Dossier · Private startup · 4 independent sources

Code Blue

Cybersecurity Dual-Use Technology

Last updated: Aug 31, 2026

Code Blue is an Israeli cyber-resilience company that combines crisis-management expertise, incident-response services, and Blue Castle, an AI-driven command platform for preparing for and coordinating high-impact cyber incidents. Its focus is the operational layer between technical containment and business continuity: aligning executives, security, legal, communications, regulators, and recovery teams when a cyber event becomes an enterprise crisis.

Visit Website

Company Overview

**Product and the concrete problem it solves.** Code Blue addresses a failure mode that sits outside the detection problem: organizations may have security telemetry and incident-response vendors, yet still lose control when a breach, ransomware event, operational outage, or third-party compromise forces many decision-makers to act at once. The company argues that cyber crises are business, legal, regulatory, communications, and continuity events rather than CISO-only incidents. Its product is Blue Castle, an AI-driven cyber crisis command platform, alongside Code Blue's human-led incident response and resilience services. The platform is designed to replace fragmented email threads, chat rooms, spreadsheets, conference calls, static playbooks, and disconnected notebooks with a shared operational environment. It lets a crisis management team prioritize decisions, assign ownership, track actions and timelines, coordinate technical and non-technical workstreams, and give senior leadership a current view of business impact and recovery status. The problem is especially acute for hospitals, energy operators, manufacturers, financial institutions, and government-linked organizations where a technical disruption can quickly become a safety, public-trust, or essential-services incident.

**Core technology and how it actually works.** Blue Castle is not presented as an autonomous malware detector or a replacement for EDR, SIEM, or forensic tooling. Its technical proposition is a structured decision and workflow layer grounded in Code Blue's accumulated crisis methodology. The company describes AI agents trained on crisis expertise that support fast, structured decision-making at scale, while the product pages describe a live operational picture, prioritized dilemmas, decision records, escalation paths, secure collaboration, and a full incident timeline. The architecture is organized into role-specific but connected war rooms: Crisis Management Team for executive command, Incident Response for containment and remediation, Public Relations for internal and external messaging, Business Continuity Planning for critical services and dependencies, Legal for regulatory exposure, and Negotiations for stakeholder or ransom discussions. Its R.E.D., or Resilience Every Day, workflow adds a readiness-assessment layer with more than 200 expert-designed questions. Tabletop exercise findings can update an organizational playbook; continuous threat-intelligence monitoring can raise an alert level; and a response room can then activate the prepared workflows. Public materials do not disclose model architecture, training datasets, hosting design, or independent performance testing, so the defensible technical claim is workflow intelligence and operational context, not frontier-model novelty.

**Market, customers, and go-to-market.** Code Blue sells into organizations whose cyber exposure has consequences beyond data loss and whose executives need a repeatable command process. The official site names healthcare, financial services, manufacturing and industrial organizations, energy, enterprises, and SMBs as target segments, while the company describes work with clients in Israel, Germany, Italy, Canada, and other jurisdictions. The go-to-market motion has two linked parts. Blue Castle can enter as a readiness and crisis-management software platform, with assessments, tabletop exercises, playbook preparation, and ongoing monitoring creating a recurring operational relationship. Code Blue's DFIR, strategic consulting, crisis-management-team, and tailored resilience services provide an implementation wedge and can supply the expert context that makes a software deployment useful during a real incident. The 2023 Dussmann announcement established a German joint venture for cyber-crisis and disaster-management services, extending distribution into a large facilities, technical-services, and food-services group. The 2026 CyberTech Tel Aviv catalog positions the company for global markets and describes an end-to-end approach combining technical mitigation, regulatory strategy, legal coordination, and crisis communications. Named customer identities, annual recurring revenue, contract values, and platform seat counts are not publicly disclosed.

