From Breaking In to Shutting Hackers Out: The Two Lives of Tal Kollander

Tal Kollander spent years on the offensive side of hacking before switching to defence. His story is a window into how the two worlds actually think about each other.

ThreatVectr Newsdesk· 3 min read
Aerial 16:9 view of a vast server farm at night, rows of blinking rack lights stretching to the horizon, some sections suddenly going dark in a ripple pattern,
Share

Key points

  • Tal Kollander built his career in two distinct phases: first as an offensive hacker, then as a cybersecurity defender.
  • His background is rare; most security professionals enter defence directly, without hands-on attacking experience.
  • Defenders who have crossed over from offensive work often understand attacker thinking in ways that pure defenders do not.
  • Kollander's story, first covered by SecurityWeek, is part of a broader conversation about how the security industry recruits and retains talent.

Who is Tal Kollander?

Tal Kollander is a cybersecurity professional whose career splits cleanly into two chapters: years spent finding and exploiting weaknesses in computer systems, followed by years spent stopping other people from doing exactly that.

Those two chapters are not as contradictory as they sound. Offensive security, meaning the practice of deliberately attacking systems (with permission) to find flaws before criminals do, is a formal discipline. Penetration testers, red teamers, and security researchers are paid to think like criminals. The difference between that work and actual crime is, in most cases, a signed contract and a clearly defined target.

Kollander moved through both sides of that line.

Why does crossing over matter?

Defenders with genuine attacking experience are genuinely rare, and they tend to think differently. A defender who has never attacked a system learns from playbooks and vendor alerts. One who has actually exploited weaknesses knows, almost instinctively, which paths an attacker is most likely to take through a network.

That gap matters in practice. When a company suffers a breach, where criminals break into its systems and steal or lock data, investigators often ask: why didn't the defences catch this earlier? Frequently, the answer is that the defences were built by people who had never seriously tried to break them.

Kollander's career arc is, in that sense, a case study in what the industry keeps saying it wants more of.

What should ordinary people take from this?

For most people, the direct relevance is indirect. You are not hiring a penetration tester. But the organisations that hold your bank details, medical records, or travel bookings are (or should be). Knowing that the people defending those systems have actually tried to break them is a reasonable question to ask of any organisation you trust with sensitive data.

If you are a student or career-changer thinking about cybersecurity, Kollander's trajectory points to something practical: ethical hacking skills, earned through accredited training programmes or certifications, are a credible route into well-paid defensive work. The industry tends to respect people who can demonstrate they understand how attacks actually work.

The broader point is simple. Security is not just a matter of buying better software. It requires people who understand both sides of the fence, and there are never quite enough of them.

© 2026 Threat Vectr