Israel’s national cyber authority is telling the country’s critical infrastructure operators to stop assuming they can keep attackers out. In a policy shift confirmed by The Jerusalem Post and other outlets on September 1, 2026, the Israel National Cyber Directorate (INCD) says a new generation of artificial intelligence models has broken through what it calls the technological complexity barrier, letting attackers find and exploit security flaws at industrial speed. The agency’s answer is not a new firewall or a bigger budget line for patching. It is a doctrine change: from closing vulnerabilities and prevention to containment and operational resilience.

What Israel’s Cyber Directorate Actually Said

The INCD’s core claim, as reported, is specific: AI models have crossed a threshold where identifying an exploitable flaw in production software no longer takes a skilled human team days or weeks. It takes a model minutes, and it can do it at a scale no human red team can match. That claim tracks with what Western agencies have been saying with less urgency for the past year, but the INCD’s framing goes further than most. Rather than asking defenders to close every gap before an attacker finds it, a bar the agency now treats as unreachable, it is asking them to plan for the breach that already happened.

That is the origin of the directorate’s “Breach Ready” language: organizations should operate on the assumption that their internal networks are already compromised, and success is measured by how fast they detect, contain, and resume operations, not by whether they prevented the initial intrusion. It is a blunt admission that prevention-first security, the model most critical infrastructure operators have built their programs around for two decades, is losing a race it was already struggling to win.

Reports describing the specific AI systems behind this shift, including names circulating in some secondary coverage, remain unconfirmed by the INCD itself. What is confirmed is the strategic conclusion the agency has drawn: patch-and-pray no longer scales against attackers who can automate vulnerability discovery.

Israel’s Multi-Year Plan: Cloud, AI, and Quantum by 2030

The doctrine shift sits inside a broader national plan. Yossi Karadi has described Israel’s new multi-year cyber defense strategy as resting on three pillars: cloud security, cyber AI, and quantum technologies, with the plan intended to be fully operational by 2030. That four-year runway is itself a signal. Israel, a country that treats cyber defense as a matter of national survival given its threat environment, is not promising a quick fix. It is building for a decade-long contest in which AI plays offense and defense simultaneously.

Karadi also identified where the pressure has landed hardest over the past year: the financial sector, government institutions, and digital service providers were the three most targeted areas in Israel. That list is not surprising on its own, but it matters because it tells operators where the INCD expects the “Breach Ready” doctrine to be tested first. A bank or a government portal that assumes breach and plans for fast containment looks very different, operationally, from one still betting everything on the perimeter holding.

The three-pillar structure also explains why quantum technologies sit alongside AI in the plan rather than as a separate initiative. Israeli planners are treating the AI-acceleration problem and the eventual quantum-decryption problem as related fronts in the same long war, both requiring infrastructure investment years ahead of the threat becoming acute.

The State Comptroller’s Warning: Cracks Already Found

The urgency behind the doctrine shift is not theoretical. Israel’s State Comptroller has reported severe security flaws in some of the country’s most sensitive information systems, including medical centers, energy and transportation infrastructure, the Israel Land Authority, the IDF’s biometric database, and the Ministry of Education’s database of matriculation exam results and grades. Those are not minor administrative systems. A biometric database breach touches identity verification for a military that runs on conscription. A matriculation records breach can be exploited for fraud that follows a person for life. Energy and transportation flaws translate directly into physical-world risk if an attacker with AI-assisted exploit development gets in.

The Comptroller’s findings are what give the INCD’s new posture its teeth. It is one thing for an agency to warn abstractly that AI is changing the threat landscape. It is another for the country’s independent auditor to have already documented exploitable gaps in the biometric and grading systems the government relies on. Read together, the two reports make the case for containment-first planning almost on their own.

Why “Containment Over Prevention” Is a Real Doctrine Shift

Security teams have talked about defense in depth and assume-breach architectures for years, but most budgets, staffing models, and vendor contracts in critical infrastructure still center on prevention: firewalls, patch cycles, vulnerability scanning, and perimeter controls. The INCD’s shift asks operators to rebalance that spending toward detection speed, network segmentation that limits lateral movement, and incident response capacity that can restore operations in hours rather than days.

