Cyberattacks against Israeli companies have tripled

Adv. Vered Zlaikha, Partner and Head of Cyber Affairs and AI Practice at Lipa Meir & Co. Advocates  credit: Roni Cohen
Adv. Vered Zlaikha, Partner and Head of Cyber Affairs and AI Practice at Lipa Meir & Co. Advocates credit: Roni Cohen

Adv. Vered Zlaikha: Directors should outline strategies and risk management in companies, with cybersecurity one of those risks that must be considered.

The Commissioner of the Privacy Protection Authority Adv. Gilad Semama told a conference earlier this month, "Since the beginning of the Swords of Iron War, we see an increase by three times in serious cyberattacks against Israeli companies. Even before the war, the data security observance in companies was not satisfying, and therefore companies and organizations must give more emphasis on compliance with the Privacy Protection Law and regulations (data security), as is relevant at the current time. A company that does not secure its data and does not comply with the provisions of the privacy protection regulations puts itself at great risk of losing its assets and collapsing."

Adv. Semama was speaking at a conference led by the Privacy Protection Authority and Israel Directors Union, regarding the new proposed instructions of the Authority on the role of the board of directors in carrying out corporate duties, in connection with privacy protection regulations (data security), which are stimulating discussions and concerns among directors in the Israeli economy.

According to the draft guidelines, published for the public’s comments in September 2023,the Privacy Protection Authority’s position is that when considering corporate governance principles and the customary division of duties between the organs of a corporation, in general the board of directors is the appropriate body to ensure the existence and performance of certain supervisory duties, imposed under the regulations on a company.

The duties the draft guidance refers to include determining the organs within the organization responsible for carrying out the regulations’ requirements, applying a mechanism for supervision, monitoring, compliance and updating on the fulfillment of the requirements under the regulations by those responsible in the organization; and setting policy decisions regarding the ways personal data is used by the organization, and the management of other material decisions in this regard.

In addition, the draft guidance suggests the board of directors will carry out directly some of the actions required under the regulations, including among other things, the approval of the database definitions document and the main principles of the organization’s data security procedure, as well as discussing risk surveys’ results and appropriate solutions to deficiencies found.

Adv. Semama said, "The area of data security supervision should also be set out before the board member who needs to display vigilance and awareness of compliance with the standards of data security regulations in the company. This would be a binding directive and not a recommendation, aimed at companies and organizations which the field of data processing is at the core of their activities, or in companies where there is a significant risk regarding privacy protection. At the moment, this is a draft regulation, and we have received public comments. Our goal is to create a fitting instruction, while at the same time, it is also important to understand that the time has come to raise the standard of data security in companies."

Directors who took part in the event raised the concern that the new instruction might assign executive duties to the board of directors, and therefore may not be applicable, while exposing them to regulatory sanctions.

Adv. Vered Zlaikha, Partner and Head of Cyber Affairs and AI Practice at Lipa Meir & Co. Advocates praised the open dialogue created by the Privacy Protection Authority with the public before publishing the instruction and set out several difficulties that may arise in her perspective regarding the PPA's draft instruction, from the board of directors’ point of view. She said, "We must understand that in the current reality, the proposed instruction is likely to apply to many organizations in the economy. Directors should outline strategies and risk management in companies, when cybersecurity is one of those risks that must be considered. In this regard, the Authority’s instructions may help to raise the board of directors’ awareness and provide them with the tools to fulfill their role. However, the draft that has been brought before the public raises concern that directors will become an executive body instead of a supervisory body in some respects.

Adv. Zlaikha also addressed the concern about the responsibility that lays with the directors for data security deficiencies. "The fact that the board of directors should be informed and supervise the company's security practices, while demonstrating proactivity in the supervision of risk surveys in the organization, does not necessarily mean that the board of directors should bear the responsibility of a database controller, according to the regulations in this context. In my opinion, the board of directors should be involved regarding deficiencies found in risk surveys, as well as oversee that a course of action to solve these data security deficiencies has been found, but the responsibility for finding solutions to deficiencies, rests with the senior management level. The difficulty is in the Authority's requirement presenting that directors bear a direct duty under the regulations if the new instruction draft is adopted as it was published.

Hadar Zofiof Hacohen, CEO of the Israel Directors Union expressed concerns about the interpretation of the corporate law as may be understood from in the document, and regarding the possible damage to corporate governance if the draft directive, is approved as published, without the relevant changes. She also stated, The Union will continue in its mission to hold meetings of this type in order to provide directors with an enabling environment for their voices to be heard both when formulating legislation or new instructions and regarding proposals for streamlining from the field to promote a transparent, credible and secure market."

