act through. Irregular has documented agents cooperating to steal data and switching off security tools in red-team runs.
The mechanism. Deterministic action control wrapped around non-deterministic models. The Israeli research habit is to publish the attack and the countermeasure together.
The frontier. Today: prompt filtering and tool-call blocking. By 2028: agent-to-agent traffic treated like network traffic, segmented, inspected and rate-limited. The hard part is unsolved, as the Zenity dossier admits: deterministic control over non-deterministic agents without blocking legitimate work.
The agentic engine. Guardrail models watch the working agents. Humans decide which actions always need approval. Legit’s VibeGuard, for example, asks a person before an agent deletes code or touches production.
Build or buy. Buy. Build the requirement into public procurement of AI agents, and fund academic work on containing agent worms.
19. The AI and software supply-chain gate
What it is. A gate on everything that is installed or pulled in, from packages, extensions and containers to models, MCP servers and agent “skills”, together with hardened release pipelines for the security tools themselves.
Who proves it. Koi began with a fake VS Code theme, built in about thirty minutes, that reached 300+ organisations in a week. Its Wings engine detonates every component and update in a sandbox, and its disclosures included ShadyPanda (145 browser extensions, 4.3 million installs) and ClawHavoc (341 malicious agent skills); Palo Alto bought it about twenty months after it was founded. Zenity has disclosed a malicious-skills campaign with 1.7 million installs. Snyk bought Invariant Labs, which named “tool poisoning” and “MCP rug pulls”, and Legit keeps secrets out of agent memory by injecting them through MCP.
The mechanism. Inventory, sandboxed analysis and approval at install time, plus immutable, pinned and signed releases (Ronen et al 2017).
The frontier. The warning came in March 2026. After a non-atomic credential rotation, attackers force-pushed 76 of 77
trivy-actiontags of Aqua’s Trivy to credential-stealing malware, then reused stolen credentials to poison two Checkmarx GitHub Actions. Security vendors are supply-chain targets too. By 2028: an AI bill of materials (Cycode’s AI-BOM) and signed agent skills become standard.The agentic engine. Analysis agents detonate and score components, and humans approve anything with high privilege. Check the analysts as well as the code: a company has sued Palo Alto and Koi over a threat report allegedly built on unverified AI output.
Build or buy. Buy the gate. Build a funded programme of secure release engineering for widely used open-source projects, which the Aqua dossier calls “cheap brand protection.”
20. Frontier-model evaluation and red-teaming
What it is. Measuring what a model can do offensively before it ships, red-teaming it against real adversarial content, monitoring drift after deployment, and protecting its weights to a defined security level.
Who proves it. Irregular (formerly Pattern Labs), about 25 people, sits inside the pre-release evaluation loop of OpenAI, Anthropic and Google DeepMind. Its work is cited in the evaluations of Claude 3.7 Sonnet and OpenAI’s o3 and o4-mini, and it co-wrote RAND’s SL1–SL5 (Nevo et al 2024). Alice (formerly ActiveFence) sells red-teaming, runtime guardrails and drift detection built on years of labelled real-world abuse data, works with 8 of the 10 leading AI labs, and reports ARR approaching $100M.
The mechanism. Test environments that compound with every engagement (Anthropic judged Irregular’s “more diverse” than it could build internally), scarce adversarial data, and MLSecOps, meaning security testing and monitoring built into the machine-learning lifecycle (Mirsky et al 2021).
The frontier. The failure is instructive. In July 2026 Anthropic disclosed that a misconfigured environment run with Irregular had given test machines live internet access: of 141,006 runs reviewed, six across three incidents reached real organisations’ production systems, and OpenAI reported a similar lapse. A range for testing offensive AI is itself critical infrastructure. By 2028: states and large firms evaluate every model and agent they deploy, as EU AI Act testing duties bite.
The agentic engine. Attacker agents run inside contained ranges. Humans own containment, and in particular the egress rules.
Build or buy. Buy access to evaluators. Build national evaluation capacity inside the cyber gym (feature 23), with containment audited like any other critical system.
Layer 6 — Learn and govern
The first five layers can all be bought. The sixth is where a state adds what no vendor can supply: shared memory across organisations, a pipeline for new knowledge, a place to train and certify defensive agents, and rules that keep autonomy accountable. It is also the layer where a mid-sized European country has the most room to lead.
