Dossier · Private startup · 4 independent sources
ThreatDash
Last updated: Sep 8, 2026
ThreatDash is an Israeli industrial-cyber startup building a read-only, vendor-agnostic operational-risk intelligence layer that connects process, OT, IT, cyber, maintenance, and operator signals. Its goal is to show which operational zones and critical assets may be at risk before a cyber or technical anomaly becomes a production, safety, or resilience incident.
Visit WebsiteCompany Overview
**Product and the concrete problem it solves.** ThreatDash addresses a gap between industrial security telemetry and operational decision-making. A process-critical plant may already have a historian, SCADA and PLC/HMI systems, OT monitoring, a SIEM, EDR, maintenance software, engineering records, and human observations, yet those systems generally describe separate events rather than the combined operational meaning of those events. A suspicious controller change, an after-hours use of engineering credentials, an unusual process signal, and a maintenance exception may each look manageable in isolation while their relationship creates a developing risk to a production line, utility dependency, safety boundary, or delivery commitment. ThreatDash presents itself as the missing context layer: it identifies developing “Risk Situations,” maps them to “Operational Zones” and “Key Assets,” and gives operations, OT, IT, and security teams a shared view of what to investigate first. Its public product scenario uses an illustrative hydrogen-electrolysis environment in which an after-hours controller-parameter change has not yet affected production, but should be validated before it can progress into process drift or instability. The company explicitly says it is not replacing SCADA, historians, SIEM, EDR, or OT-security tools; the wedge is prioritization and operational interpretation above existing systems.
**Core technology and how it actually works.** The disclosed architecture is a combination of reusable industrial-risk models, plant-specific configuration, deterministic operational logic, explainable AI assistance, and read-only integration. ThreatDash says a customer acceleration phase starts with existing documentation, exports, representative data, and stakeholder input. The platform maps site assets, dependencies, criticality, operational zones, and available signals, then configures relevant risk patterns for the site’s topology and operating context. AI is used to help create, enhance, and tune models, recognize patterns, and prioritize investigation, while approved deterministic logic remains authoritative during operational use. That division is material for safety and trust: the system is intended to explain why a developing situation was surfaced and to keep a human in the loop, rather than issuing autonomous process-control commands or making an opaque, irreversible change. Its vendor-agnostic posture allows it to work with process and utility data, alarms, controller logs, OT and IT events, security telemetry, maintenance information, and operator observations. Public sources do not disclose the model architectures, supported protocols, data-retention design, deployment topology, latency targets, or security certifications, so the defensible technical description is a controlled context-and-reasoning layer rather than a claim of a new detection algorithm.
**Market, customers, and go-to-market.** ThreatDash is targeting process-critical manufacturing and utility-dependent industrial operations, including food and beverage, pharmaceuticals, specialty chemicals, hydrogen production, industrial materials, and facilities dependent on power, steam, compressed air, cooling, water, refrigeration, HVAC, analyzers, or control infrastructure. These sites have a strong economic reason to prioritize risk before disruption: an incident can create production loss, batch or quality impact, delivery failure, safety or environmental exposure, or equipment damage. The initial commercial motion is deliberately narrow and consultative. Instead of asking a plant to replace its control or security stack, ThreatDash proposes a focused, read-only acceleration phase that produces an initial operational-risk view, documented assumptions, simulated risk situations, mapped data-source options, and criteria for controlled live-source validation. This reduces the trust barrier for an industrial buyer and lets the company prove model fit before it touches production data. The company’s public materials describe preparation to engage early lighthouse customers and partners, but do not name customers, contracts, revenue, paid pilots, deployment sites, or recurring commercial metrics. The go-to-market thesis is therefore credible but pre-scale: win one or more process-critical reference sites, prove that the context layer improves investigation and escalation, then expand across plants, sectors, and critical-infrastructure operators.
