**From Hacker to Defender: Tal Kollander’s Journey to Protecting the Digital World**
Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks. Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so.
Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers. A ‘bad’ hacker accesses a computer for personal gain: such as money, kudos, or political advantage. These are black hat hackers. They do not report their findings to the computer owner, but they may circulate or sell the access method to other hackers or brokers on the criminal underground.
The two basic categories of computer hacker can thus be viewed as either moral or immoral. But just as morality has a third category, amoral (neither one nor the other, perhaps both), so there is a third color to hackers – grey hats who play both sides, sometimes white and sometimes black. However, not all black hat hackers are bad people. Good people can be pressured or brainwashed by their government to hack core targets in foreign countries. In some countries they are persuaded it is a patriotic act for the sake of their country, and in other countries they can be threatened with dire consequences for both themselves and their families if they refuse. It is the act, not the psychology of the person, that defines the hacker.
This clear categorization assists in classifying edge cases. A pentester working with the agreement of the computer owner is not a hacker. A pentester working without that agreement is a hacker, even though he might be a moral white hat hacker. A nation state actor, whether working for the NSA, GCHQ, FSB, MSS or IDF, is automatically an immoral black hat hacker when he doesn’t have authorization from the target computer’s owner. Patriotism is not a factor in hacker classification.
### Becoming a Hacker
Kollander was too young to recognize it was hacking when she first started. She was just a girl doing Flash gaming on the internet and was in first place. “One day I woke up to find that I was no longer in first place; I was second. Someone had come out of nowhere. So, I said to myself, he must have cheated. And I wanted to know how.”
Intense and ongoing curiosity was a key factor in creating the young hacker. It’s what drove her to understand computer hardware and software at a deep level, so she could answer the continuous questions: why did that happen, what if I do this, what else is over there or hidden under here…? This was the initial trigger – the same trigger that created most young hackers: curiosity within gaming.

*Tal Kollander*
“In one game, I contacted one of the other players, and we became friends. Then we used ICQ and we became good friends. Together we built something to help us win at gaming and earn prizes.” Later, they built something else that would prevent anyone else doing the same thing, and they sold it to the companies. “That’s how I earned my first million dollars”, she comments.
She got her first computer when she was 13, during junior high and high school. She learned basic coding, first html and then Pascal, C and C#, and was taught at school how to build a project. “But remember,” she says, “when you are hacking, you don’t go to the things you know. There are other things, other corners you need to see, what’s beyond the visible and obvious, what’s behind that.”
This curiosity didn’t just stay within gaming. Social media arrived with a new challenge to her curiosity. Another friend had her Facebook account hacked. “I looked at Facebook and discovered how easy it was to hack social media back then; and it’s still easy-ish today. From there, one thing led to another, and I always wanted to do it bigger and wider and to get into new areas.”
In my teenage years, she says in her LinkedIn profile, I was a professional hacker, always on the hunt to crack open what seemed impossible, always on the lookout for IT challenges.
“What got me into this? The money was good, but it was a side effect. I was just curious to do so many things. I was curious to take advantage of games, to break the email server, to get into the bigger companies that claim they are secure. I wanted to go against the odds. If somebody said, ‘You can’t do this’, it became my drive. All it took was for someone to tell me this can’t be done, and I would want to do it.”
Then everything changed. Military service, compulsory in Israel, beckoned and she joined the Army.
### The Army Factor
“When I joined the Army, I took the fighter pilot course, and then I continued to the computer units – first the IDF’s Mamram computer unit, and then the Rafael Advanced Defense Systems. I became a hacker for the IDF. Instead of getting another million dollars in the bank, I got 100 bucks per month – which was very embarrassing, but it was the money you got in the Army back then.”
The IDF adopted her skills but changed the onus from using them for her own benefit to using them for her country’s benefit. “Start helping your country now, start helping us protect our weapons, the Iron Dome or whatever. There were numerous projects where I needed to think like a hacker in order to protect them. I had to be way more sophisticated than a regular pentester. I had to hack into our own critical infrastructure and super high clearance networks to learn how to stop them from being hacked by the country’s enemies.”
The experience changed her mindset. “Doing this for the Army and my country changed me. Instead of breaking computer networks, I started wanting to protect them. That was the ‘wow’ moment for me. Oh, wow, I can actually do something good with my abilities.”