21. National collective defence: sector SOCs, a national SOC and a “Cyber Dome”
What it is. The layer no organisation can build alone: sector SOCs feeding a national SOC, real-time CISO exchange, and warnings and mitigations pushed to the whole market, so one victim’s lesson protects everyone.
Who proves it. Israel’s National Cyber Directorate (INCD) runs defence in three layers (market resilience, operational response, national defence), aiming for “the defense operational cycle to outpace that of the adversary” and “immunization from similar attacks throughout the market”, with CyberNet linking CISOs in real time (INCD 2021). The 2025 strategy adds a “Cyber Dome”, an idea first sketched by Raska (RSIS 2014), whose systems “will fuse and correlate various types of data, incorporating AI to create a holistic snapshot of all imminent attacks and threats to the economy”, plus a national SOC fed by sectoral SOCs (INCD 2025).
The mechanism. Federation plus trust by design. Sector SOCs keep context and a national SOC sees the whole, and responsibility shifts from operator to state as the threat level rises (Frei, ETH CSS 2020). Israel moved critical-infrastructure protection out of the Shin Bet and deliberately gave the civilian authority no law-enforcement powers, “to prevent any ongoing suspicion of NSA-like practices”; its head likened the service to a public water system: “When we will find contamination, we will not suspect who contaminated it” (Tabansky 2020).
The frontier. Today: hotlines and alerts. By 2028: machine-readable sharing at machine speed, against targets now written into the 2025 strategy: “zero significant damage to critical infrastructure” and a stated position against paying ransoms (Shabtai, BESA 2025). The plumbing is the obstacle: 53% of ICS-specific observables lack adequate representation in the STIX standard and 77% of extracted artefacts lack operational detail (Hahn et al 2026).
The agentic engine. Fusion agents correlate the sector feeds and early-warning agents draft alerts. Humans own intervention, legal limits and attribution.
Build or buy. Build: this is the sovereign core, and for us it belongs with NÚKIB and the sector CSIRTs. Buy components such as KELA’s national suite, but be wary of “sovereign stacks” sold whole, like that of Dream Security, founded by NSO’s former CEO. Its own dossier’s verdict: “Sovereignty rented from a foreign vendor is still dependency.”
22. The research-to-product and disclosure pipeline
What it is. An institutional pipeline that turns academic attack research into coordinated disclosure, global patches, standards and start-ups, so the loop learns about a new class of threat before adversaries use it.
Who proves it. Ben-Gurion showed that a botnet of 1,355 hijacked smart-irrigation systems could empty a water tower in an hour (Nassi et al 2018). Tel Aviv University’s NXNSAttack fix was adopted by BIND, Unbound, PowerDNS, CZ.NIC’s Knot, Google, Cloudflare, Amazon and Microsoft (Afek, Bremler-Barr & Shafir 2020), and its Siemens S7 model flagged single anomalous bits while passing over 99.82% of production traffic as normal (Kleinmann & Wool 2014). Weizmann and the Technion add IoT chain reactions and Morris II, and the INCD counts seven academic cyber centres and 500+ papers (INCD 2021). Company labs (Team82, Oligo, Zenity Labs, Koi) carry the habit into the market, and Team8’s foundry turned theses into Claroty and Sygnia.
The mechanism. Publish the attack and the countermeasure together, ship a fix that can actually be deployed (MaxFetch ran in BIND with no loss of throughput), and fund labs through several channels: state centres, industry institutes and philanthropy.
The frontier. Today: human researchers. By 2028: autonomous vulnerability research (AIxCC; Checkmarx in Project Glasswing) multiplies the volume of findings, and coordinated disclosure has to run at machine speed as well.
The agentic engine. Research agents fuzz and reason over nationally critical code, and disclosure agents coordinate with maintainers. Humans own dual-use judgement and timing.
Build or buy. Build. Brno’s Masaryk University already co-authored NATO’s reference architecture for autonomous defence (Kott et al 2019). Pair a funded disclosure programme with a foundry wired to critical-infrastructure buyers.
23. The cyber gym
What it is. A national range that doubles as a training gym and certification ground for defensive AI agents. It uses simulation for speed and emulation for truth, and runs public challenges with real budgets.