**Traction, funding, and third-party validation.** ThreatDash was incorporated in Israel on June 4, 2025, and the Israel Innovation Authority lists it as an Israeli seed-stage company with five employees, supplementary funding, and participation in the 2025 Tnufa entrepreneur/startup program. The Authority describes the company as unifying IT, OT, and AI data into a single business-centric risk view across digital and physical assets, and classifies its technology across cyber, IT/OT operations, artificial intelligence, and agentic AI. Startup Nation Finder gives a more cautious product-development description: it lists ThreatDash as founded in June 2025 in Be’er Sheva, with 1–10 employees and a customer-development or pre-funding posture. The discrepancy is useful rather than problematic: public institutional data confirms an active Israeli venture and government-program support, while the ecosystem profile indicates that commercial maturity remains very early. ThreatDash’s own site now presents a product scenario, defined acceleration workflow, leadership, and a concrete operating model; its company LinkedIn introduction says it is preparing to engage early lighthouse customers and partners. No public source reviewed here confirms a priced venture round, named customer, paid deployment, independent benchmark, patent portfolio, or production outage prevented by the platform. The record should treat public funding-program validation and product readiness as real signals, while keeping commercial traction unproven.
**Founders and team background.** The founding team combines industrial, cybersecurity, product, and software-development experience, although the public team is small. ThreatDash identifies Tomer Domshlak as founder and CEO, responsible for strategy, product direction, software development, customer validation, and commercial execution; the company says he brings more than ten years of startup, software-product, and cybersecurity experience. Alex Domshlak is described as co-founder and the lead for industrial cyber-physical risk, OT security, and reusable operational-risk models, with more than twenty years of leadership across enterprise IT, cybersecurity, and global manufacturing and a CISSP credential. The company also says it has dedicated software-development capacity through Codekings, a development company founded by Tomer Domshlak. That arrangement can provide continuity for a very small startup, but it is not the same as a disclosed full-time engineering organization, and public sources do not establish headcount beyond the Israel Innovation Authority’s five-person figure. The relevant founder-market fit is practical: the product depends on understanding how plant operations, security teams, asset criticality, human escalation, and fragmented enterprise software intersect. The diligence gap is equally clear: buyers and partners will need evidence of experience with specific control systems, safety processes, secure deployments, and regulated critical-infrastructure procurement, not only general cybersecurity and software credentials.
**Competitive dynamics.** ThreatDash competes against both point products and internal integration projects. Microsoft Sentinel and other SIEM platforms aggregate security events; Claroty and Nozomi Networks provide OT and cyber-physical visibility; Dragos focuses on industrial threat detection and response; Splunk and Elastic support broad observability and security analytics; and large industrial automation vendors such as Siemens and Schneider Electric embed monitoring, asset context, and operational controls into their own ecosystems. Plant engineering teams can also build dashboards and correlation logic across historians, SCADA, CMMS, IAM, and security tools, while systems integrators can create bespoke operational-risk workflows. ThreatDash’s claimed edge is the position it occupies: a vendor-neutral, read-only layer focused on the operational consequence and investigation priority rather than another raw telemetry collector, a process-control product, or a generic alert queue. Reusable industry and asset models could shorten deployment and encode domain logic across sites, while explainable reasoning and deterministic authority may reduce resistance in environments where black-box automation is unacceptable. The edge is not yet proven as a moat. Incumbents already own data access and customer trust, integrators can customize workflows, and a small team may struggle to support the protocol diversity and site-specific modeling that make the product valuable.
**Defense, security, and resilience dual-use relevance.** ThreatDash’s core technology has credible dual-use relevance because the same operational-risk problem exists in factories, utilities, water systems, logistics sites, hospitals, defense-industrial plants, and military support infrastructure. In commercial settings, connecting cyber events to process-critical assets can help operators investigate a suspicious change before it affects production, safety, quality, or delivery. In defense and national-security settings, a read-only, explainable context layer could help protect ammunition, energy, water, communications, aerospace, and other industrial facilities whose control systems and enterprise networks are increasingly connected. It could also support joint operations where OT, IT, physical processes, and human observations must be interpreted together under time pressure. This is resilience and critical-infrastructure adjacency, not fielded defense capability: no military customer, government deployment, classified program, defense contract, security accreditation, or incident-response result is publicly disclosed. The company’s own framing is industrial and process-critical rather than defense-first. Accordingly, dual_use is true because the underlying capability directly transfers between commercial industrial operations and security/resilience missions, while the dual-use score remains below the level warranted for an operational defense supplier. Diligence should focus on data sovereignty, secure network segmentation, human authorization, auditability, and behavior when communications or trusted data sources are degraded.
