Commission

Cybersecurity Commission

A country under ~15 cyberattacks a day has one way out — its own school of cyber defence and its own solutions.

CERT-UA records an average of 15 cyber incidents per day and tracks more than 150 threat clusters; in 2026 the enemy shifted from mass primitive attempts to targeted operations using AI and social engineering — hitting hospitals, local governments, defence systems and business. In these conditions cybersecurity is not a cost line but a condition of existence for companies and the country.

The commission's position is principled: the most-attacked nation in the world must have its own defence industry. Ukraine's experience of repelling attacks is a unique export asset, and Ukrainian cybersecurity solutions should first of all protect Ukrainian institutions rather than lose tenders to foreign boxes. Security expertise forged by war is economic patriotism too.

Goals

What we protect

The commission's four priorities.

Member cyber resilience

A minimum protection standard for every member company: from MFA and backups to an incident response plan.

Threat intelligence sharing

A fast channel between members for phishing, compromise and vulnerability alerts — an attack on one becomes a vaccine for all.

Ukrainian security solutions

Promoting domestic cybersecurity products in the public sector and business — a school hardened by real attacks deserves trust.

Smart NIS2 adaptation

Harmonising with European requirements without the paper bureaucracy that kills small teams.

Tasks

What we do daily

01

Attack warnings

We promptly share information about active campaigns with members — from fake 'update the app' mailouts to attacks on member brands.

02

Audit and recommendations

We help member companies assess their security: checklists, pen tests by specialised members, incident post-mortems.

03

Liaison with CERT-UA and SSSCIP

We keep a direct channel with state response teams — industry and state must see one threat picture.

Methods

How we work

Trust and confidentiality

We discuss member incidents in the language of lessons, not names — otherwise intelligence sharing is impossible.

Practices from practitioners

Recommendations are written by engineers who repel attacks daily, not by template consultants.

Training people

Most breaches start with an email — regular staff drills are cheaper than any incident.

Initiatives

Current initiatives

Brand attack registry

Public tracking of phishing campaigns against member products — like the fake Medoc sites — with user guidance.

Minimum cyber standard

A practical baseline-hygiene checklist for small and medium IT companies: a week to adopt, no enterprise budgets.

Customer cyber education

Joint materials for members' clients: how to tell an official update from an attack.

Let's defend the industry together

Does your team repel attacks or build security solutions? The commission needs your experience.