Cyber 2.0
Last updated: Jul 31, 2026
Cyber 2.0 develops network-containment software and gateways intended to stop cyberattacks from spreading after an initial compromise. Its portfolio targets enterprise IT, industrial OT/IoT, and connected-vehicle environments through a combination of allow-listing, port scrambling, and isolation controls.
Visit WebsiteCompany Overview
Cyber 2.0's product thesis is that an organization should be able to limit attack propagation even when the first endpoint has been compromised and the malicious process is unknown. The company describes Cyber2IT as an IT network product and Cyber2OT as an OT/IoT product; it also markets protection for connected cars. Public product material describes a Chaos Engine or Containment Engine that continually changes communication ports and a Dynamic List that allows approved software or communication behavior while restricting unknown activity. The Vortex Gateway extends the model to devices that cannot run an endpoint agent, including industrial controllers and other embedded or legacy equipment. These are vendor-described capabilities, so the database should treat claims such as “total” or “unbreakable” protection as positioning rather than independently established performance.
The commercial opportunity spans three difficult but related environments. In enterprise IT, the value proposition is reducing ransomware and worm blast radius after EDR, antivirus, identity, or firewall controls have missed an event. In OT and IoT, the proposed advantage is protecting controllers and legacy devices without changing the device software or interrupting deterministic operations. In connected vehicles, the relevant buyer problem is controlling communication among ECUs, telematics systems, and gateways. Each market has different deployment, safety, and evidence requirements; success in one should not be assumed to transfer automatically to the others. OT buyers will want deterministic failure behavior, maintenance procedures, segmentation evidence, and integration with existing monitoring, while automotive buyers will require extensive validation and supply-chain acceptance.
Cyber 2.0 competes across overlapping categories rather than against one identical product. Illumio and Akamai Guardicore represent policy-driven segmentation and workload isolation; Dragos, Claroty, and Nozomi Networks represent OT visibility and detection; firewalls, NAC, EDR/NDR, and unidirectional gateways are important substitutes. The company's differentiation is the attempt to make containment itself the primary control, using dynamic port scrambling and an allow-list model instead of relying only on threat signatures or behavioral detection. A 2024 Frost & Sullivan award document describes the Containment Engine and Vortex Gateway, references nine patents, and cites customer testimonials, but it is not a substitute for audited revenue, independently reproducible testing, or a full customer reference list. Current LinkedIn activity and hiring indicate an operating commercial team, while public sources do not establish scale, retention, or broad production adoption.
The dual-use case is substantive because the underlying problem is shared by civilian critical infrastructure and defense networks: an initial foothold must not become access to the rest of the environment. Potential defense and national-security applications include protecting logistics and maintenance networks, limiting propagation across defense-industry partner environments, and isolating compromised systems in utilities or other critical services. This is a technology adjacency, not evidence of classified deployment or government contracting. Sensitive customers would need to validate the cryptographic and operational properties of port scrambling, understand how authorized traffic is maintained, test loss-of-control and recovery scenarios, and confirm that the gateway cannot itself become a high-impact choke point. The most important diligence question is whether the system produces measurable containment and availability benefits under realistic, independently designed attack and safety tests.
Dual-Use Assessment
Cyber 2.0's network-containment and gateway technology has credible commercial and defense applicability because both enterprise and mission-critical networks need to limit lateral movement after an initial compromise. The defense case is prospective: no public evidence here proves classified deployment, government contracts, or military validation, and high-assurance adoption would require independent testing, accreditation, resilient failover, and proof that containment cannot disrupt safety-critical operations.
Strategic Fit Assessment
Priority signal means this entry may be worth researching within the Claw & Talon thesis. It does not mean investable, suitable, endorsed, available, or likely to produce returns.
Cyber 2.0 is relevant to strategic diligence because it focuses on a persistent failure mode in cybersecurity: attackers can spread after perimeter and detection controls are bypassed. Its product claims, patents, current commercial activity, and 2024 OT-security recognition support a credible technology thesis, but public evidence is insufficient to establish revenue scale, funding depth, customer concentration, renewal rates, or independently measured efficacy. The key diligence work is to validate deployment friction, false-blocking rates, recovery behavior, integration with EDR/NDR and OT monitoring, and the repeatability of outcomes across more than one vertical. The legacy strategically relevant flag reflects strategic fit, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
The company addresses a strategically important layer of cyber resilience: limiting the blast radius of an intrusion in connected enterprise, industrial, and vehicle environments. Its potential value is highest where legacy equipment, air-gapped or intermittently connected networks, and safety constraints make agent deployment or rapid patching difficult. Strategic significance remains conditional on proof that the system interoperates with existing security operations, fails safely, and can be administered at scale; the record should not imply current defense adoption.
Key Technologies
- Chaos-model-based port scrambling and moving-target defense
- Dynamic allow-list or approved-software control
- Agent-based enterprise network containment
- Vortex Gateway for agentless legacy and OT devices
- Network access control and micro-segmentation
- Remote tracking, audit visibility, and containment telemetry
Use Cases & Applications
- Contain ransomware and worm propagation after an enterprise endpoint is compromised
- Restrict unknown software from using internal network paths in data-center and cloud estates
- Protect PLC, SCADA, and other controller communications without installing software on the controller
- Add a gateway control layer for legacy OT, IoT, and embedded devices
- Limit communication among connected-car ECUs, telematics, and vehicle gateways
- Isolate compromised systems in hybrid IT/OT incident response
- Reduce lateral-movement exposure across defense-industrial-base and critical-infrastructure partner networks
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work.
This record lists 5 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- cyber20.com Public source used for profile verification.
- cyber20.com Public source used for profile verification.
- LinkedIn company page Public source used for profile verification.
- israeltrade.org.au Public source used for profile verification.
- trademarks.justia.com Public source used for profile verification.
- Profile update timestamp Last updated in the Claw & Talon database on Jul 31, 2026.
Investor Lens
What this entry is
Private startup
Why it may matter
Cyber 2.0 may matter as a Cybersecurity entry with not currently an investable standalone company for Israeli technology research.
How an independent investor should read this
Not currently an investable standalone company. Read this profile as a starting point for independent verification, not as a recommendation or suitability assessment.
Evidence to verify
- Verify current status
- Verify traction
- Verify cap table/funding
- Verify technical claims
- Verify regulatory/export-control issues
- Verify customer concentration
Main investor questions
- Is the company currently active, independently financeable, and raising or not raising on terms you can verify?
- What customer, revenue, product, and technical evidence supports the company story?
- What valuation, cap table, rights, and follow-on assumptions would govern any private exposure?
- Does the dual-use claim map to actual commercial and government/defense/resilience buyer evidence?
- What evidence would change the thesis or show that the profile is stale?
What not to infer
- Inclusion does not imply endorsement.
- Inclusion does not imply allocation availability or current fundraising.
- Scores do not indicate investment suitability or expected returns.
- Strategic importance does not automatically imply venture return potential.
Diligence questions
- What evidence verifies Cyber 2.0's current customer traction, deployment status, and revenue concentration?
- Which technical claims are independently demonstrable today, and which remain roadmap or pilot-stage assertions?
- Where does the product create real defense, intelligence, critical-infrastructure, or emergency-response value beyond ordinary commercial adoption?
- How does the platform integrate into existing SOC, cloud, identity, or compliance workflows without adding operational burden?
- What would disconfirm the priority signal: weak customer references, thin technical differentiation, poor capital efficiency, or limited allied-market access?
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.
Related companies
Need a diligence readout?
Use the profile and related checklists as a starting point. If the decision needs more context, request a company screen, founder-call prep, diligence memo, or sector readout.