National Cyber Protection Bill – Israel Aligns with Global Standards | Adv. Adiel Klein

The National Cyber Protection Bill, approved in its first reading in the Knesset on June 8, 2026, aims to regulate cyber protection in Israel and anchor the National Cyber Directorate. The law will apply to essential organizations in infrastructure sectors and digital service providers with an annual turnover of NIS 40 million or more, or 50 or more employees. It includes a duty to report significant attacks, financial sanctions, and criminal liability for violators.

On June 8, 2026, the Knesset plenum approved in its first reading the National Cyber Protection Bill, 2026. Israel, among the most cyber-attacked countries in the world, especially since the outbreak of the 'Iron Swords' war with a sharp increase in the scope and intensity of attacks against civilian entities, has remained without a comprehensive national legislative framework in this field. The bill aims to raise awareness of cyber protection in the public and private sectors, create a uniform line for functional continuity in an organization experiencing a cyber event, and anchor the National Cyber Directorate (Sections 2-4) as the body coordinating national defense, alongside 'sectoral units' (Section 5) that will operate under each regulator. The core of the bill is the concept of 'essential organization' (Section 8): any government body and any organization meeting the sectoral criteria in the Third Addendum – communications, energy, health, water and sewage, transportation, chemicals, agriculture, local authorities, and more. In the private sector, the applicability to 'digital service and hosting providers' (Item 9 of the Third Addendum) is surprising in its scope – about 20 types of services, including cloud, data centers, IT, and cyber security. A provider will fall under the law if its annual turnover is NIS 40 million or more, or it employs 50 or more employees, or provides services to the government. The law requires essential organizations to adopt appropriate cyber protection measures, using international standards such as ISO 27001 and NIST 800-53, and includes a duty to immediately report a significant cyber attack (Section 11). Violations involve financial sanctions in the hundreds of thousands of shekels, and in severe cases criminal liability and personal exposure for office holders (Sections 44-45). The National Cyber Directorate stated that the proposal aims to increase national resilience and maintain routine in the home front, while balancing operational needs with continued normal activity, and that it focuses on essential organizations in core sectors like the European NIS2 directive. The author, Adv. Adiel Klein, estimates that the proposal will undergo further changes and there will be a preparation period, but the direction is clear – national alignment with international regulations and the understanding that cyber protection is an integral part of the business lifecycle. He also notes possible indirect implications in operational, insurance, and labor spheres.

National Cyber Protection Bill – Israel Aligns with Global Standards | Adv. Adiel Klein