Who proves it. Mostly not Israel, which is the point. Australia’s CybORG trains agents in simulation and validates them in emulation: all 21 agents succeeded in simulation, but only 139 of 210 emulation runs did, and four agents never transferred (Standen et al 2021). The Five Eyes run the annual CAGE challenges, and DARPA’s AIxCC final ran seven autonomous systems for about 143 hours on 53 projects derived from critical-infrastructure software, each with $85K of compute and $50K of LLM credits (Zhang et al 2026). The library holds no public Israeli equivalent; the closest are commercial (Irregular’s environments, Pentera Labs).
The mechanism. The gap between simulation and reality is the core risk, and exploitability, not average reward, is the metric. CAGE entries scored against fixed red agents reward overfitting, and agents that beat scripted attackers can be brittle against adaptive ones (Palmer et al 2024).
The frontier. Today: research gyms. By 2028: certification. No defensive agent gets autonomy on a critical network without passing the gym, and the same range hosts AI-model evaluation (feature 20), with containment audited after Irregular’s egress failures.
The agentic engine. Red agents fight blue agents while evaluator agents score them. Humans design the scenarios and set certification thresholds.
Build or buy. Build: this is where a mid-sized EU state can lead rather than follow. A Czech-hosted, EU-open challenge with real compute budgets would fill a gap Israel has left open.
24. Governed autonomy
What it is. Explicit rules for what each agent may do without asking, when it must hand off to a human, how the defenders’ own models are attacked and tested, and how every action is logged and reversed.
Who proves it. NATO’s architecture bounds destructive actions by rules of engagement, confines them to the host and keeps a human override open (Kott et al 2019); INSS recommends deciding, system by system, which functions keep human supervision (Antebi, INSS 2021). The sharpest evidence is Israel’s own. Before October 7 the intelligence community’s “love affair” with cyber intelligence and AI brought automated processing “with little or no human intervention”, an “intelligence pool” that analysts pulled from instead of warnings pushed to them, and the 2021 dismantling of 8200’s OSINT unit on the strength of machine translation (Bar, NIPP 2024).
The mechanism. Tiered autonomy. Reversible actions are taken first and reported afterwards. Destructive actions, and any action touching a crown jewel, need a human first. Offensive or cross-border action is never autonomous and stays an all-of-government decision under law (INCD 2021).
The frontier. Today: ad hoc approvals. By 2028: autonomy levels certified in the gym, MLSecOps for the defenders’ own models, which can be poisoned and evaded (Mirsky et al 2018; Shamir et al 2019), and audit trails a regulator can read.
The agentic engine. Oversight agents watch the working agents, and a named human owns every autonomy grant. Warnings are pushed, never left in a pool, and dissent has a protected channel. The 2025 strategy now writes in countermeasures against the biases that underrate strategic surprise (Shabtai, BESA 2025); the October 7 lesson is that a system must hear the analyst who is right (Wyss, CTC Sentinel 2024).
Build or buy. Build. This is policy, not product, and it is the feature that decides whether the other twenty-three can be trusted.
How the twenty-four compose into one machine
One graph. The most important design decision is that all twenty-four features read and write one world model. Its nodes are assets, identities (human, machine, agent), data stores, code, runtime processes and adversaries; its edges record what can reach, access, run on, call, own and exploit what. The seven graphs named at the start of this report, from Wiz’s to the one inside Torq, are each a partial version of the “world model” in NATO’s reference architecture (Kott et al 2019). The machine needs one graph, in an open schema, owned by the defender, not seven owned by seven vendors. Hunters’ use of the OCSF schema points the way; the gaps Hahn et al (2026) found in STIX for industrial systems show how far there is to go.
One loop. Layer 1 writes the graph. Layer 2 annotates it with attack paths, reachability, validation results and mitigations. Layer 3 compiles those into enforcement: segmentation rules, browser and allow-list policy, edge virtual patches, diodes. Layer 4 watches for deviations and acts; Layer 5 applies all of it to agents; Layer 6 brings warnings and research in, sends lessons out, certifies agents and sets their autonomy.
An illustration, not a case study:
09:00 · An advisory is published. An intake agent parses it, and the graph shows 14 instances in the estate.
09:10 · Runtime evidence (Oligo-type) shows the vulnerable function executes on three of them. Path analysis (Wiz- or XM-type) shows one sits on a choke point to the billing database.
09:25 · A mitigation agent drafts a virtual patch at the edge and a tightened segmentation rule (Zafran-, Cato- and Zero Networks-type). A human approves it, because the billing database is a crown jewel.
09:40 · Validation (Pentera- or Cymulate-type) confirms the path is closed, and a patch agent opens a pull request with proof of the vulnerability attached.
