A Cyberattack on a Power Utility Is Not a Private Matter
When a power plant, water utility, or telecommunications operator suffers a ransomware attack, the damage does not stay within the organization's walls. A regional blackout, a disruption to communications infrastructure, or an attack on healthcare systems can endanger human lives and destabilize the routine functioning of the entire economy.
For this reason, entities classified as critical infrastructure in Israel are not subject only to the general cybersecurity laws applicable to any business — they fall under a dedicated, more stringent regulatory regime. This regime combines primary legislation, government resolutions, a dedicated oversight body, and sector-specific directives issued by industry regulators.
This article is intended for technology companies, service providers, and infrastructure operators that supply services to entities classified as critical, as well as for companies that are themselves considered critical infrastructure within their sector. Understanding this regulatory framework is essential both for compliance purposes and for managing contractual risk vis-à-vis government and public-sector clients.
The Security in Public Bodies Law as the Regulatory Foundation
The central legislative foundation for oversight of information security and cybersecurity in Israel's critical infrastructure is the Security in Public Bodies Law, 5758-1998 (חוק להסדרת הביטחון בגופים ציבוריים). The law applies to a closed list of entities appended in its schedule, including the Israel Electric Corporation, the Airports Authority, water corporations, ports, and other infrastructure bodies.
The law authorizes the Israel Security Agency (Shin Bet) to set mandatory security directives for the designated entities, including in the area of information security and cybersecurity, and requires those entities to appoint a security officer and to act in accordance with the directives issued to them. Over the years, the scope of these directives has expanded to include substantial cyber defense components, beyond traditional physical security.
It is important to understand that the law does not apply only to the public body itself — it also has implications for suppliers and subcontractors that provide it with technology, cloud infrastructure, or development services. Technology companies contracting with an entity classified as critical infrastructure may find themselves required to meet specific security requirements as a condition of engagement, even when they are not themselves directly subject to the law.
The Regulatory Role of the National Cyber Directorate
The National Cyber Directorate, operating within the Prime Minister's Office under government resolutions, is responsible for Israel's national cyber defense policy. The Directorate publishes methodologies for cyber risk management, guides organizations in building defense programs, and operates CERT-IL, the national cyber incident response center, through which organizations can report incidents and receive professional assistance.
In practice, the Directorate operates on two main levels with respect to critical infrastructure: professional support and advisory services on one hand, and directive and oversight powers on the other, applied according to the criticality level assigned to each entity. Organizations designated at a high criticality level are required to meet more stringent standards, including periodic risk assessments and readiness exercises.
As of the date of this article, a comprehensive bill on cyber defense regulation has been under consideration in Israel for several years, intended to anchor the National Cyber Directorate's powers in primary legislation and expand their application to a broader range of entities. Companies operating in critical infrastructure sectors, or providing services to such entities, should monitor the progress of this legislation, as it may significantly change the scope of obligations applicable to them.
Sector-Specific Regulation: Banking, Capital Markets, Energy, and Telecommunications
Beyond the general framework, most sectors classified as critical are also subject to dedicated sector-specific regulation, issued by the regulator overseeing that particular industry.
- Banking sector — the Bank of Israel publishes proper banking management directives addressing cyber risk management, including structured requirements for governance, risk identification, technological controls, and incident reporting.
- Capital markets, insurance, and savings — the Capital Market, Insurance and Savings Authority publishes circulars requiring institutional entities to manage cyber risk, including resilience testing and reporting of material incidents.
- Public capital markets — the Israel Securities Authority has published guidance regarding disclosure of cyber risks and material cyber incidents in public companies' reports.
- Energy and water — the Ministry of Energy and the Water Authority operate dedicated regulatory frameworks for production and transmission infrastructure, in conjunction with National Cyber Directorate directives.
- Telecommunications — the Ministry of Communications regulates information security requirements applicable to network operators and internet service providers.
These directives are updated from time to time. A company engaging with a client in a regulated sector should review the current version of the relevant directive on the regulator's official website, rather than relying on historical information.
Board and Management Accountability at Infrastructure Entities
Under most of the regulatory frameworks described above, compliance responsibility does not rest solely with the organization's information security personnel — it extends up to the board of directors and senior management. Many directives require board approval of the cyber risk management program, ongoing reporting to management on incidents and risks, and the appointment of a designated officer responsible for the matter.
At entities classified as critical infrastructure, failure to meet these requirements can create a basis for personal exposure of officers, not only corporate exposure. Technology companies supplying services to such entities are typically required to demonstrate sound corporate governance in the cyber domain as part of the client's due diligence process prior to engagement.
Cyber Incident Reporting and Enforcement Powers
Most of the frameworks described above include an obligation to report significant cyber incidents — whether to the National Cyber Directorate, to the sector regulator, or to both in parallel. Reporting deadlines, materiality thresholds, and the manner of reporting are set out in the specific directive applicable to the entity, and vary between sectors.
In addition, where an incident involves a leak of personal data, separate reporting obligations may also apply under the Privacy Protection Law, 5741-1981, as amended by Amendment 13, including a duty to notify the Privacy Protection Authority in circumstances defined by law. A company experiencing a cyber incident may therefore find itself required to report in parallel to several regulatory bodies, not only to its sector regulator.
The various regulators hold enforcement powers that include requiring the correction of deficiencies, imposing operational restrictions, and, in serious cases, administrative sanctions. The scope of these powers and sanctions varies according to the applicable law and directive, and it is advisable to review current information on the relevant regulator's website before drawing conclusions regarding specific exposure.
What Companies Operating in This Space Actually Need to Do
Companies supplying technology, cloud infrastructure, or development services to entities classified as critical infrastructure, as well as entities so classified themselves, should act on several parallel fronts.
- Assess whether the organization, or a service it provides, falls under the Security in Public Bodies Law or under a sector-specific definition of critical infrastructure.
- Map the full set of relevant regulatory directives, including those of the National Cyber Directorate and the applicable sector regulator, and keep this mapping current on an ongoing basis.
- Ensure contracts with institutional clients include clear information security clauses, including audit rights, incident reporting obligations, and appropriate indemnification mechanisms.
- Build an internal incident response procedure that quickly identifies applicable reporting obligations — regulatory, contractual, and under the Privacy Protection Law.
- Ensure that responsibility for cyber risk management is anchored at the board level, rather than remaining solely a professional IT matter.
The regulatory framework governing critical infrastructure in Israel continues to evolve, both due to technological change and the possible advancement of new primary legislation. Companies operating in this space need a dynamic compliance approach, based on ongoing monitoring of regulatory updates rather than reliance on a static legal snapshot.
The information contained in this article is general in nature and does not constitute legal advice. For advice tailored to the specific circumstances of your company, we invite you to contact our firm.