The problem of formal compliance in cybersecurity
According to the ENISA Threat Landscape 2025 report, over 53% of organizations affected by cyberattacks were critical entities falling under the NIS2 directive. This confirms that strict regulatory pressure and compliance certificates do not guarantee actual protection. Attackers increasingly exploit supply chain vulnerabilities, legacy protocols, and legitimate administration tools to move laterally across networks.
Key threat analysis and architectural approach
To comprehensively assess infrastructure readiness, experts recommend using structured frameworks, such as the Cisco Cybersecurity Readiness Index 2025. It evaluates protection across five key pillars: identity intelligence, device trust, network resilience, cloud security, and AI defense.
The main attack vectors include:
- phishing and bypassing basic multi-factor authentication;
- compromise of third-party software (Supply Chain);
- exploitation of signaling protocols (SS7, Diameter) in telecom;
- digital identity fraud.
To eliminate blind spots and prevent lateral movement inside the network, proactive threat modeling is critical. For AI-driven systems, implementing the NIST AI RMF 1.0 standard is highly recommended.
Implications for business
For businesses and critical infrastructure, relying solely on paper-based compliance creates a false sense of security while leaving networks vulnerable to devastating lateral attacks. This gap between formal certification and actual resilience means companies risk severe operational disruptions, data breaches, and a loss of trust from partners who demand verified supply chain security.
Implementing the Security by Design principle
Effective defense requires integrating security at the system design stage. A prime example of this approach is Softengi (Intecracy Group consortium), which utilizes the UnityBase low-code platform by InBase to develop enterprise solutions. The platform features built-in security tools: Role-Based Access Control (RBAC), Row-Level Security, and an immutable Audit Trail. This foundation powers Megapolis.DocNet and Scriptum, systems that combine regulatory compliance with architectural resilience.
How to respond
To transition to a proactive defense, organizations are advised to implement the following measures:
- Zero Trust concept: continuous authentication and authorization of every network action.
- Microsegmentation: dividing infrastructure into isolated zones to contain security incidents.
- Telecom network protection: deploying STIR/SHAKEN technology for caller authentication.
- Supply chain audits: regular security assessments of third-party APIs and vendors.
Prepared by a Software Ukraine member. Original publication.