**Growth stage, trajectory, and key diligence risks.** ThreatDash is early: it is a 2025 company with five employees in the Innovation Authority record, a public Tnufa/Startup Fund signal, a product site describing controlled validation rather than mature production deployments, and no disclosed revenue or institutional VC round. The trajectory is attractive if the team can turn a difficult integration and reasoning problem into a repeatable product: establish lighthouse sites, prove that model-driven context reduces time-to-triage or prevents operational impact, add more industrial domains, and become a trusted resilience layer across heterogeneous plants. The main risks are substantial. First, industrial sales cycles are slow and reference-dependent, especially where safety, OT change control, and procurement are involved. Second, site-specific models may create services-heavy economics and limit gross margins if reusable abstractions do not generalize. Third, false prioritization can waste scarce engineering attention, while missed escalation can damage trust in a high-consequence environment. Fourth, read-only integration still requires secure access to sensitive architecture and operational data. Fifth, Claroty, Dragos, Nozomi, Microsoft, Siemens, Schneider, and integrators can bundle overlapping context or acquire a specialist. Sixth, the public evidence does not yet prove live customer value, model accuracy, protocol coverage, or long-term data-governance posture. The next diligence milestones are named lighthouse deployments, documented validation results, repeatable model configuration, customer retention or expansion, security-assurance evidence, and proof that the company can scale beyond founder-led industrial consulting.
Dual-Use Assessment
ThreatDash's core operational-risk context layer has substantive commercial and resilience applications. Commercial plants can use it to connect process, OT, IT, cyber, maintenance, and operator signals to developing risks before production, safety, or quality is affected. The same read-only, explainable, human-in-the-loop approach could support defense-industrial facilities, military support infrastructure, utilities, water systems, communications sites, and other critical operations whose cyber events can create physical consequences. Public evidence does not establish a defense customer, government deployment, classified program, accreditation, or fielded military capability, so the dual-use case is credible critical-infrastructure resilience adjacency rather than demonstrated defense traction.
Strategic Fit Assessment
ThreatDash merits a positive legacy priority signal because it targets a consequential gap in industrial resilience with a technically specific product and credible Israeli public-program validation. (1) The company is not selling another generic AI alert layer: it connects fragmented process, OT, IT, cyber, maintenance, and operator evidence to operational zones and critical assets. (2) The read-only posture, explainable reasoning, deterministic authority, and human-in-the-loop workflow are appropriate design choices for industrial environments where automated control changes would be unacceptable. (3) The Israel Innovation Authority identifies an active 2025 Israeli seed-stage company with five employees and support through the Tnufa/Startup Fund pathway, while the company's own site documents a defined acceleration and validation process. (4) Founders Tomer and Alex Domshlak combine startup/software, cybersecurity, global manufacturing, OT, and industrial cyber-physical experience. The counterweights are decisive: no priced VC round, revenue, named customer, paid deployment, independent benchmark, certification, or disclosed production outcome is public; the product may require services-heavy site configuration; established OT vendors and integrators own the customer relationships; and the defense connection is resilience adjacency rather than fielded defense capability. This is a strategic diligence assessment and legacy priority signal, not an investment recommendation.
Strategic Value to U.S.-Israel Alliance
ThreatDash's strategic value is concentrated in cyber-physical resilience and the ability to interpret operational consequences before an incident becomes a production or safety event. (1) It could help industrial operators use the security and process data they already collect without forcing a rip-and-replace transformation. (2) Its vendor-neutral context layer may be useful across fragmented plants, utilities, and defense-industrial sites where no single system has a complete view of dependencies and physical consequences. (3) The read-only and explainable design is aligned with high-consequence environments that need accountable investigation and evidence preservation rather than opaque autonomous control. (4) Be'er Sheva location and Israel Innovation Authority support connect the company to Israel's cyber and resilience ecosystem. Strategic value remains conditional on live validation: the public record shows a young startup preparing lighthouse engagements, not an established critical-infrastructure deployment or government capability.
