Lee Moser and Gil Geron.

America’s new cyber strategy could be a big opportunity for Israeli companies

The White House is creating a framework for private firms to conduct active operations against transnational criminals, while Israeli companies may have an advantage in intelligence, data and cyber technology. 

The US government is changing the rules of the game in the fight against cybercrime. A new White House memorandum establishes a program that will allow private American cybersecurity companies to conduct active cyber operations against transnational criminal organizations, including intelligence gathering and operations designed to disrupt, damage or disable computer systems, all under the control, supervision and approval of the US government.
The move is intended to harness the technological capabilities, speed and innovation of the private sector to combat fraud, cybercrime and threats to US citizens, businesses and national security.
3 View gallery
גיל גרון, מנכ"ל ומייסד משותף באורקה סקיוריטי, ולי מוזר, מייסדת שותפה בקרן Protego
גיל גרון, מנכ"ל ומייסד משותף באורקה סקיוריטי, ולי מוזר, מייסדת שותפה בקרן Protego
Lee Moser and Gil Geron.
(Photos: Orca Security, Adi Eckstein)
The program will be managed by the National Coordination Center (NCC). Private companies selected to participate will undergo a strict screening process and operate under procedures to be established by the Department of Justice and the Department of Homeland Security. Each operation will require prior written approval and will be conducted on behalf of the US government and under its legal authority.
Participating companies will also be able to receive threat information from private companies and government agencies and use that information to propose cyber operations against criminal organizations.
The scope of the permitted activities is broad. “Cyber surveillance operations” will allow companies to collect information and intelligence from systems without the authorization of their owners, while “cyber influence operations” include the manipulation, disruption, prevention, damage or disabling of information systems and infrastructure.
The framework does, however, set limits. Actions likely to cause death or serious injury, or that would constitute a use of force or an armed attack under international law, cannot be approved.
For Israel’s cyber industry, the move could be particularly significant.
According to Lee Moser, founding partner at the VC fund Protego Ventures, one of the most striking aspects of the memorandum is its explicit reference to small and agile companies.
“This is the first time we have seen an American security document that explicitly requires allowing entry to small and agile companies, and not just giants,” she said. In her view, the language reflects a recognition that “the adversary is advancing at the pace of a startup, and therefore defense must also.”
Moser believes the opportunity extends beyond companies that directly conduct cyber operations.
“For those who build the automation and audit layer on top of the offensive capability today, a market is opening up here that did not exist a week ago,” she said.
The key point for Israeli companies is that the memorandum currently defines eligible participants as private American companies. But Moser believes Israeli companies could have a structural advantage because many are incorporated in the US from the outset.
“A large part of our companies are incorporated in the US from the start, unlike markets in Europe and Asia that tend to remain local,” she said.
That does not constitute an automatic entry ticket. The precise criteria for participation are still to be determined in procedures expected to be published within 60 days. But US incorporation could give some Israeli companies a potentially stronger starting position.
Moser also points to an opportunity at the intelligence and data layer. The program allows participating companies to receive threat information from private and government entities and use it to propose operations to the NCC.
From the perspective of the Israeli industry, she said, this could create a significant market because “Israeli industry is particularly strong” in intelligence and data.
Companies seeking to participate will also have to meet federal requirements, including FedRAMP certification, which is used to authorize cloud products and services for use by the US government.
Israel has a broad range of cybersecurity companies operating in these areas, including firms developing new capabilities using artificial intelligence. The new framework could therefore create opportunities beyond the relatively small group of companies focused directly on offensive cyber operations.
3 View gallery
אריק קליינשטיין
אריק קליינשטיין
Arik Kleinstein.
(Photo: Mari Ron)
Arik Kleinstein, managing partner at Glilot Capital, also sees the memorandum as a significant change in the way the US government views the role of private cybersecurity companies.
The framework could open the door to integrating private-sector capabilities into active cyber operations, he said, but primarily for mature companies that have already demonstrated experience working with the US government and met stringent security, compliance and trust requirements.
Who bears the risk?
Alongside the potential business opportunity, however, Kleinstein sees fundamental questions about responsibility and risk.
When a private company conducts an active operation against infrastructure in another country, the line between an anti-crime operation and an incident with national or diplomatic consequences can become thin.
The government will therefore have to determine who bears responsibility if an operation causes unexpected damage, affects a third party or triggers retaliation against the company involved.
3 View gallery
שי מישל שותף מנהל בקרן ההשקעות מרלין ונצ'רס
שי מישל שותף מנהל בקרן ההשקעות מרלין ונצ'רס
Shay Michel.
(Photo: Orel Cohen)
“The US does not have to choose between sovereign control and innovation that comes from its allies,” said Shay Michel, a partner at Merlin Ventures.
“Israel has spent decades building cyber capabilities and technologies in an environment where threats are operational and real, not theoretical,” he said. “This memorandum presents a correct model: the American government retains the authority and control, while trusted private companies bring speed, expertise and advanced technology.”
Michel said the relationships developed between the US and Israeli technology sectors could serve as a bridge between American security needs and Israeli capabilities developed under real operational pressure.
The American move also comes against the backdrop of the rapid development of artificial intelligence, which is changing the economics and speed of cyber operations.
Gil Geron, CEO and co-founder of Orca Security, believes the memorandum could signal a broader shift in how Western governments respond to cyber threats.
The decision to enlist private companies for active operations reflects an understanding that the technological capabilities and speed of the private sector have become strategic assets that governments cannot afford to ignore, he said.
Attackers and criminal groups can increasingly use AI to accelerate processes that previously required significant time and resources. Geron said the US government understands that the state cannot compete with this pace on its own and is therefore looking for ways to connect the speed and capabilities of private companies with government infrastructure.
At the same time, he believes AI could ultimately strengthen defenders more than attackers, in part because one of the biggest challenges is the enormous increase in the number of assets, services and systems exposed to the internet.
For Israel, the potential opportunity therefore extends well beyond companies that conduct cyber operations themselves. The new framework could create demand for intelligence, data, automation, auditing, control systems and technologies that allow governments to deploy private-sector capabilities while maintaining oversight.
The advantage of Israeli companies may lie not only in their ability to conduct cyber operations, but also in the technological infrastructure surrounding them, particularly among companies that have already established a legal, commercial and technological presence in the US.
But the road from a White House memorandum to an operating system is still long. Detailed participation procedures are expected within 60 days and will have to define eligibility requirements, security standards, approval processes and the division of responsibility between the government and private companies.
If the framework develops into a permanent operating model, it could change not only the way the US government fights cybercrime, but also the opportunities available to Israeli cybersecurity companies seeking a larger role in the American market.