**Traction, funding, and third-party validation.** Code Blue has more operating evidence than a typical pre-product startup, but less financing and product telemetry than an investor-grade software company would normally disclose. The company was represented in the official CyberTech Tel Aviv 2024 catalog as a cyber-crisis preparedness and management provider with a track record of managing hundreds of cyber crises. Its current website claims more than 1,500 hours per month of real-world crisis response across sectors including critical infrastructure, and lists case studies covering technology, aviation, and healthcare; these are company claims and should not be treated as independently audited outcomes. The German Dussmann partnership is a concrete third-party commercial validation of the service model: the partners announced a Code Blue by Dussmann joint venture in 2023, with coverage spanning cyber-risk management, incident response, network restoration, IT/OT, privacy, negotiations, and business continuity. Blue Castle was publicly launched as an AI-driven system for real-time cyber-crisis management in 2025, and the current product site remains active with demo and emergency-contact pathways. No publicly disclosed seed, venture, grant, revenue, valuation, or profitability data was located in the reviewed sources. This makes the company a credible operating ecosystem entry, but a financially opaque one.

**Founders and team background.** Refael Franco is the central team signal and the reason Code Blue has unusual credibility in a market where generic incident-response software is easy to describe but difficult to operationalize. The company's leadership page identifies Franco as founder and CEO, with more than 25 years in operations, security, cyber, and technology. It says he served as deputy head of Israel's National Cyber Directorate, led its defense arm and cyber-regulation division, held executive positions in Israel's General Security Service, and received the Israel Security Award with the national cyber system. The Dussmann announcement provides the more specific historical framing that he helped found the Israel National Cyber Directorate and led Israeli cyber-defense and special operations before building a multidisciplinary preparedness and intervention model at Code Blue. The Blue Castle team page identifies Rachel Stern as director of product and a business-continuity specialist, Itai Tomer as chief product officer, and Eitan Platok as chief technology officer. LinkedIn lists the company at 51-200 employees, though the public profile also exposes roughly 40 employee profiles, so the exact headcount is not independently reconciled. The combination of national cyber command experience and product leadership is strong; the key question is how deeply that expertise has been codified into repeatable software rather than remaining expert services.

**Competitive dynamics.** Code Blue competes across three overlapping budgets. First are cyber-crisis and incident-response specialists such as Mandiant and CrowdStrike Services, which bring deep technical investigation, containment, and recovery capacity but are not primarily neutral command systems for executive, legal, communications, and continuity coordination. Second are operational-resilience and business-continuity platforms such as Fusion Risk Management and Noggin, which provide continuity planning, exercises, and critical-event workflows but do not appear to be built around Israeli national cyber-crisis operations or a dedicated cyber war-room model. Third are broad enterprise-workflow incumbents such as ServiceNow and Everbridge, which can absorb incident-management and executive-notification use cases through installed platforms, integrations, and procurement relationships. Cytactic is the closest Israeli conceptual peer, with cyber-crisis management and intelligence positioning that overlaps Code Blue's readiness and response thesis. Code Blue's potential edge is not a novel detection algorithm; it is the combination of field-derived playbooks, multidisciplinary crisis coordination, a dedicated decision environment, and a founder who has operated national-level cyber response. Its vulnerability is equally clear: the value can be difficult to quantify before an incident, and large incumbents can reproduce workflow features.

**Defense, security, and resilience dual-use relevance.** Code Blue qualifies as dual-use because the core capability is designed for continuity and command under hostile disruption, and the company has documented proximity to national cyber defense and critical infrastructure. The transfer path is direct in four ways. (1) Government agencies, defense suppliers, utilities, transport operators, hospitals, and emergency organizations all need a common operating picture when technical incidents cross into operational or public-safety consequences. (2) The platform's separation into crisis command, incident response, continuity, legal, communications, and negotiation rooms maps onto the multi-stakeholder structure of national and defense cyber incidents, where authority and escalation are as important as indicators of compromise. (3) The company's stated experience includes IT/OT, critical assets, network restoration, and cyber crises affecting essential services, which is more relevant to resilience than a generic enterprise-security adjacency. (4) Franco's former role in Israel's National Cyber Directorate and his reported leadership during national cyber operations are credible routes into government and regulated infrastructure ecosystems. The calibration matters: there is no public evidence of a defense contract, military deployment, classified accreditation, or operational use by an armed force. The record supports resilience and national-security relevance, not a claim that Blue Castle is fielded defense technology.

