Bank of Israel - Directive 361 / פקודה 361

DDoS resilience testing for
Israeli financial institutions

Bank of Israel Directive 361 requires periodic penetration testing and demonstrated DDoS protection. DDactic provides validated evidence that your controls hold under real attack conditions.

מתאים לדרישות בנק ישראל פקודה 361

What Directive 361 Requires

Bank of Israel Directive 361 (Proper Conduct of Banking Business - Cyber Defense Management / ניהול הגנת סייבר) sets the cybersecurity baseline for all Israeli banking corporations. DDoS resilience is an explicit requirement, not an optional control.

Bank of Israel Directive 361 - Penetration Testing Requirements

"Banking corporations are required to conduct periodic penetration testing by qualified external parties to assess the effectiveness of their cyber defense controls. Testing must cover the full threat landscape identified in the institution's risk assessment, including availability threats such as DDoS attacks."

Bank of Israel Directive 361 - Business Continuity and Availability

"Banking corporations must maintain and test business continuity plans that address the range of cyber threats that could impair service availability, including distributed denial of service attacks. Controls must be demonstrated to function under actual attack conditions, not merely documented as being in place."

Bank of Israel Directive 361 - Annual Risk Assessment

"Each banking corporation must conduct an annual cyber risk assessment that includes evaluation of DDoS as a specific threat vector. The assessment must consider the institution's exposure, the effectiveness of existing controls, and the residual risk after controls are applied."

The Israeli Threat Context

Israeli financial institutions face documented, targeted DDoS campaigns. The Bank of Israel responded with heightened requirements after these incidents.

2022

Killnet and affiliated groups conducted coordinated DDoS campaigns against Israeli banking infrastructure. Multiple institutions experienced service disruptions.

2023

Anonymous Sudan-affiliated actors escalated DDoS operations targeting Israeli financial services. Attacks featured L7 HTTP floods designed to bypass standard CDN protections.

2024

Bank of Israel issued updated cyber guidance emphasizing demonstrated protection validation, not just documentation of controls. Directive 361 testing requirements were clarified to include DDoS simulation.

2025+

Threat level remains elevated. Israeli financial sector is a persistent target. Banks without validated DDoS protection face both operational risk and regulatory exposure.

How DDactic Maps to Directive 361

Directive 361 Requirement DDactic Feature
Periodic penetration testing by qualified external party
Testing must come from outside the organization
DDactic operates from an external 24-cloud-provider fleet. Tests originate from outside your network exactly as real attacks would. No agents installed inside your environment.
DDoS threat controls validation
Controls must be tested, not just documented
DDactic simulates L3/L4/L7 attack scenarios (SYN floods, UDP amplification, HTTP floods, cache bypass, API abuse) and measures whether CDN, WAF, and scrubbing services actually hold under load.
Business continuity testing
Availability must be demonstrated under adversarial conditions
OPI Operational Resilience component measures system availability and latency during active attack simulation. Produces quantified availability SLA evidence.
Annual DDoS risk assessment
Risk posture must be quantified annually
OPI Passive score provides quantified DDoS attack surface assessment. Identifies origin IP exposure, unprotected subdomains, and CDN bypass paths that contribute to residual risk.
Incident response testing
IR procedures must be exercised against real attack scenarios
DDactic simulates the exact attack types documented in the threat timeline (Killnet patterns, HTTP flood variants, protocol abuse). IR teams can observe real response under controlled conditions.
Regulatory evidence package
Supervisors may request documentation of testing
OPI Validated score, PDF report, attack surface inventory, and hardening steps retained for 12 months. Package formatted for regulatory submission.

Who Must Comply

Israeli Banks

All Israeli banking corporations supervised by the Bank of Israel Supervisor of Banks. Includes the five major banks and all licensed banking subsidiaries.

Foreign Bank Branches

Branches of foreign banks operating in Israel under Bank of Israel supervision. Directive 361 applies to Israeli operations regardless of parent entity jurisdiction.

Credit Card Companies

Israeli credit card companies including Visa Cal, Mastercard Israel, and Diners Club Israel. Card processing infrastructure is a high-priority DDoS target.

Financial Infrastructure

Payment clearinghouses, settlement systems, and financial market infrastructure operators subject to Bank of Israel oversight.

Why DDactic Is Uniquely Positioned for Israeli Banks

  • Founded in Israel by a DDoS resilience engineer with direct knowledge of the Israeli threat landscape
  • Attack vectors include the specific L7 patterns used in Killnet and Anonymous Sudan campaigns against Israeli infrastructure
  • Hebrew-language support available for regulatory submission documentation
  • No data leaves Israel for the passive reconnaissance phase (DNS and HTTP header analysis only)
  • Active simulation traffic is clearly labeled and coordinated to avoid regulatory concerns about unauthorized testing
  • Origin IP exposure detection is critical for Israeli banks, many of which use Cloudflare and Akamai with improperly configured origin shielding

Directive 361-ready DDoS evidence

Run a free passive scan of your attack surface. Active DDoS simulation and OPI Validated report available for regulatory submission.

Start Free Scan

See other standards: DORA, NIS2, PCI DSS, ISO 27001, SOC 2