Skip to main content
Cyber Security 8 min read By Adv. Or Elyashiv

Who Regulates Cybersecurity for Israel's Critical Infrastructure

A guide to the regulatory framework governing critical infrastructure operators in Israel, from general legislation to sector-specific directives, and what it actually requires.

קראו בעברית

A Cyberattack on a Power Utility Is Not a Private Matter

When a power plant, water utility, or telecommunications operator suffers a ransomware attack, the damage does not stay within the organization's walls. A regional blackout, a disruption to communications infrastructure, or an attack on healthcare systems can endanger human lives and destabilize the routine functioning of the entire economy.

For this reason, entities classified as critical infrastructure in Israel are not subject only to the general cybersecurity laws applicable to any business — they fall under a dedicated, more stringent regulatory regime. This regime combines primary legislation, government resolutions, a dedicated oversight body, and sector-specific directives issued by industry regulators.

This article is intended for technology companies, service providers, and infrastructure operators that supply services to entities classified as critical, as well as for companies that are themselves considered critical infrastructure within their sector. Understanding this regulatory framework is essential both for compliance purposes and for managing contractual risk vis-à-vis government and public-sector clients.


The Security in Public Bodies Law as the Regulatory Foundation

The central legislative foundation for oversight of information security and cybersecurity in Israel's critical infrastructure is the Security in Public Bodies Law, 5758-1998 (חוק להסדרת הביטחון בגופים ציבוריים). The law applies to a closed list of entities appended in its schedule, including the Israel Electric Corporation, the Airports Authority, water corporations, ports, and other infrastructure bodies.

The law authorizes the Israel Security Agency (Shin Bet) to set mandatory security directives for the designated entities, including in the area of information security and cybersecurity, and requires those entities to appoint a security officer and to act in accordance with the directives issued to them. Over the years, the scope of these directives has expanded to include substantial cyber defense components, beyond traditional physical security.

It is important to understand that the law does not apply only to the public body itself — it also has implications for suppliers and subcontractors that provide it with technology, cloud infrastructure, or development services. Technology companies contracting with an entity classified as critical infrastructure may find themselves required to meet specific security requirements as a condition of engagement, even when they are not themselves directly subject to the law.


The Regulatory Role of the National Cyber Directorate

The National Cyber Directorate, operating within the Prime Minister's Office under government resolutions, is responsible for Israel's national cyber defense policy. The Directorate publishes methodologies for cyber risk management, guides organizations in building defense programs, and operates CERT-IL, the national cyber incident response center, through which organizations can report incidents and receive professional assistance.

In practice, the Directorate operates on two main levels with respect to critical infrastructure: professional support and advisory services on one hand, and directive and oversight powers on the other, applied according to the criticality level assigned to each entity. Organizations designated at a high criticality level are required to meet more stringent standards, including periodic risk assessments and readiness exercises.

As of the date of this article, a comprehensive bill on cyber defense regulation has been under consideration in Israel for several years, intended to anchor the National Cyber Directorate's powers in primary legislation and expand their application to a broader range of entities. Companies operating in critical infrastructure sectors, or providing services to such entities, should monitor the progress of this legislation, as it may significantly change the scope of obligations applicable to them.


Sector-Specific Regulation: Banking, Capital Markets, Energy, and Telecommunications

Beyond the general framework, most sectors classified as critical are also subject to dedicated sector-specific regulation, issued by the regulator overseeing that particular industry.

These directives are updated from time to time. A company engaging with a client in a regulated sector should review the current version of the relevant directive on the regulator's official website, rather than relying on historical information.


Board and Management Accountability at Infrastructure Entities

Under most of the regulatory frameworks described above, compliance responsibility does not rest solely with the organization's information security personnel — it extends up to the board of directors and senior management. Many directives require board approval of the cyber risk management program, ongoing reporting to management on incidents and risks, and the appointment of a designated officer responsible for the matter.

At entities classified as critical infrastructure, failure to meet these requirements can create a basis for personal exposure of officers, not only corporate exposure. Technology companies supplying services to such entities are typically required to demonstrate sound corporate governance in the cyber domain as part of the client's due diligence process prior to engagement.


Cyber Incident Reporting and Enforcement Powers

Most of the frameworks described above include an obligation to report significant cyber incidents — whether to the National Cyber Directorate, to the sector regulator, or to both in parallel. Reporting deadlines, materiality thresholds, and the manner of reporting are set out in the specific directive applicable to the entity, and vary between sectors.

In addition, where an incident involves a leak of personal data, separate reporting obligations may also apply under the Privacy Protection Law, 5741-1981, as amended by Amendment 13, including a duty to notify the Privacy Protection Authority in circumstances defined by law. A company experiencing a cyber incident may therefore find itself required to report in parallel to several regulatory bodies, not only to its sector regulator.

The various regulators hold enforcement powers that include requiring the correction of deficiencies, imposing operational restrictions, and, in serious cases, administrative sanctions. The scope of these powers and sanctions varies according to the applicable law and directive, and it is advisable to review current information on the relevant regulator's website before drawing conclusions regarding specific exposure.


What Companies Operating in This Space Actually Need to Do

Companies supplying technology, cloud infrastructure, or development services to entities classified as critical infrastructure, as well as entities so classified themselves, should act on several parallel fronts.

The regulatory framework governing critical infrastructure in Israel continues to evolve, both due to technological change and the possible advancement of new primary legislation. Companies operating in this space need a dynamic compliance approach, based on ongoing monitoring of regulatory updates rather than reliance on a static legal snapshot.


The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.

Adv. Or Elyashiv
Written by

Adv. Or Elyashiv

Founder of Or Elyashiv Law Firm, specializing in technology law, privacy protection, intellectual property, and commercial law. Advising tech companies, startups, and international investors. Data Protection Officer (DPO), a graduate of the Tel Aviv University training program for data protection officers, held in cooperation with the Israeli Privacy Protection Authority.

View All Articles

Need Legal Guidance on Cyber Regulation?

Our firm advises technology companies and infrastructure entities on aligning their information security policies with applicable regulatory requirements, and on structuring contractual arrangements with institutional and public-sector clients.