That rebalancing is hard precisely because prevention spending is easier to justify to a board. A firewall upgrade has a clear before-and-after. Investing in faster containment is harder to sell until the day it saves the organization, and by then the investment decision is years in the past. Israel’s directorate is effectively telling every critical infrastructure operator in the country that this justification problem no longer matters: the assumption has to change now, budget cycles or not.

How Fast Exploit Development Has Actually Gotten

Guy Segal, CEO of Israeli incident response firm Sygnia, has described the compression directly. Segal has said threat actors are increasingly using autonomous agents inside a victim’s own network to move wider and faster once they gain a foothold, and that turning a previously unknown software vulnerability into a working exploit, a process that used to take attackers weeks, now takes hours. That single data point (weeks compressed to hours) is arguably the clearest evidence for why the INCD abandoned prevention-first thinking. A defense model built around patch cycles measured in days or weeks cannot outrun an attack cycle measured in hours.

Segal’s second point, about agents operating inside compromised networks rather than attackers manually pivoting machine to machine, describes a meaningful change in tradecraft. Autonomous lateral movement means detection windows shrink even after the initial breach, which is exactly the phase the “Breach Ready” doctrine is designed to address. If containment depends on catching an attacker before they reach the crown-jewel systems, and the attacker’s internal movement is now automated, defenders need automated detection and segmentation to match, not just faster human analysts.

The Industry View: AI Multiplies Attacker Reach

Israeli cybersecurity companies, several of them global players in the sector, are describing the same pattern from the vendor side. Yevgeny Dibrov, CEO of asset-visibility firm Armis, has said AI’s impact on the scale of cyberattacks worldwide is already dramatic, and that AI tools let even a relatively small attacker mount an attack at a scale that used to require far more resources, sometimes a hundred or even a thousand times larger than before. That framing matters for critical infrastructure operators specifically, because it means the attacker pool capable of targeting a national power grid or hospital network is no longer limited to state-level actors with large budgets.

Sergey Shykevich, who leads threat intelligence at Check Point Software Technologies, has pointed to a related shift: AI and deepfakes are blurring the line between real and fake in ways that open a new arena for attackers to extract sensitive information from government entities, healthcare providers, and enterprises. That is a different attack surface than exploit automation. It is social engineering at a scale and believability that older training-based defenses (spot the phishing email, verify the caller) were not built to catch. For critical infrastructure operators, it means the containment doctrine has to cover credential theft through AI-generated impersonation, not just software vulnerability exploitation.

Both executives are describing the same underlying dynamic from different angles: AI is not creating new categories of attack so much as it is collapsing the cost and time required to run existing ones at a scale previously reserved for the best-funded threat actors. That collapse is exactly what the INCD says has broken through the old complexity barrier.

Global Agencies Are Saying the Same Thing, With Less Urgency

Israel is not alone in reaching this conclusion, though its posture is more concrete than most. The UK’s National Cyber Security Centre has assessed that artificial intelligence will almost certainly increase the volume and heighten the impact of cyberattacks over the next two years, a formal risk assessment rather than a prediction, in its report on the impact of AI on the cyber threat. In June 2026, the Five Eyes intelligence alliance went further on timing, warning jointly that AI could fuel severe cyberattacks against governments and businesses within months rather than years, reported by the New York Post as “the timeline is not years, it is months.”

Microsoft has been making a parallel case from the vendor side since spring. Charlie Bell, Executive Vice President of Microsoft Security, wrote that the objectives of attackers have not changed, but the tempo, iteration, and scale of generative AI-enabled attacks are certainly upgrading them, and separately that AI is not just accelerating cyberattacks, it is upgrading them. Bell’s framing, published on Microsoft’s security blog in April 2026, is a useful counterpoint to Israel’s move: Microsoft is describing the same acceleration but has not, publicly, told its customer base to abandon prevention in favor of containment. Israel’s directorate is the first major national cyber authority to draw that conclusion out loud and turn it into stated policy.

