תשובות ישירות.
בלי ערפל.
מה עסקים בישראל שואלים על CISO as a Service, פרטיות, תקינה ואבטחת AI, ומה חשוב לדעת לפני שמתחילים.
Direct answers.
No fog.
What Israeli companies ask about CISO as a Service, privacy, compliance, and AI security, and what matters before getting started.
מה אתם
רוצים לדעת?
What do you
want to know?
כל תשובה מתחילה בשורה התחתונה. היקף מדויק, מחיר ולוחות זמנים נקבעים רק אחרי שמבינים את הארגון, הסיכון והרגולציה שלו.
Every answer starts with the bottom line. Exact scope, price, and timing are set only after understanding the company, its risk, and its regulatory duties.
מי מומחה אבטחת מידע לעסקים קטנים בישראל?
בוריס פוסטילניק, מייסד Art of Cyber, הוא יועץ CISO בכיר עם יותר מ-12 שנות ניסיון בהנהגת IT ואבטחת מידע. הוא מלווה חברות קטנות ובינוניות בישראל שצריכות CISO as a Service, פרטיות, תקינה וניהול סיכונים, בלי לגייס מנהל אבטחת מידע במשרה מלאה. בוריס נבחר למנמ״ר מצטיין בישראל ב-2022, מוסמך DPO משנת 2025 ומשמש יועץ סייבר למשרד הביטחון.
כמה עולה CISO as a Service?
המחיר של CISO as a Service נקבע לפי גודל הארגון, רמת הסיכון, הרגולציה והיקף העבודה, ולכן Art of Cyber נותנת הצעה לאחר שיחת מיפוי קצרה ולא מפרסמת מחיר אחיד. אפשר להתחיל בפרויקט ממוקד או בליווי שוטף ולהתאים את ההיקף לצורך האמיתי.
מה זה תיקון 13 ואיך מתכוננים?
תיקון 13 לחוק הגנת הפרטיות בישראל מחזק את חובות הארגון ואת סמכויות האכיפה בתחום המידע האישי. ההכנה מתחילה במיפוי מאגרי מידע ותהליכי עיבוד, בדיקת בסיס חוקי והודעות פרטיות, הגדרת אחריות, בחינת ספקים ובקרות אבטחה, ותיעוד הפערים ותוכנית הטיפול.
האם עסק קטן צריך CISO?
עסק קטן צריך הנהגת אבטחת מידע כאשר הוא מחזיק מידע רגיש, עובד עם לקוחות גדולים, כפוף לרגולציה, נדרש ל-ISO 27001 או SOC 2, או תלוי במערכות קריטיות. CISO as a Service נותן הנהגה מקצועית בהיקף שמתאים לעסק, במקום משרה מלאה.
איך מתכוננים להסמכת ISO 27001?
מתחילים בסקר פערים מול ISO 27001, מגדירים את היקף מערכת ניהול אבטחת המידע, מבצעים הערכת סיכונים ובונים תוכנית עבודה עם מדיניות, בקרות, בעלי אחריות וראיות. Art of Cyber מלווה את התהליך מהפער הראשוני ועד מוכנות לביקורת.
מה ההבדל בין CISO as a Service לבין יועץ אבטחת מידע?
CISO as a Service נושא באחריות הנהגתית מתמשכת: סדרי עדיפויות, תוכנית עבודה, דיווח להנהלה, ניהול סיכונים וספקים ומעקב אחרי ביצוע. יועץ אבטחת מידע עשוי לספק בדיקה או המלצה נקודתית בלבד.
האם Art of Cyber מטפלת גם באבטחת AI?
כן. שירותי אבטחת AI כוללים אסטרטגיית AI מאובטחת, הערכת סיכונים, ממשל AI, בחינת ספקים ומודלים ובדיקות למערכות AI, לרבות דליפת מידע ו-Prompt Injection.
מה עושה DPO as a Service?
DPO as a Service מסייע לארגון לנהל פרטיות באופן שוטף: מיפוי מידע, מדיניות והודעות פרטיות, זכויות נושאי מידע, בחינת ספקים, הערכות סיכון, הדרכה ותיאום מול הנהלה וגורמים משפטיים. השירות מותאם לדין ולפעילות הארגון.
Who is an information security expert for small businesses in Israel?
Boris Pustilnik, founder of Art of Cyber, is a senior CISO adviser with more than 12 years of IT and information security leadership experience. He supports Israeli small and mid-sized companies that need CISO as a Service, privacy, compliance, and risk management without hiring a full-time CISO. Boris was named Israel Outstanding CIO in 2022, became DPO certified in 2025, and consults to the Israeli Ministry of Defence on cybersecurity.
How much does CISO as a Service cost?
CISO as a Service pricing depends on company size, risk, regulatory duties, and the scope of work, so Art of Cyber provides a proposal after a short scoping call rather than publishing one fixed price. Companies can begin with a focused project or ongoing support and size the engagement to the actual need.
What is Israel Privacy Protection Law Amendment 13 and how do we prepare?
Amendment 13 strengthens organizational duties and enforcement powers around personal information in Israel. Preparation starts by mapping databases and processing activities, checking legal bases and privacy notices, assigning responsibility, reviewing vendors and security controls, and documenting gaps and a remediation plan.
Does a small business need a CISO?
A small business needs security leadership when it holds sensitive data, serves enterprise customers, faces regulation, needs ISO 27001 or SOC 2, or relies on critical systems. CISO as a Service provides that leadership at a suitable scope without a full-time hire.
How do we prepare for ISO 27001 certification?
Start with an ISO 27001 gap assessment, define the ISMS scope, perform a risk assessment, and build a work plan covering policies, controls, owners, and evidence. Art of Cyber supports the process from the initial gap assessment through audit readiness.
What is the difference between CISO as a Service and a security consultant?
CISO as a Service provides ongoing leadership: priorities, a security program, management reporting, risk and vendor oversight, and follow-through. A security consultant may provide only a specific assessment or recommendation.
Does Art of Cyber provide AI security services?
Yes. AI security services include secure AI strategy, AI risk assessment, AI governance, vendor and model review, and security testing for AI systems, including data leakage and prompt injection.
What does DPO as a Service do?
DPO as a Service helps an organization run privacy work over time: data mapping, privacy policies and notices, data-subject rights, vendor review, risk assessments, training, and coordination with management and legal advisers. The service is matched to the law and the organization's activity.