10:30 · The national CERT publishes the mitigation in machine-readable form. Threat intelligence (KELA-type) later flags an exploit for sale, and every subscriber’s agents check themselves against it.
Where real deployments break. The dossiers are candid about the failure points:
Integration seams. Axonius, Zafran and 7AI all depend on APIs that competing platforms can restrict or price. A loop joined only by third-party APIs lasts only as long as those vendors allow.
Alert noise. Without the Layer 2 joins the loop drowns, which is why the best products are measured by what they remove: Pentera cuts about 10,000 alerts to 6–8 root causes; Oligo claims 90–99% noise reduction, Torq about 70%.
Platform lock-in. Bundles are not loops. Armis lost its neutrality inside ServiceNow, Wiz’s neutrality inside Google is an open question, and XM Cyber’s owner now licenses its own technology from CrowdStrike. Hunters shows the flip side: a correct architecture loses to whoever owns the telemetry.
Blocking fear. Sensors and allow-lists go to monitor-only after one bad block; autonomy is revoked after one outage.
The defenders’ own supply chain. Trivy and Checkmarx fell to the same campaign in March 2026; every privileged tool in the loop is a target.
The humans. A loop whose warnings sit in a data pool rather than being pushed to someone who must act fails, however good its sensors (Bar, NIPP 2024).
Operating model and metrics
Twelve indicators show whether the loop is actually closing:
Coverage of the graph · the share of assets, identities (human, machine, agent) and sensitive data stores with a named owner and the required controls; the unit is the gap Axonius flags, such as a laptop without EDR.
Agent visibility · agents in the register as a share of agents discovered. Noma typically finds 10 to 100 times more than teams expected.
Exploitable exposure on crown-jewel paths · the count of open choke points, not total findings. XM Cyber found only 2% of exposures sit on choke points.
Time from disclosure to mitigation · median hours from advisory to blocked exploitation on reachable instances: the headline number, because machines exploit from the advisory text (Fang et al 2024).
Validated control efficacy · the share of simulated attack techniques blocked or detected, re-run continuously (Pentera, Cymulate).
Lateral reachability · the share of servers reachable from anywhere on the internal network. Zero Networks’ benchmark found 80%, and the target is near zero around crown jewels.
Crown jewels at tier · the share of registered crown jewels meeting their assigned SL level (Nevo et al 2024).
Autonomous closure with audited error · alerts closed without a human, always reported beside the rate of wrong actions.
Analyst hours returned · the measure 7AI publishes, which boards understand.
Fraud and scam loss per million sessions · the budget that feels the loss (BioCatch, Forter).
Sharing latency · the time from the first victim’s report to mitigation across the market, which is the INCD’s “immunization” put into numbers.
Recovery order and time · how fast the functions that matter return. When ransomware locked every system at Hillel Yaffe hospital in October 2021, occupancy fell from 83% to 64%; national experts had a new network built and systems restored in clinical-priority order, and restoring records and the laboratory module was associated with a 30% rebound, imaging archives with 50% (Abbou et al 2024). Rank recovery by function and rehearse the paper-based blackout.
The human roles that remain are the ones that carry judgement:
the loop owner · one accountable executive, or for the state NÚKIB
crown-jewel owners · who set adversary tiers and accept residual risk
detection and agent engineers · who curate agent skills and review wrong actions
the red-team lead · who sets rules of engagement for offensive validation
the intelligence analyst and law-enforcement liaison · who own attribution
the incident commander · who approves destructive actions in a crisis
the AI-governance officer · who owns the agent register and autonomy grants
plant engineers · who own every inbound change to OT
the protected dissenter · the analyst whose warning the system is obliged to escalate
Building it: a twelve-month roadmap
The sequence fits a Czech-scale national programme, led by NÚKIB with sector regulators and operators of essential services, or a large enterprise with a board-level loop owner. It follows the loop’s own order, but governance starts on day one, not in month twelve.
Months 0–3 · Name and see
Appoint the loop owner and publish an autonomy charter: which actions agents may take alone, which need approval and which are never autonomous (feature 24).
Build the crown-jewel register and assign each asset an adversary tier on the SL1–SL5 model (feature 12).
Stand up the graph with bought asset, identity and data-map tools (features 1–3), exporting everything into a schema the state owns.
Open the agent register for public bodies (feature 17) and baseline the twelve metrics.