Key Technologies
- Reusable industry- and asset-specific operational-risk models configured to plant topology, dependencies, criticality, and available signals
- Read-only integration of process and utility data, historians, SCADA, controller logs, OT and IT events, EDR, SIEM, maintenance systems, and operator observations
- Explainable AI assistance for pattern recognition, model enhancement, investigation prioritization, and controlled continuous learning
- Deterministic operational reasoning that remains authoritative over bounded AI assistance during live use
- Cyber-physical context mapping from abnormal signals to Risk Situations, Operational Zones, Key Assets, and possible process consequences
- Human-in-the-loop risk investigation workflow with simulated validation before selected live-source connection
- Vendor-agnostic operational-risk layer designed to complement existing industrial and security systems rather than replace them
Use Cases & Applications
- Early investigation of after-hours controller or configuration changes in process-critical manufacturing
- Protection of hydrogen, chemical, pharmaceutical, food, and industrial-material production from developing cyber-physical risk
- Correlation of utility instability, process alarms, maintenance events, and cyber signals affecting production continuity
- Prioritization of investigation across SCADA, historians, OT networks, IT infrastructure, EDR, SIEM, and engineering systems
- Operational-risk monitoring for defense-industrial plants and military-support manufacturing sites
- Resilience assessment for power, water, refrigeration, compressed-air, cooling, and other utility-dependent operations
- Read-only lighthouse validation using simulated Risk Situations before controlled live-source integration
- Cross-team escalation and evidence preservation for operations, OT, IT, security, engineering, and plant leadership
Sources and verification
This profile is based on public-source research, Claw & Talon curation, and editorial judgment. Inclusion does not imply endorsement, partnership, investment, or a recommendation to transact. Readers should still confirm current status, customers, funding, and product claims before relying on this profile. The editorial policy explains how profiles are researched, where automated drafting is used, and how corrections work; the research methodology documents how evidence is graded, what counts as an independent source, and why some profiles are excluded from search indexing.
This record lists 6 public references used for company identity, status, positioning, or material-claim review.
Public sources
The links below are visible public references used for source discipline around company identity, status, funding, customer, acquisition, public-company, or other material claims where available.
- ThreatDash official website Verifies the operational-risk intelligence product, process/OT/IT/cyber signal sources, Risk Situations and Operational Zones concepts, read-only and vendor-agnostic architecture, deterministic logic and explainable AI positioning, acceleration-phase workflow, leadership, and Be'er Sheva company address.
- Threatdash Ltd — Israel Innovation Authority Verifies the Israeli company identity, 2025 establishment, five employees, Seed stage, supplementary funding, Tnufa/Startup Fund participation, Be'er Sheva location, IT/OT/AI/agentic-AI classification, and Alexey Domshlak contact record.
- ThreatDash — Startup Nation Finder Verifies the Israeli ecosystem profile, June 2025 founding, Be'er Sheva headquarters, 1-10 employee range, customer-development or pre-funding posture, vendor-agnostic IT/OT/agentic-AI context-layer description, and enterprise target market.
- ThreatDash Operational Risk Intelligence for Industrial Cyber-Physical Environments Verifies the company's public launch framing, early lighthouse-customer preparation, industrial cyber-physical scope, signal sources, risk-situation prioritization, explainability, reusable models, and non-replacement positioning.
- Threatdash LTD — Peerlist company profile Corroborates the Be'er Sheva startup identity, Israel Innovation Authority backing, operational-risk and resilience context-layer thesis, Alex Domshlak's CISSP leadership, Tomer Domshlak's technical role, and associated software-development capacity.
- ThreatDash Ltd — Israeli public company information mirror Corroborates the active Israeli private-company identity, company number 517172458, June 4, 2025 founding date, Be'er Sheva address, and Alexey Domshlak association.
- Profile update timestamp Last updated in the Claw & Talon database on Sep 8, 2026.
Related sector
See the Cybersecurity sector page for market context, related subcategories, and other Israeli companies in this part of the database.