Tal Kollander: From Black Hat Hacker to Cyber Defender

Tal Kollander, a former black hat hacker and IDF veteran, is CEO and CISO of Remedio, which raised $65 million in September 2025 to detect and repair configuration drift used in lateral attacks.

Remedio, formerly Gytpol, secured $65 million in external funding in September 2025 to scale a platform that finds and fixes configuration drift in enterprise systems. The company, founded in May 2019, changed its name to Remedio ahead of the financing. Co-founders include Tal Kollander, Gilad Raz and Yaakov Kogan.

The Remedio platform scans infrastructure and identifies small configuration changes that diverge from intended settings. The company prioritizes which deviations pose the greatest risk and applies fixes to reduce the chance that attackers can move from an initial access point to higher-value systems.

Remedio reported that the funding will be used to expand engineering resources, scale operations and grow its customer base. The company said headcount doubled within months after the round.

Tal Kollander leads Remedio as chief executive and chief information security officer. Kollander began hacking as a teenager, writing code in HTML, Pascal, C and C# and creating tools for online gaming. She later sold anti-cheat and security tools to companies.

Kollander joined the Israel Defense Forces, completing fighter pilot training and then serving in high-security computer units including Mamram and at Rafael Advanced Defense Systems. She moved from offensive testing to defensive roles while in the military, conducting internal security work on critical systems.

After leaving the military in 2011, Kollander worked in corporate security. Her roles included deputy CISO at MalamTeam Ltd and security architect and CISO for the Israeli arm of Avnet. She joined EMC in 2013 as an IT security architect and remained through the company’s transition to Dell EMC. She spent roughly 15 years in defensive cybersecurity roles before co-founding Gytpol in 2019.

Kollander frames hackers by actions: white hats who report vulnerabilities, black hats who exploit access for gain, and grey hats who operate between those categories. She treats unauthorized actors working for foreign governments as black hats when they target systems without owner permission.

Kollander described a common pattern in breaches: attackers use small misconfigurations to move laterally inside networks. “Ninety-nine percent of the time, you will find hackers move laterally,” she noted, adding that artificial intelligence has sped some attack techniques. Kollander said Remedio aims to find configuration gaps and repair them before attackers can exploit those paths. She added that customers drive the company’s priorities.

Remedio positions its product as a tool to reduce windows of exposure by correcting configuration and compliance gaps. The company plans to direct the recent funding into product development and geographic expansion while increasing engineering and support teams.

Articles by this author