Months 3–6 · Understand and close doors
5. Deploy the attack-path twin and continuous validation on crown jewels (features 5 and 7).
6. Segment crown jewels and put authentication-layer MFA on legacy and admin paths (feature 10). Put one-way gateways on the highest-consequence OT sites in energy and water (feature 12).
7. Build the disclosure-to-mitigation pipeline, with the national CERT publishing machine-readable mitigations alongside advisories (feature 8).
Months 6–9 · Respond at machine speed
8. Pilot an agentic SOC on a federated, open-schema data layer in two sectors, feeding a national SOC. Launch a CyberNet-style trusted CISO exchange (features 14 and 21).
9. Convene the banks, the central bank and the police into a behavioural fraud-sharing consortium (feature 15). Contract incident-response retainers and form a national responder reserve (feature 16).
10. Put a supply-chain gate on developer and administrator endpoints in government, and make runtime guardrails a condition of buying AI agents (features 18 and 19).
Months 9–12 · Learn
11. Open the national cyber gym and an EU-open challenge with real compute budgets, with Masaryk University and the Czech technical universities as founding partners, and house AI-model evaluation in the same range (features 20 and 23).
12. Launch a research-to-product foundry with ten critical-infrastructure design partners and a funded coordinated-disclosure programme (feature 22).
13. Review the metrics and decide which agents move up an autonomy tier and which move down.
What to buy, and what to build. Buy what is mature and commoditising: the tools behind features 1–7, 9–11 and 13–19, and the diodes for feature 12. Build what makes it a loop and makes it ours: the graph and its schema, the crown-jewel register, the national twin, the CERT mitigation feed, the national SOC and sharing fabric, the fraud consortium, the national red team, the gym, the research pipeline and the autonomy charter.
Buy on conditions drawn from the Dream Security and Cellebrite dossiers: source-code access or escrow, local hosting and staff, data export in open schemas, clean exit clauses and, for dual-use tools, published end-use vetting.
The dependency risks, named.
Ownership has moved west. Wiz belongs to Google; CyberArk and Koi to Palo Alto Networks; Armis to ServiceNow; Astrix to Cisco; XM Cyber’s IP is going to CrowdStrike and BioCatch to Visa. The only European buyers in the dossiers are Thales (Imperva) and Schwarz, which sold XM Cyber’s IP on and licensed it back.
Independence is thinning. Check Point, Cato, Radware, Claroty, Axonius, Island and Cyera remain independent, several are obvious targets, and Varonis is in reported talks with Proofpoint.
Country exposure. Principal R&D sits in Israel. Radware’s annual report warns that the shekel will “materially increase” its costs, and Guardz’s CTO ran a funding round while deployed as a reservist.
Model dependence. AI-native products such as Glow reason on American frontier models.
Reputational tail. Dream Security’s NSO lineage and Cellebrite’s uneven vetting (Serbian customers suspended, similar evidence from Jordan and Kenya dismissed) show how a vendor’s export governance becomes its customers’ problem.
The mitigation is the same in every case: own the graph, own the policies, keep the exit open.
Close: build the loop, buy the parts
The question behind this report was what the most advanced cybersecurity system in the world would look like if Israel’s best companies and research were combined. The answer is less a list of twenty-four products than one machine with twenty-four organs: a live graph of everything owned, context that reduces millions of findings to a handful of choke points, architecture that removes attack classes outright, agents that respond in minutes, a new layer for AI agents, and a national layer that learns, shares and holds autonomy to account.
Israel has built almost every organ, and its own strategy describes the whole in almost exactly those terms: a “Cyber Dome” that fuses data with AI into “a holistic snapshot of all imminent attacks” (INCD 2025). But the Cyber Dome is still in its preliminary operating stage, and in 2025–26 Israel sold many of the organs to American platforms, which are assembling bundles, not loops.
That leaves room for a mid-sized European state. The Czech Republic does not need an 8200 or fifty unicorns. It needs to own four things no vendor can sell it: the graph, the policies, the gym and the judgement. It can buy the rest on hard conditions from the best builders in the world, one of which, Cato, is already tripling its engineering centre in Prague. The pressure comes from offence, which already runs at a few dollars an attempt, before the patch is written. The first move is the least glamorous one: name the crown jewels, map them into one graph, and write down what the machines may do without asking. The rest of the roadmap follows from those three steps.