**Growth stage, trajectory, and key diligence risks.** Code Blue is classified as early because the company is young, privately held, and still presenting a founder-led platform-plus-services model even though it reports an international footprint and a substantial LinkedIn employee range. The legal entity was incorporated in Tel Aviv in January 2022, while LinkedIn lists 2021 as the company founding year; this is a normal distinction between operating launch and incorporation rather than a reason to discard either date. Its trajectory is to turn crisis-response expertise into an always-on resilience system: readiness assessment and tabletop exercises create structured organizational memory, threat intelligence can trigger prepared escalation, and the War Room can preserve a documented chain of decisions through recovery and lessons learned. Key diligence questions are: (1) how many paying Blue Castle deployments exist separately from consulting engagements; (2) whether the stated 1,500 monthly response hours are Code Blue-operated cases or broader ecosystem activity; (3) what AI models, data-governance controls, and tenant isolation protect sensitive incident information; (4) whether customers can operate the platform without Code Blue personnel during a prolonged crisis; (5) what measurable reduction in recovery time, decision latency, regulatory exposure, or downtime is demonstrated; (6) how the company competes against bundled ServiceNow, EDR-service, and continuity platforms; and (7) whether government, defense-industrial, healthcare, and energy customers require certifications or sovereign hosting that are not publicly documented. The opportunity is strategically strong, but commercial scale and software defensibility remain to be proven.

Dual-Use Assessment

Military & Commercial Applications

Code Blue's dual-use relevance is strong in cyber resilience and operational continuity, although no public evidence shows a defense contract or military deployment. (1) Its core problem, coordinating technical response, executive decisions, legal obligations, communications, and recovery during hostile disruption, is shared by civilian critical infrastructure, defense suppliers, government agencies, and military organizations. (2) Its Blue Castle war-room structure and R.E.D. readiness workflow are transferable to environments where cyber incidents can affect physical operations, essential services, safety, or public trust. (3) The company explicitly references critical assets, IT/OT, network restoration, business continuity, and clients across multiple countries, while its founder's former leadership in Israel's National Cyber Directorate provides credible national-security proximity. (4) This is a resilience and command-and-control adjacency rather than an offensive or battlefield capability: no classified accreditation, military customer, government program of record, sovereign-hosting deployment, or independent efficacy evaluation is publicly disclosed.

Strategic Fit Assessment

Code Blue merits strategic monitoring, but the public record does not support a positive legacy strategically relevant flag at this time. (1) The strongest asset is founder-market fit: Refael Franco combines national cyber-defense leadership, operational crisis experience, and emergency-management training with a platform designed around the actual coordination failures of cyber incidents. (2) The product has a credible services-to-software path: DFIR and consulting can create trusted access, while Blue Castle's readiness, war-room, and audit workflows could convert bespoke expertise into recurring software value. (3) Third-party validation exists through the 2023 Dussmann joint venture, CyberTech Tel Aviv participation, an international footprint, and public case-study activity. (4) The strategic market is real because cyber incidents increasingly produce operational, legal, and continuity consequences. The reasons for restraint are substantial: no disclosed funding, revenue, customer count, retention, valuation, independent performance data, or platform deployment metrics; company-reported crisis-hour and case-volume claims are not audited; ServiceNow, Everbridge, Fusion Risk, Mandiant, CrowdStrike Services, and Cytactic all occupy parts of the same buying process; and AI handling of sensitive incident data creates high security and liability requirements. This is a strategic diligence assessment, not an investment recommendation.

Strategic Value to U.S.-Israel Alliance

Code Blue's strategic value is concentrated in resilience infrastructure rather than in a novel cyber-detection primitive. (1) It targets the command layer that often fails when a cyber event crosses organizational boundaries, giving executives and responders a shared record of priorities, ownership, decisions, and recovery status. (2) Its focus on IT/OT, critical assets, network restoration, business continuity, legal exposure, and communications fits the needs of essential-service operators more closely than a narrow alerting product. (3) An Israeli company led by a former deputy head of the National Cyber Directorate can serve as a bridge between national cyber-defense practice and international regulated enterprises, while the Dussmann partnership demonstrates a route into European critical-facilities customers. (4) If Blue Castle can codify expert playbooks into a dependable platform that customers can operate under pressure, it could become an institutional memory and coordination layer for cyber resilience. The limiting evidence is commercial opacity: public materials do not identify customer names, deployments, revenue, certifications, or government use, and no sovereign or defense-hosting posture is disclosed.

