Government bill · 25th Knesset · published as law 14 August 2025
חוק התמודדות עם תקיפות סייבר חמורות במגזר השירותים הדיגיטליים ושירותי האחסון (הוראת שעה – חרבות ברזל) (תיקון מס' 3), התשפ"ה-2025Law for Countering Severe Cyber Attacks in the Digital Services and Storage Services Sector (temporary provision – Swords of Iron) (Amendment No. 3), 2025 · automatic translation · suggest a correction
Status: התקבלה בקריאה שלישית
Topics: Military and defense*, Communications, media and technology*, Emergency, war and COVID* · * from the Knesset's official law classification
Official summary of the law (Knesset)
The Law on Dealing with Severe Cyber Attacks in the Digital Services and Storage Services Sector, 2023, is intended to provide the National Cyber Directorate and security bodies with tools for detecting, preventing, and containing cyber attacks against companies providing digital services and storage services. The Law was originally enacted as a temporary provision linked to the "Swords of Iron" war, with the aim of protecting state infrastructure, public bodies, and security bodies from harm. Now, as part of Amendment No. 3 to the Law, 2025, the temporary provision has been disconnected from its link to significant military operations, so that the arrangement will continue to remain in effect regardless of the fighting situation, and accordingly the words "Swords of Iron" were deleted from the Law's title. The validity of the temporary provision was extended until 31 January 2026. As part of the amendment, an authorized manager was empowered to require a provider to present any information or document, including computer output, if there is a reasonable basis to assume that a severe cyber attack against the provider or through it is occurring or is about to occur. In addition, an obligation was established for a provider to report significant attacks to the Cyber Directorate. Furthermore, a provider that has been attacked was obligated to immediately notify connected organizations that may be directly harmed by the attack, unless an authorized body instructs otherwise. To ease the burden on providers, the amendment establishes an expanded list of international information security standards that allow a provider to receive exemption from most of the obligations under the Law, if it declares that it complies with them. Finally, the periodic reporting obligation to the Knesset Foreign Affairs and Defense Committee was expanded to include data on the number of information requests directed to providers, the number of self-reports received, and the number of cases in which a provider was prohibited from updating a connected organization about an attack.
automatic translation · suggest a correction
Hebrew original
חוק התמודדות עם תקיפות סייבר חמורות במגזר השירותים הדיגיטליים ושירותי האחסון, התשפ"ד-2023, נועד להקנות למערך הסייבר הלאומי ולגופי הביטחון כלים לאיתור, מניעה ובלימה של תקיפות סייבר נגד חברות המספקות שירותים דיגיטליים ושירותי אחסון. החוק נחקק במקור כהוראת שעה בזיקה למלחמת "חרבות ברזל" במטרה להגן על תשתיות מדינה, גופים ציבוריים וביטחוניים מפני פגיעה. כעת, במסגרת תיקון מס' 3 לחוק, התשפ"ה-2025, נותקה הוראת השעה מהזיקה לפעולות הצבאיות המשמעותיות, כך שההסדר ימשיך לעמוד בתוקפו ללא תלות במצב הלחימה, ובהתאם לכך נמחקו המילים "חרבות ברזל" משם החוק. תוקפה של הוראת השעה הוארך עד ליום י"ג בשבט התשפ"ו (31 בינואר 2026). במסגרת התיקון, הוסמך מנהל מוסמך לדרוש מספק להציג לו כל ידיעה או מסמך, לרבות פלט מחשב, אם ישנו יסוד סביר להניח שמתרחשת או עומדת להתרחש תקיפת סייבר חמורה נגד הספק או באמצעותו. בנוסף, נקבעה חובת דיווח של ספק למערך הסייבר על תקיפות משמעותיות. כמו כן, הוטלה על ספק שהותקף חובה ליידע באופן מיידי ארגונים מקושרים שעלולים להיפגע ישירות מהתקיפה, אלא אם כן הורה גורם מוסמך אחרת. כדי להקל על ספקים, התיקון קובע רשימה מורחבת של תקני אבטחת מידע בין-לאומיים שמאפשרים לספק לקבל פטור ממרבית החובות בחוק, אם יצהיר שהוא עומד בהם. לבסוף, הורחבה חובת הדיווח העיתית לוועדת החוץ והביטחון של הכנסת, כך שתכלול גם נתונים על מספר דרישות המידע שהופנו לספקים, מספר הדיווחים העצמיים שהתקבלו ומספר המקרים שבהם נאסר על ספק לעדכן ארגון מקושר בדבר תקיפה.
Readings
- Bill passed first reading5 for · 0 against · 2 abst.
- Law passed16 for · 0 against
Reservations, sections and other votes (1)
In order. Votes on reservations and individual sections are shown separately from the vote on the bill as a whole.
- 13 August 2025 · Second reading · סעיפים 1-13הצעת חוק התמודדות עם תקיפות סייבר חמורות במגזר השירותים הדיגיטליים ושירותי האחסון (הוראת שעה – חרבות ברזל) (תיקון מס' 3), התשפ"ה-2025Bill for Countering Severe Cyber Attacks in the Digital Services and Storage Services Sector (temporary provision – Swords of Iron) (Amendment No. 3), 2025auto15 for · 0 againstVote on sections of the bill