Prevention-First vs. Containment-First: A Direct Comparison

The table below lays out how the two doctrines differ in practice, based on the INCD’s reported guidance and how critical infrastructure security programs have traditionally operated.

DimensionPrevention-First (traditional)Containment-First (“Breach Ready”)
Core assumptionPerimeter and patching can keep attackers outAttackers are already inside or will get in regardless of controls
Primary metricNumber of vulnerabilities closed, patch cadenceTime to detect, time to contain, time to resume operations
Budget priorityFirewalls, vulnerability scanning, patch managementNetwork segmentation, detection tooling, incident response capacity
Exploit-development timeline it defends againstWeeks (manual attacker research)Hours (AI-assisted exploit generation, per Sygnia’s Guy Segal)
Lateral movement defenseAssumes attacker moves manually, slower detection is tolerableAssumes autonomous in-network agents, requires automated segmentation
Success conditionBreach never happensBreach happens but operations resume quickly

Where Israel’s Critical Infrastructure Is Already Exposed

The State Comptroller’s findings give a second, more specific table worth laying out on its own, because it shows why the doctrine shift is landing where it is landing. Each of the flagged systems sits in a sector the INCD has separately identified as under pressure.

System / Sector Flagged by State ComptrollerWhy It Matters
Medical centersPatient care and records systems, direct physical-safety risk if disrupted
Energy and transportation infrastructureNational-scale physical impact if attackers pivot from IT to operational systems
Israel Land AuthorityProperty and land-registry records, high fraud potential if altered
IDF biometric databaseIdentity verification tied to a conscription-based military
Ministry of Education matriculation exam and grades databaseAcademic records fraud with lifelong consequences for individuals

What This Means for Security Teams Outside Israel

Israel’s INCD is a relatively small national agency by global standards, but it has a track record of setting direction that larger cybersecurity markets end up following, in part because so much of the global cybersecurity vendor base, Check Point and Sygnia among them, is headquartered or founded there. When an agency with that much practical exposure to nation-state and criminal attackers concludes that prevention alone has stopped working, security leaders elsewhere should treat it as an early signal rather than a local curiosity.

The practical takeaway for security teams outside Israel is not to abandon patching and vulnerability management. It is to stop treating containment and incident response as the secondary budget line that gets cut when a prevention tool needs renewal. Segal’s hours-not-weeks exploit timeline and Dibrov’s hundred-to-thousand-fold scale multiplier both point to the same operational reality: the gap between “vulnerability disclosed” and “vulnerability weaponized” has compressed faster than most patch management programs were designed to handle, and that gap is where containment capability now has to do the work prevention used to do alone.

Historical Context: From Stuxnet to AI-Native Attacks

Israel’s relationship with critical infrastructure cyber risk did not start this year. The country has been on both sides of the most consequential infrastructure-targeting cyberattack in history, the Stuxnet operation against Iranian centrifuges over a decade ago, and has built its domestic cyber defense industry partly around lessons drawn from that era: infrastructure attacks are patient, well-resourced, and aimed at physical consequences, not just data theft. What has changed since then is the resource requirement. Stuxnet-class operations used to require nation-state budgets and years of development. The INCD’s warning is that AI-assisted exploit development is closing that gap, putting infrastructure-relevant capability within reach of smaller, less patient actors.

That history also explains why Israel is moving toward a stated containment doctrine faster than most peer nations. A country that has already lived through both ends of an infrastructure-grade cyberattack, as the actor and as a hardened target, treats the AI-acceleration warning less as a hypothetical model risk and more as a rerun of a threat it already understands, just running on a faster clock.