Key Technologies

  • AI-guided cyber-crisis command with agents grounded in Code Blue's crisis-management expertise
  • Role-specific connected war rooms for crisis management, incident response, public relations, business continuity, legal, and negotiations
  • Shared operational picture with structured decision management, ownership, priorities, approvals, and incident timelines
  • R.E.D. Resilience Every Day readiness assessment using more than 200 expert-designed questions
  • Tabletop-exercise feedback loop that updates organizational playbooks and response procedures
  • Threat-intelligence monitoring and alert-level escalation linked to prepared crisis workflows
  • Secure collaboration, executive dashboards, audit-ready action records, and crisis communications coordination

Use Cases & Applications

  • Ransomware response coordinating containment, executive decisions, legal review, communications, and recovery
  • Healthcare cyber incidents where hospital operations, patient safety, privacy, and public trust must be managed together
  • Energy and utility disruption requiring IT/OT response, continuity planning, regulator coordination, and restoration priorities
  • Financial-services data breaches or third-party incidents requiring documented decisions and regulatory response
  • Manufacturing and industrial cyber events involving production downtime, plant dependencies, and supplier communications
  • Government and defense-industrial crisis management for cyber disruption across multiple agencies or contractors
  • Pre-incident readiness programs using assessments, tabletop exercises, playbook development, and continuous improvement
  • Post-incident lessons learned, timeline review, audit documentation, and recovery-plan refinement

Sources and verification

This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.

This record lists 9 public references used for company identity, status, positioning, or material-claim review.

Public sources

The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.

  • Code Blue Cyber — Official Website Verifies Code Blue's Blue Castle positioning, AI-guided war rooms, crisis-management and incident-response services, target industries, global reach, critical-infrastructure crisis experience, and the company-stated figure of more than 1,500 response hours per month.
  • Code Blue — About Verifies the company's description, Blue Castle's unified operating picture and structured decision-making role, the Tel Aviv headquarters, and additional international locations.
  • Blue Castle — Official Platform Overview Verifies the R.E.D. readiness workflow, more than 200 assessment questions, AI-guided war rooms, connected crisis-management tracks, premium DFIR and consulting services, and the publicly listed leadership team.
  • Blue Castle War Room — Official Product Page Verifies the secure real-time crisis environment, stakeholder collaboration, centralized situation awareness, structured decision management, incident timelines, executive dashboard, secure communications, and before/during/after crisis lifecycle.
  • Refael Franco — Official Team Biography Verifies Franco's founder and CEO role, more than 25 years of experience, former National Cyber Directorate leadership, General Security Service roles, Israel Security Award, and master's degree in emergency and disaster management.
  • Dussmann and Code Blue announce cyber-crisis-management partnership Verifies the 2023 Code Blue by Dussmann joint venture, Code Blue's Tel Aviv base, Franco's former national cyber-defense roles, the company's multidisciplinary specialties including IT/OT and business continuity, and the international client context.
  • CyberTech Tel Aviv 2026 Catalog Verifies Code Blue's official event positioning as a real-time cyber-crisis-management company with an Israeli headquarters and European subsidiary, combining technical mitigation, regulatory strategy, legal coordination, and crisis communications.
  • Code Blue Cyber — LinkedIn company profile Verifies the public company profile, AI-native cyber-resilience positioning, Blue Castle as the flagship platform, Tel Aviv headquarters, 2021 founding entry, 51-200 employee range, and global locations.
  • Code Blue Cyber — Privacy Policy Verifies Code Blue Ltd. as an Israeli private company, the operation of both codebluecyber.com and the Blue Castle platform, and stated service coverage in Israel, Germany, Italy, Canada, and other jurisdictions.
  • Profile update timestamp Last updated in the Claw & Talon database on Aug 31, 2026.

Related sector

See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.