From National Grids to Boutique Rigor: How Dima Shaposhnykov Built One of Israel's Fastest-Growing Cybersecurity Practices - and What He's Doing With That Experience Now

From National Grids to Boutique Rigor: How Dima Shaposhnykov Built One of Israel's Fastest-Growing Cybersecurity Practices - and What He's Doing With That Experience Now
Written By:
IndustryTrends
Published on
Updated on

When Dmytry Shaposhnykov talks about security compliance, he is not speaking as a consultant who learned the standards from a textbook. He is speaking as the executive who built PwC Israel's cybersecurity practice from the ground up, scaled it into a multi-million-dollar operation serving the country's largest banks and critical national infrastructure, and then left to prove the same discipline works at boutique scale.

Shaposhnykov, co-founder and CISO of the cybersecurity consultancy MindCypher and a Major in the IDF reserves, has spent the better part of a decade at the intersection of two worlds that rarely meet: the hands-on engineering of secure systems and the executive governance frameworks that certify them. His argument - that compliance standards like ISO 27001 and PCI DSS only create value when they sit on top of security that actually works - is grounded in a track record that includes some of the most sensitive infrastructure projects in Israel.

Building a Practice From Zero

Shaposhnykov arrived at PwC Israel in 2022 What followed was one of the fastest scaling stories in the Israeli consulting market. As Head of Cybersecurity, he built PwC Israel's cybersecurity services practice from the ground up - growing the team to more than thirty security professionals and delivering approximately $10 million in annual revenue, while the broader PwC NEXT technology unit he helped build expanded from nineteen people to more than seventy in roughly three years.

The growth was not driven by headcount alone. Shaposhnykov positioned the practice around a differentiator most consulting firms talk about but few deliver: senior practitioners who design and implement, rather than advise and depart. Under his leadership, the practice served C-level executives across banking, insurance, energy, healthcare, and technology, and contributed frameworks, tooling, and research back to PwC's global network - including specialized knowledge in application security and operational technology (OT) security that drove new service lines internationally.

“Consulting firms are usually structured to sell strategy and subcontract execution,” Shaposhnykov says. “We inverted that. The people who wrote the architecture were the people who had built these systems before. Clients noticed the difference, and the growth followed.”

Securing Israel's Electricity Grid

Among the projects Shaposhnykov led at PwC, one stands out for its national significance. When Israel established NOGA, the independent system operator responsible for managing and developing the country's entire electricity grid, the new company needed a security foundation built from nothing - for one of the most consequential pieces of critical infrastructure in the country.

Shaposhnykov led that work from inception. His team built two fully secured, high-availability data centers from the ground up to support national grid operations, and designed a unified security architecture spanning IT, cloud, and OT environments - a combination that is notoriously difficult to get right, because the operational technology controlling physical grid equipment obeys entirely different constraints than corporate IT. The engagement delivered on schedule, including an innovative secure remote access solution designed to meet the strictest operational and regulatory requirements. The policies, controls, and monitoring practices established under his leadership continue to protect one of Israel's most critical national assets.

“When the asset is the national electricity supply, there is no version of ‘good enough on paper,’” he says. “Everything has to function under real conditions, including emergency conditions. That project shaped how I think about every security program since.”

Transforming Banking Security

The second pillar of Shaposhnykov's PwC tenure was the Israeli banking sector - among the most heavily regulated environments in the world. For MATAF, the technology and operations arm of the First International Bank of Israel, he developed a comprehensive SaaS adoption framework that reduced the bank's onboarding timeline for new cloud software from eight months to six weeks, without relaxing a single security requirement. The vendor security assessment methodology he authored for that engagement went on to influence Cloud Security Alliance guidance for startups - a case of client work shaping industry standards.

For another leading Israeli bank, he led a security-driven transformation from on-premises infrastructure to the cloud, rescuing a stalled AWS landing zone deployment and rebuilding it into a functional foundation capable of supporting large-scale projects under the bank's regulatory constraints. Across the sector, his team assessed and remediated major SaaS applications and designed adoption operating models that regulators and risk committees could stand behind.

Building People, Not Just Systems

Shaposhnykov's impact at PwC extended beyond client delivery into the industry itself. He championed an internal CISSP certification program that achieved a 100 percent exam pass rate among participants - a striking figure against a first-attempt industry pass rate commonly cited near 23 percent. In partnership with Google and Reichman Tech School, his team built a comprehensive Cyber Analyst training course that has run multiple cohorts, feeding new talent into an industry with a chronic shortage of qualified professionals.

“A security practice is ninety percent the people,” he says. “Technology changes every eighteen months. Judgment compounds. If you are not building people, you are not building anything durable.”

The Same Discipline, Applied to Compliance

That background is what makes Shaposhnykov's current focus - security governance and compliance for the mid-market - more than consulting boilerplate. At MindCypher, he applies the same standard to ISO 27001 and PCI DSS engagements that he applied to national infrastructure: the controls must work first, and the certification follows.

“Compliance gets a bad reputation because most of what people see is paperwork compliance,” Shaposhnykov says. “ISO 27001 is asking whether your organization can defend the assets it says it can defend. If you treat that question seriously, the certification follows. If you treat the certification as the goal, you end up with neither.”

The 2022 revision of ISO 27001 - which organizations were required to transition to by late 2025 - has, in his view, made hollow certification harder to sustain. New requirements around threat intelligence, cloud security, and business continuity force organizations to demonstrate that controls actually inform decisions rather than merely exist in policy binders. PCI DSS has moved in the same direction, increasingly rewarding organizations that can show the substance behind their controls.

“The regulators have caught up to what the security community already knew,” he says. “You cannot defend what you do not understand, and you cannot certify what you have not actually built.”

Characteristically, Shaposhnykov has tested the philosophy on his own firm. MindCypher put itself through a full ISO 27001:2022 implementation - complete with a formal risk register, asset inventory, internal audit, and corrective action process - despite being a small boutique operating cloud-first and fully remote.

“It looks excessive from the outside and reasonable from the inside,” he says. “Our clients ask us how to do this. If we can't describe it from lived experience, we have no business consulting on it.”

Why It Matters

The through-line of Shaposhnykov's career - from securing a national electricity grid, to transforming how Israeli banks adopt cloud technology, to building one of the country's fastest-growing security practices, to bringing that rigor to mid-market firms - is a consistent refusal to separate governance from engineering. In a market where certifications are increasingly demanded and increasingly gamed, that combination has become rare, and valuable.

“The value of a real certification is that it survives scrutiny,” Shaposhnykov says. “A paper certification fails the moment something actually happens. A real one doesn't.”

About Dmytry Shaposhnykov and MindCypher

Dmytry (Dima) Shaposhnykov is co-founder and CISO of MindCypher, a boutique cybersecurity consultancy specializing in managed detection and response, penetration testing, and compliance consulting (ISO 27001, PCI DSS). He is the former Head of Cybersecurity at PwC Israel, where he built the firm's cybersecurity practice from the ground up and led security programs for Israel's national electricity grid operator and major financial institutions. He is a Major in the IDF reserves.Dmytry served as a judge of Tantun Holdings AI Hackathon. 

logo
Artificial Intelligence News & Cryptocurrency News: Latest Trends | Analytics Insight
www.analyticsinsight.net