Market and Vendor Impact

A national shift toward containment-first spending is a direct tailwind for the categories that support it: network segmentation, extended detection and response, incident response retainers, and asset visibility. Israeli vendors are positioned close to this shift by default. Check Point’s threat intelligence work under Shykevich, Armis’s asset-visibility platform under Dibrov, and Sygnia’s incident response practice under Segal all sit in exactly the product categories the INCD’s doctrine change favors. None of that guarantees contract wins, but it does mean the domestic policy shift and the domestic vendor base’s product lines are pointed in the same direction, which is not always true when a government changes security doctrine.

For infrastructure operators, the harder-to-quantify cost is organizational. Containment-first security requires incident response plans that are tested, not just written, and staff who can execute them under pressure. That is a training and retention cost more than a procurement cost, and it is the piece of the 2030 plan Karadi’s timeline suggests Israel expects to take years to build, not months.

Five Predictions for the Next 12 to 24 Months

  • More national cyber agencies, particularly in the EU and among NATO members, will follow Israel’s lead and formally shift guidance from prevention-first to a stated resilience or containment standard, echoing the direction already signaled by the UK’s NCSC and the Five Eyes alliance.
  • Incident response and managed detection and response vendors, including Sygnia and comparable firms, will see demand outpace demand for pure vulnerability-scanning tools as budgets rebalance toward containment.
  • Israel’s financial sector, government institutions, and digital service providers, the three areas Karadi flagged as most targeted, will be the first to publicly report “Breach Ready” incident drills and updated response benchmarks.
  • Expect follow-up reporting on the specific AI models the INCD says are behind the acceleration; until the agency confirms names, treat any specific model attribution circulating online as unverified.
  • The State Comptroller’s findings on the IDF biometric database and Ministry of Education systems will drive targeted remediation funding before the broader 2030 plan reaches maturity, since these are the most reputationally sensitive gaps already on the public record.

What Operators Should Do Now

Security leaders reading Israel’s shift from the outside should not treat it as a call to stop patching. Vulnerability management still closes the doors attackers would otherwise walk through for free. The change is about what happens after a door gets opened anyway. Segmentation that limits how far an intruder can move, detection tuned to catch autonomous in-network movement rather than just known malware signatures, and incident response plans that have been rehearsed under realistic time pressure are the specific capabilities the INCD’s doctrine points toward. Organizations that already run regular tabletop exercises and have measured their own mean time to containment are closer to “Breach Ready” than they may realize. Organizations that have never measured it have a clear, concrete starting point.

Frequently Asked Questions

What is the Israel National Cyber Directorate (INCD)?
The INCD is Israel’s national government agency responsible for cybersecurity policy and defense of critical infrastructure and government systems.

What does “Breach Ready” mean in the INCD’s guidance?
It means organizations should assume their internal networks are already compromised and focus resources on fast detection, containment, and resumption of operations, rather than assuming prevention controls will keep every attacker out.

Why is the INCD shifting away from a prevention-first approach?
The agency says newer AI models can identify and exploit software vulnerabilities at industrial scale and speed, a pace that reports say traditional patch-and-prevent security models cannot keep up with.

What are the three pillars of Israel’s 2030 cyber defense plan?
According to Yossi Karadi, the plan rests on cloud security, cyber AI, and quantum technologies, with a target of being fully operational by 2030.

Which sectors in Israel have been targeted most over the past year?
Karadi identified the financial sector, government institutions, and digital service providers as the three most targeted areas.

What did Israel’s State Comptroller find in critical systems?
The Comptroller reported severe security flaws in systems including medical centers, energy and transportation infrastructure, the Israel Land Authority, the IDF’s biometric database, and the Ministry of Education’s matriculation exam and grades database.

How much faster is AI-assisted exploit development compared to before?
Sygnia CEO Guy Segal has said turning a previously unknown vulnerability into a working exploit, which used to take weeks, now takes hours.

Is Israel the only country moving toward a containment-first cyber doctrine?
No. The UK’s National Cyber Security Centre and the Five Eyes intelligence alliance have both issued warnings about AI accelerating the scale and speed of cyberattacks, though Israel’s INCD has gone further by formally naming a containment-first doctrine shift.