Expert View 9 min read

Four years of evolution in Ukrainian corporate cyber resilience

Over the past four years of full-scale war, the cyber resilience of Ukrainian companies has evolved from reactive response to strategic proactivity. This...

Over the past four years of full-scale war, the cyber resilience of Ukrainian companies has evolved from reactive response to strategic proactivity. This is a period where cybersecurity has ceased to be merely an IT function, becoming a fundamental element of business continuity and national security. The aggressor actively uses cyberspace for destabilization, which has forced the Ukrainian IT sector and critical infrastructure to adapt with unprecedented speed. The ua.software publication analyzes how attack vectors have changed, how security operations have adapted, and what key role the state plays in shaping overall cyber resilience.

New attack vectors and their impact on the cyber resilience of Ukrainian companies

The evolution of cyber threats against Ukraine over the last few years is unprecedented. From initial targeted DDoS attacks and phishing campaigns, we have moved to complex hybrid operations that combine cyberattacks with psychological and informational influence. Attackers actively use wiper attacks to destroy data, supply chain attacks to penetrate networks through trusted partners, and disinformation as an integral element of cyber operations to undermine trust and incite panic.

The specificity of the enemy's targets has also expanded. While the initial focus was on government agencies and critical infrastructure (energy, logistics, telecommunications), Ukrainian businesses subsequently became targets for testing new tactics and tools. Small and medium-sized enterprises, which often have less protected systems, become easy prey, and their compromise can be used as a bridgehead for attacks on larger companies or state registries.

The consequences of such attacks go far beyond direct financial losses. Companies face serious reputational risks that can undermine the trust of clients and partners. Disruption of operations, especially for manufacturing or logistics companies, can lead to significant losses and supply chain failures. Data loss, including confidential information, intellectual property, or personal data, creates long-term compliance and recovery challenges.

The rise in attacks on cloud infrastructures and SaaS solutions, which are actively used by Ukrainian companies to ensure flexibility and scalability during the war, has become particularly noticeable. This requires businesses not only to implement cloud solutions but also to have a deep understanding of shared responsibility models for security, as well as investments in additional layers of protection, such as Cloud Access Security Brokers (CASB) and Cloud Security Posture Management (CSPM).

Adapting security operations to wartime requirements

In the face of constant cyberattacks, Ukrainian Security Operations Centers (SOC) and cybersecurity teams have been forced to radically change their approaches. The shift from reactive incident response to proactive defense has become key. This includes deep integration of Threat Intelligence, which allows for predicting potential attack vectors, understanding the adversary's tactics, techniques, and procedures (TTPs), and strengthening defenses in advance. Enhanced 24/7 monitoring using modern SIEM systems and Endpoint Detection and Response (EDR) has become the standard.

The implementation of Zero Trust architectures has become critical for many companies. Traditional perimeter defense proved insufficient, as attacks often begin with the compromise of internal users or systems. Zero Trust, with its "never trust, always verify" principle, ensures constant verification of every user and device, regardless of their location in the network. This significantly increases resilience against internal threats and attacks that have already penetrated the perimeter.

One of the biggest problems remains the shortage of qualified cybersecurity personnel. According to Ivan Abramov, Development Manager at SL-IT, "today, the demand for cybersecurity specialists in Ukraine exceeds supply several times over. Companies are actively investing in the retraining of internal IT specialists, using SOC outsourcing services, and resorting to automating routine tasks with SOAR platforms to compensate for the lack of expertise."

Optimizing cybersecurity budgets has also become a priority. With limited resources, companies focus on prioritizing investments in critical systems and data. This means not just purchasing the most expensive solutions, but choosing tools that provide maximum cost-efficiency, integrate with existing infrastructure, and require minimal maintenance resources. The emphasis is on developing internal competencies and fostering a culture of cybersecurity among all employees, as humans remain the weakest link in the defense chain.

The role of the state in shaping the cyber resilience of Ukrainian companies

The state plays a key role in coordinating and strengthening national cyber resilience. The National Cybersecurity Coordination Center (NCCC) and the Computer Emergency Response Team of Ukraine (CERT-UA) have become central links in the system of warning, response, and information exchange regarding cyber incidents. CERT-UA regularly publishes warnings about new threats, provides recommendations, and assists companies in investigating and mitigating the consequences of attacks. This ensures a unified vector in the fight against cyber aggression.

Legislative changes and regulations have also been significantly strengthened. The laws of Ukraine "On Basic Principles of Cybersecurity of Ukraine" and other regulatory acts establish increased requirements for the protection of critical infrastructure, personal data processing, and general compliance. In 2023, amendments were introduced that increase liability for violations in the field of cybersecurity, encouraging companies to implement protective mechanisms more thoroughly.

