Tal Kollander’s history divides neatly into two halves: first as an active hacker and then as the block that stops hacks.
Based in Tel Aviv, Israel, Tal Kollander has the mindset of a hacker (we’re talking specifically about computer hackers). She believes hackers use creative skills to access computers by ‘non-legit’, basically criminal but creative, methods. A hacker to Kollander is anyone who accesses a computer without proper authorization to do so.
Hackers are then subdivided by their subsequent actions. A ‘good’ hacker will report findings to the computer owner. “This is what I found. Now go fix it,” explains Kollander. These are white hat hackers.
A ‘bad’ hacker accesses a computer for personal gain: such as money, kudos, or political advantage. These are black hat hackers. They do not report their findings to the computer owner, but they may circulate or sell the access method to other hackers or brokers on the criminal underground.
The two basic categories of computer hacker can thus be viewed as either moral or immoral. But just as morality has a third category, amoral (neither one nor the other, perhaps both), so there is a third color to hackers – grey hats who play both sides, sometimes white and sometimes black.
However, not all black hat hackers are bad people. Good people can be pressured or brainwashed by their government to hack core targets in foreign countries. In some countries they are persuaded it is a patriotic act for the sake of their country, and in other countries they can be threatened with dire consequences for both themselves and their families if they refuse. It is the act, not the psychology of the person, that defines the hacker.
This clear categorization assists in classifying edge cases. A pentester working with the agreement of the computer owner is not a hacker. A pentester working without that agreement is a hacker, even though he might be a moral white hat hacker. A nation state actor, whether working for the NSA, GCHQ, FSB, MSS or IDF, is automatically an immoral black hat hacker when he doesn’t have authorization from the target computer’s owner. Patriotism is not a factor in hacker classification.
Becoming a hacker
Kollander was too young to recognize it was hacking when she first started. She was just a girl doing Flash gaming on the internet and was in first place. “One day I woke up to find that I was no longer in first place; I was second. Someone had come out of nowhere. So, I said to myself, he must have cheated. And I wanted to know how.”
Intense and ongoing curiosity was a key factor in creating the young hacker. It’s what drove her to understand computer hardware and software at a deep level, so she could answer the continuous questions: why did that happen, what if I do this, what else is over there or hidden under here…? This was the initial trigger – the same trigger that created most young hackers: curiosity within gaming.
“In one game, I contacted one of the other players, and we became friends. Then we used ICQ and we became good friends. Together we built something to help us win at gaming and earn prizes.” Later, they built something else that would prevent anyone else doing the same thing, and they sold it to the companies. “That’s how I earned my first million dollars”, she comments.
She got her first computer when she was 13, during junior high and high school. She learned basic coding, first html and then Pascal, C and C#, and was taught at school how to build a project. “But remember,” she says, “when you are hacking, you don’t go to the things you know. There are other things, other corners you need to see, what’s beyond the visible and obvious, what’s behind that.”
This curiosity didn’t just stay within gaming. Social media arrived with a new challenge to her curiosity. Another friend had her Facebook account hacked. “I looked at Facebook and discovered how easy it was to hack social media back then; and it’s still easy-ish today. From there, one thing led to another, and I always wanted to do it bigger and wider and to get into new areas.”
In my teenage years, she says in her LinkedIn profile, I was a professional hacker, always on the hunt to crack open what seemed impossible, always on the lookout for IT challenges.
“What got me into this? The money was good, but it was a side effect. I was just curious to do so many things. I was curious to take advantage of games, to break the email server, to get into the bigger companies that claim they are secure. I wanted to go against the odds. If somebody said, ‘You can’t do this’, it became my drive. All it took was for someone to tell me this can’t be done, and I would want to do it.”
Then everything changed. Military service, compulsory in Israel, beckoned and she joined the Army.
The Army factor
“When I joined the Army, I took the fighter pilot course, and then I continued to the computer units – first the IDF’s Mamram computer unit, and then the Rafael Advanced Defense Systems. I became a hacker for the IDF. Instead of getting another million dollars in the bank, I got 100 bucks per month – which was very embarrassing, but it was the money you got in the Army back then.”
The IDF adopted her skills but changed the onus from using them for her own benefit to using them for her country’s benefit. “Start helping your country now, start helping us protect our weapons, the Iron Dome or whatever. There were numerous projects where I needed to think like a hacker in order to protect them. I had to be way more sophisticated than a regular pentester. I had to hack into our own critical infrastructure and super high clearance networks to learn how to stop them from being hacked by the country’s enemies.”
The experience changed her mindset. “Doing this for the Army and my country changed me. Instead of breaking computer networks, I started wanting to protect them. That was the ‘wow’ moment for me. Oh, wow, I can actually do something good with my abilities.”
Becoming legit
With this change in mindset, she began her career in defensive cybersecurity. She left the IDF in 2011 and became deputy CISO at MalamTeam Ltd, which could be described then primarily as an IT integrator and outsourcing provider, and now as one of Israel’s national IT backbones.
One year later she became security architect and CISO at the Israeli subsidiary of Avnet. In 2013 she moved to EMC and became Dell EMC’s IT security architect and CISO following the 2016 acquisition by Dell Technologies. This time she stayed for a total of 5 ½ years – but it’s clear she still had the heart and mindset of a hacker.
In May 2019 she co-founded and bootstrapped a firm called Gytpol along with Gilad Raz and Yaakov Kogan. In September 2025, Gytpol changed its name to Remedio and raised its first external funding of $65 million. Kollander is both CEO and CISO at Remedio.
“We were under the radar for several years but were now ready for more rapid expansion,” she explains. Within months of that funding, the firm doubled in size.
“At Remedio, we want to teach you how hackers operate. Because you may have the best EDRs or whatever in the market, but you still get breached, you still get hacked. Once hackers find an entry point, they move laterally abusing configuration and compliance drifts.”
Configuration drift is unseen but almost inevitable in modern infrastructures. It is the unnoticed, slow but incremental process of small changes accumulating until the system no longer matches its original specifications or deployment configuration. Users don’t see this, but hackers find it.
“Ninety-nine percent of the time, you will find hackers move laterally, obviously faster today with AI, but they move laterally abusing something that Remedio not only knows about, but can fix,” she says.
“We don’t want to just find these problems before the hackers do; we want to fix them. The company is my family, but the customers are my drive. We’re almost like the hackers themselves seeking out these flaws but fixing them before they can be abused. We fill that gap between just knowing about something and addressing it.”
She understands the hackers because for many years she was one. She understands how to fix these problems because for the last 15 years she has been a cybersecurity defender.
Today, Kollander is no friend to black hat hackers. Even though she grew up among them, she wants things to change. “I think people, inside, are good. Maybe it’s the environment they live in or the brainwashing they receive, but people can be good. It’s patience that is hard.”
Related: Hacker Conversations: Isira Adithya, the Evolution of an Ethical Hacker
Related: Hacker Conversations: Joey Melo on Hacking AI
Related: Hacker Conversations: Inti De Ceukelaire, Raging Against the Machine Creatively