Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Shamir Research Institute

Shamir Research Institute Vendor Cyber Rating & Cyber Score

sri.org.il

For almost 40 years the Shamir Research Institute has been operating from the capital city of the Golan Heights, Katzrin, to advance the practical, applicable and academic research across the Golan and beyond. The institute is home for scientists who live in the Golan, where they do the research and where they find practical solutions in a varied gamut of subjects.


SRI A.I CyberSecurity Scoring

SRI
Company Information
Website:http://www.sri.org.il/Home
Employees number:50
Number of followers:1,790
NAICS:8135
Industry Type:Non-profit Organizations
Homepage:sri.org.il
SRI Risk Score (AI oriented)
Between 650 and 699
logo
SRINon-profit Organizations
Updated:
17/05/2026
661/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SRI Global Score (TPRM)
xxxx
logo
SRINon-profit Organizations
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SRI
SRIWeak
Current Score
661B (WEAK)
01000
1 incidents
-105 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
665Before Incident
JULY 2026
665Before Incident
JUNE 2026
664Before Incident
MAY 2026
661Before Incident
APRIL 2026
660Before Incident
MARCH 2026
761Before Incident
Ransomware
01 Mar 2026SRI
DragonForce, Shamir Medical Center and RansomHouse: State-backed ransomware activity raises new concerns over escalating threats to OT, critical infrastructure operations

Ransomware as a Geopolitical Weapon: Nation-State Exploitation of Cybercrime for Strategic Coercion

656After Incident
CRITICAL-105
DRAUNISHA1779027889
Ransomware as a Geopolitical Weapon: How Nation-States Exploit Cybercrime for Strategic Coercion Ransomware is no longer just a tool for financial extortion it has become a key instrument in geopolitical cyber warfare, enabling nation-states to disrupt adversaries while maintaining plausible deniability. Criminal groups, hacktivists, and state-aligned actors are increasingly converging, sharing infrastructure, tactics, and even strategic objectives to amplify the impact of cyber operations. ### Iran’s Hybrid Cyber Warfare Model Iran has emerged as a leading practitioner of this approach, blending cybercrime, espionage, and industrial sabotage. Recent investigations reveal how pro-Iran hackers have targeted critical wheat reserves, demonstrating how cyberattacks can directly threaten food security. A 2026 Trellix assessment highlighted Iran’s growing sophistication, including the use of ransomware-style operations that blur the line between state-directed campaigns and criminal activity. Meanwhile, Iranian-linked actors have targeted internet-connected cameras across the Middle East, synchronizing cyber operations with physical conflict. Ransomware’s role in the U.S.-Israel-Iran conflict has evolved significantly since 2020, when it was first used as cover for destructive or coercive activity. By 2023, it became a clear tool of strategic pressure, particularly after October 2023, when attacks increasingly intersected with critical infrastructure targeting. Groups like Handala Hack (TAT26-14) and DragonForce have conducted extortion campaigns against energy, healthcare, and manufacturing sectors, often leveraging ransomware-as-a-service (RaaS) models to obscure attribution. ### Blurring Lines Between Cybercrime and State Operations Iranian state actors frequently collaborate with criminal ransomware groups, using them as proxies to conduct attacks while maintaining deniability. The Pay2Key campaign, for example, aligned with geopolitical timelines, while groups like NoEscape, RansomHouse, and ALPHV/BlackCat have been linked to Iranian-backed access brokers. Unlike U.S. or Israeli cyber operations which typically adhere to formal military or intelligence channels Iran’s approach resembles irregular warfare, relying on proxies, criminal markets, and ambiguity to evade clear attribution. Despite the surge in ransomware activity, confirmed cases of direct operational technology (OT) disruption remain rare. Instead, the primary risk stems from enterprise-level compromises that indirectly affect industrial continuity, visibility, and recovery. ### Targeting Trends and Strategic Intent The most exposed sectors include water and wastewater, energy, fuel systems, transportation, manufacturing, government services, and healthcare. Within OT environments, attackers focus on internet-facing PLCs, HMIs, remote access pathways, and engineering workstations, particularly at the Level 0/1 boundary where sensors and actuators lack authentication or logging. The strategic intent is clear: coercive disruption, with the ability to manipulate physical processes while minimizing detectable network evidence. ### The Challenge of Attribution Distinguishing between state-directed campaigns and opportunistic cybercrime has grown increasingly difficult. Threat intelligence teams rely on pattern-based attribution, analyzing capability thresholds, infrastructure overlap, geopolitical timing, and victim selection. However, shared tooling, access brokers, and RaaS models allow different actors to operate on the same infrastructure, complicating attribution. Cases like the Shamir Medical Center attack initially attributed to Eastern European ransomware but later linked to Iran highlight the ambiguity. ### Defensive Shifts: From Prevention to Resilience Industrial operators in the U.S. and Israel are adapting by prioritizing resilience over prevention. Key measures include: - Disconnecting internet-facing PLCs and tightening remote access controls. - Improving IT-OT segmentation and treating CISA advisories as operational baselines. - Enhancing recovery capabilities, particularly for OT systems where traditional IT restoration methods fall short. Governments are providing guidance such as CISA’s Cybersecurity Performance Goals (CPGs) but regulatory frameworks struggle to keep pace with conflict-driven cyber threats. While intelligence sharing has improved, operators often find it insufficiently actionable for real-time defense. As ransomware continues to evolve from a criminal enterprise into a geopolitical weapon, the distinction between cybercrime and state-sponsored warfare will only grow more blurred leaving critical infrastructure in the crosshairs of hybrid conflict.
INCIDENT DETAILS -
TYPE
Ransomware, Cyber Espionage, Industrial Sabotage
MOTIVATION
Geopolitical coercionStrategic disruptionPlausible deniabilityHybrid warfare
IMPACT
Water and wastewater systemsEnergy sectorsFuel systemsTransportationManufacturingGovernment servicesHealthcareIndustrial control systems (ICS)Operational Impact: Indirect disruption of industrial continuity, visibility, and recovery
DATA BREACH
Data Encryption: Ransomware encryption in some cases
FEBRUARY 2026
761Before Incident
JANUARY 2026
761Before Incident
DECEMBER 2025
761Before Incident
NOVEMBER 2025
761Before Incident
OCTOBER 2025
761Before Incident
SEPTEMBER 2025
761Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SRI ?
?
What was SRI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SRI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SRI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SRI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SRI's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on SRI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SRI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SRI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?