Published by Globes, Israel business news - en.globes.co.il - on March 26, 2024.

© Copyright of Globes Publisher Itonut (1983) Ltd., 2024.

Adv. Vered Zlaikha, Partner and Head of Cyber Affairs and AI Practice at Lipa Meir & Co. Advocates  credit: Roni Cohen
Adv. Vered Zlaikha, Partner and Head of Cyber Affairs and AI Practice at Lipa Meir & Co. Advocates credit: Roni Cohen
Yitzhak Tshuva credit: Gidon Levy and Tali Bogdanovsky Competition Authority allows Delek takeover of Isracard

The Competition Authority is considered the easier of the two regulatory hurdles that the deal must overcome, the other being the Supervisor of Banks.

David Amsalem  credit  Noam Moskowitz, Knesset Spokesperson's Office Rafael to pay state NIS 444m dividend

The minister in charge of the Government Companies Authority, David Amsalem, has approved the payment by the defense company.

Barak MX air defense system  credit: IAI IAI profit jumps 55%

Israel Aerospace Industries posted a net profit of $493 million for 2024, and ended the year with an all-time high orders backlog of $25 billion.

A TSG system in tactical use  credit: PR TSG signs cooperation agreement with US defense co

The agreement includes the integration of TSG's advanced technologies into sensor-based defense systems, which will be integrated into the operational systems of US defense units.

Bria CEO Yair Adato credit: Kseniia Poliak Israeli visual generative AI co Bria raises $40m

Bria’s Visual Generative AI platform empowers businesses to create predictable, controllable, and on-brand content that aligns with their visual language.

Amnon Shashua and Aviram Ziv credit: Eyal Izhar OrCam stymied by investor dispute with Shashua

Demands by institutional investors are blocking the visual and hearing impairment device developer's recovery plan.

Work on the Green Line credit: Bar Lavi Egged wins tender to operate TA light rail Purple, Green Lines

NTA awarded the tender to Egged, which already operates the Red Line, despite government ministry opposition to one operator for the entire network.

Gabi Seroussi illustration: Gil Gibli Board chooses Seroussi as IAI chair as Erdan freezes candidacy

Israel Aerospace Industries board chose Gabi Seroussi as chair even though he did not to go through the preliminary process of the Government Companies Authority appointments review committee.

Bavli Park penthouse credit: Eyal Tagar Tel Aviv Park Bavli penthouse sells for NIS 43m

A 44th floor penthouse in one of the two towers in businessman Yitzhak Tshuva's Park Bavli project has been bought by an Israeli businessperson.

El Al aircraft  credit: Yoav Yaari El Al pilots receive nearly NIS 250,000 bonus each

Thanks to the agreements signed with the unions in 2018, El Al's employees as well as senior management share in last year's success.

Pentera CEO Amitai Ratzon credit: Eyal Izhar Israeli security validation co Pentera raises $60m

Pentera's platform enables security teams to analyze complete attack paths, identify root causes, and prioritize remediation for effective risk reduction.

Tel Aviv credit: Shutterstock Supply of unsold new homes hits record

Israel's real estate market is sliding into recession with 78,000 unsold new apartments in January, the Central Bureau of Statistics reports.

D&B chairman Doron Cohen and Meitar partner Dan Geva Meitar reclaims title of Israel's biggest law firm

Meitar has first place with 537 lawyers, followed by Herzog Fox Neeman with 512 lawyers, according to the latest Dun's 100 rankings.

First International Bank of Israel CEO Eli Cohen  credit: Eyal Toueg First Int'l posts top return on equity

First International Bank of Israel's return on equity in 2024 was 19%, the highest among Israel's banks.

Dina Ben Tal Ganancia  credit: Guy Kushi & Yariv Fein El Al almost quintuples profit

The airline posted a net profit of $545 million for 2024, 4.7 times the profit in 2023, and an all-time high.

Gev Hadari credit: Nati Hortig Sompo Israel appoints Gev Hadari as cybersecurity head

Hadari's expertise spans penetration testing, including Red Team operations, web applications, mobile applications, OT/IOT products, and both external and internal assessments.

Twitter Facebook Linkedin RSS Newsletters גלובס Israel Business Conference 2018