Public-private partnership has become the foundation for effective combat against cyber threats. Mechanisms for information exchange between government structures and the private sector allow for rapid response to new challenges. Joint exercises and training organized by the NCCC and CERT-UA with the participation of businesses increase the level of readiness for cyberattacks. Support programs, particularly regarding the implementation of cybersecurity standards, help companies modernize their defense systems.

International cooperation is also of immense importance. Ukraine receives significant assistance from international partners in the form of technologies, expertise, and financial resources. Exchanging experience with NATO and EU member states helps implement the best global practices and cybersecurity standards. This contributes to the formation of a unified cyber defense landscape, which is critical for increasing the overall cyber resilience of Ukrainian companies and the state as a whole.

How to evaluate the effectiveness of investments in cyber defense during the war?

Evaluating the effectiveness of investments in cyber defense during the war requires a review of traditional metrics. Instead of just the number of blocked attacks or detected incidents, indicators reflecting real resilience and recovery capability become key. Such metrics include Mean Time To Detect (MTTD), Mean Time To Respond (MTTR), and recovery indicators (Recovery Time Objective, RTO; Recovery Point Objective, RPO).

Calculating ROI in cybersecurity during the war is complex but possible. It is measured not only by direct financial gain but also by risk reduction, maintaining company reputation, ensuring business continuity, and protecting critical assets. For example, investments in backup and disaster recovery plans can prevent millions in losses from downtime or data loss, which is a clear ROI.

Regular audits and pentests remain indispensable tools for verifying the resilience of systems and processes. External independent experts can identify vulnerabilities that internal teams might miss, as well as verify the effectiveness of existing security tools. Since the full-scale invasion, the number of companies ordering such services has increased by over 60% compared to the pre-war period, which indicates an awareness of the importance of proactive verification.

Compliance with international standards, such as ISO 27001, the NIST Cybersecurity Framework, or PCI DSS, is an important foundation for building an effective cybersecurity system. However, during the war, the focus shifts to the real effectiveness of these standards in combat conditions, rather than just formal compliance. This requires adapting standards to unique threats and resource constraints. The effectiveness of investments is confirmed not by a certificate, but by the company's ability to withstand a real cyberattack.

Case studies of successful implementation of solutions, such as deploying multi-factor authentication at all levels or transitioning to a Secure Access Service Edge (SASE) architecture, show how technological innovations directly impact business indicators. Reducing the number of incidents, shortening downtime after attacks, and maintaining customer trust are the best confirmation of a sound cyber defense strategy.

Four years of full-scale war have radically changed the cybersecurity landscape in Ukraine, turning it into a critically important element of business strategy and national resilience. Ukrainian companies and state institutions have demonstrated an extraordinary ability to adapt by implementing proactive measures, developing internal competencies, and actively collaborating to counter the aggressor. Further strengthening of cyber resilience will require continuous investment in technology, staff training, and international cooperation, which will be the key to the successful functioning of the country's economy and digital space.

Frequently Asked Questions

What is cyber resilience in the context of war?

Cyber resilience during the war is an organization's ability to withstand cyberattacks, quickly restore functionality after incidents, and adapt to new threats. It includes not only technical protection but also organizational processes, staff training, and strategic planning.

How have the main vectors of cyberattacks on Ukrainian companies changed?

Attack vectors have evolved from financially motivated to targeted, destructive, and hybrid campaigns. There has been an increase in attacks on supply chains, cloud infrastructures, as well as the use of disinformation as an element of cyber operations to undermine trust and destabilize.

Why is the integration of Threat Intelligence critically important for Ukrainian companies?

Integrating Threat Intelligence allows Ukrainian companies to move from reactive to proactive defense. It enables the prediction of potential threats and the identification of new enemy tactics and tools, which significantly reduces the time to detect and respond to incidents.

What role does the state play in supporting business cyber resilience?

The state, through bodies such as the NCCC and CERT-UA, coordinates efforts, provides threat warnings, responds to incidents, and shapes the legislative framework. It also facilitates public-private partnerships and international cooperation to strengthen the overall level of cybersecurity.

How can small and medium-sized Ukrainian companies increase their cyber resilience with limited resources?

SMEs can focus on basic practices: regular software updates, multi-factor authentication, staff training, data backups, and the use of cloud services with built-in protection. Outsourcing cybersecurity and participating in state support programs are also effective paths.

Sources & materials

Intecracy Group products and solutions referenced in this article.

  1. Розробка ПЗ з використанням ШІ та AI-консалтинг — softengi.com