### Becoming Legit
With this change in mindset, she began her career in defensive cybersecurity. She left the IDF in 2011 and became deputy CISO at MalamTeam Ltd, which could be described then primarily as an IT integrator and outsourcing provider, and now as one of Israel’s national IT backbones.
One year later she became security architect and CISO at the Israeli subsidiary of Avnet. In 2013 she moved to EMC and became Dell EMC’s IT security architect and CISO following the 2016 acquisition by Dell Technologies. This time she stayed for a total of 5 ½ years – but it’s clear she still had the heart and mindset of a hacker.
In May 2019 she co-founded and bootstrapped a firm called Gytpol along with Gilad Raz and Yaakov Kogan. In September 2025, Gytpol changed its name to Remedio and raised its first external funding of $65 million. Kollander is both CEO and CISO at Remedio.
“We were under the radar for several years but were now ready for more rapid expansion,” she explains. Within months of that funding, the firm doubled in size.
“At Remedio, we want to teach you how hackers operate. Because you may have the best EDRs or whatever in the market, but you still get breached, you still get hacked. Once hackers find an entry point, they move laterally abusing configuration and compliance drifts.”
Configuration drift is unseen but almost inevitable in modern infrastructures. It is the unnoticed, slow but incremental process of small changes accumulating until the system no longer matches its original specifications or deployment configuration. Users don’t see this, but hackers find it.
“Ninety-nine percent of the time, you will find hackers move laterally, obviously faster today with AI, but they move laterally abusing something that Remedio not only knows about, but can fix,” she says.
“We don’t want to just find these problems before the hackers do; we want to fix them. The company is my family, but the customers are my drive. We’re almost like the hackers themselves seeking out these flaws but fixing them before they can be abused. We fill that gap between just knowing about something and addressing it.”
She understands the hackers because for many years she was one. She understands how to fix these problems because for the last 15 years she has been a cybersecurity defender.
Today, Kollander is no friend to black hat hackers. Even though she grew up among them, she wants things to change. “I think people, inside, are good. Maybe it’s the environment they live in or the brainwashing they receive, but people can be good. It’s patience that is hard.”
—
### FAQ
**What is the difference between white hat, black hat, and grey hat hackers?**
White hat hackers are ethical hackers who find vulnerabilities and report them to the system owner to help fix security issues. Black hat hackers exploit vulnerabilities for personal gain, such as money or political motives, without authorization. Grey hat hackers fall in between; they may sometimes act ethically and other times exploit vulnerabilities without permission, depending on the situation.
**How did Tal Kollander get started in hacking?**
Tal’s interest began with gaming, where curiosity drove her to understand how computers and software work. This led her to explore beyond the obvious, learning coding and system building. Her interest in hacking grew as she explored social media and other digital areas, eventually becoming a professional hacker during her teenage years.
**What role did the Israeli Army play in Tal’s career?**
The Israeli Army provided Tal with formal training in cybersecurity and allowed her to apply her hacking skills defensively. She worked in elite IDF units such as Mamram and Rafael, where she learned to protect critical infrastructure from cyber threats. This experience shifted her focus from breaking systems to protecting them.
**When did Tal transition to a defensive cybersecurity role?**
After leaving the IDF in 2011, Tal joined MalamTeam Ltd as deputy CISO, marking the start of her defensive cybersecurity career. She later held roles as security architect and CISO at Avnet and Dell EMC before co-founding her own company.
**What company did Tal Kollander co-found, and what is its focus?**
Tal co-founded Gytpol (later renamed Remedio), which focuses on teaching organizations how hackers operate and fixing configuration drift—unnoticed changes in system configurations that can be exploited. The company aims to close the gap between identifying vulnerabilities and remediating them before hackers can exploit them.
—
### Conclusion
Tal Kollander’s journey from a curious teenager breaking into games to a former hacker turned cybersecurity leader illustrates the power of redirecting skills for good. Her experiences in both offensive and defensive cybersecurity give her unique insight into how attackers think and how to defend against them. Today, through her company Remedio, she continues to bridge the gap between hacker intuition and protective innovation, ensuring that organizations can stay one step ahead of malicious actors. Her story is a testament to how curiosity, when guided by purpose, can transform from a potential threat into a powerful force for protection.



