Expert View 9 min read

What Ukrainian companies learned about cyber resilience during the war

Four years of full-scale war have radically changed the cybersecurity landscape, demanding unprecedented adaptation from businesses. It is the cyber resilience of Ukrainian...

Four years of full-scale war have radically changed the cybersecurity landscape, demanding unprecedented adaptation from businesses. Cyber resilience of Ukrainian companies has become not just a technical task, but a critical condition for survival and operational continuity. Since February 2022, Ukrainian enterprises, from small businesses to large IT corporations and critical infrastructure facilities, have faced significantly intensified pressure from state-sponsored cybercriminals and hacktivists. This period has revealed both vulnerabilities and an extraordinary capacity for innovation and rapid restructuring of defensive strategies. The editorial team at ua.software examines how the cyber resilience of Ukrainian companies has evolved and what key lessons domestic businesses have learned during these challenging times.

New vectors of cyberattacks and their impact on the cyber resilience of Ukrainian companies

Since the beginning of the full-scale aggression, the motivation behind cyberattacks has shifted significantly. While financially motivated cybercrimes previously dominated, the primary driver is now the destruction and destabilization of Ukrainian infrastructure. The aggressor purposefully uses cyberattacks as a tool of hybrid warfare, aiming to undermine state institutions, the economy, and social stability. This required Ukrainian companies to immediately rethink their security priorities.

One of the most striking examples has been targeted attacks on critical infrastructure, particularly in the energy sector and telecommunications. There have been documented cases of the use of wiper-type malware, such as Industroyer2 or CaddyWiper, aimed at the complete destruction of data and the disabling of systems. These attacks not only caused operational disruptions but also had a psychological impact, attempting to sow panic and distrust. According to the SSSCIP, the number of cyberattacks on critical infrastructure has increased manifold since February 2022.

In addition to direct destruction, there is a rise in disinformation campaigns that use cyber tools to spread fake news and manipulate public opinion. There has also been a significant increase in supply chain attacks, where attackers compromise software or services used by many companies. This creates a cascading effect, threatening entire sectors of the economy, including the Ukrainian IT sector, which is often part of global supply chains.

Adapting Security Operations: strategies and challenges

In the face of constant and intensive cyberattacks, Ukrainian companies have been forced to radically revise their approaches to Security Operations. The traditional model, focused primarily on post-incident response, proved insufficient. Instead, there has been an active transition to a proactive model, where threat hunting and deep analytics play a key role.

The role of incident response and threat intelligence has been significantly strengthened. Security teams no longer just wait for alerts to trigger; they actively search for signs of compromise and analyze the tactics, techniques, and procedures (TTPs) of potential attackers. Sharing threat information between companies and state structures, such as the NCCC, has become a vital element of this strategy. Approximately 60% of Ukrainian IT companies have invested heavily in developing their SOC centers or engaging external cybersecurity experts over the past year.

The use of cloud technologies has also become a critical factor in increasing resilience and security scalability. Cloud platforms offer more flexible tools for backup, disaster recovery, and the implementation of distributed security systems, which reduces single points of failure. In parallel, principles of Zero Trust and micro-segmentation are being actively implemented, assuming that no user or device should be trusted by default, and access is granted only when necessary and after thorough verification. This minimizes potential damage in the event of an individual element being compromised.

At the same time, staffing remains one of the biggest challenges. The demand for qualified cybersecurity professionals significantly exceeds supply. This underscores the need for continuous training and upskilling of existing teams, as well as the creation of new educational programs to prepare future experts. Without an adequate level of expertise, even the most advanced technologies prove ineffective.

State policy and regulation to strengthen the cyber resilience of Ukrainian companies

The role of the state in shaping national cyber resilience has taken on special significance during the full-scale war. The National Cybersecurity Coordination Center (NCCC) and the State Service of Special Communications and Information Protection of Ukraine (SSSCIP) have become key bodies coordinating efforts to counter cyber threats, shaping policy, and developing strategic documents. Their activities include threat monitoring, information sharing, and providing recommendations for the private sector.

The state has also initiated a number of cybersecurity support programs and cooperation with the private sector. One example is the Diia.City initiative, which creates favorable conditions for IT business development, including aspects of cyber defense. Within the framework of such programs, companies can gain access to up-to-date threat intelligence, participate in joint exercises, and benefit from certain incentives for implementing high security standards. Such synergy between the state and business is critical for forming a strong shield against cyberattacks.

International cooperation and the exchange of experience with partners from the European Union, the USA, and other countries have also significantly strengthened national cyber resilience. Ukraine receives assistance in the form of technology, expertise, and funding, which allows for the faster adoption of advanced global practices. Participation in international exercises and joint cyber defense operations helps Ukrainian specialists improve their qualifications and stay up to date with the latest methods of countering cyber threats. This cooperation is two-way, as Ukraine, being on the front line of the cyber war, also shares unique experience with its partners.

Special attention is paid to compliance requirements and legislative changes aimed at protecting critical infrastructure and personal data. Implementing new regulatory norms that meet international standards is mandatory for companies that work with sensitive information or are part of critical infrastructure. This includes enhanced requirements for security audits, risk management, and incident response, which generally contributes to raising the overall level of cyber resilience of Ukrainian companies.

How can Ukrainian companies maintain a high level of cyber resilience in the long term?

Maintaining a high level of cyber resilience in the long term requires a comprehensive approach and constant investment. First and foremost, this concerns investments in advanced technologies. The use of artificial intelligence (AI) and machine learning (ML) for automation of threat detection and response is becoming a necessity rather than a luxury. These technologies allow for processing vast amounts of data, detecting anomalies, and responding to incidents much faster than is possible with human resources alone.

Equally important is the development of a cybersecurity culture within companies. Technologies are only effective when used correctly, and the human factor often remains the weakest link. Regular training, phishing simulations, and increasing general employee awareness of cyber threats are critical. Every employee must understand their role in the overall security system and their responsibility for following security rules.

Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP) must become a priority for every organization. This is not just about data backup, but about developing detailed action plans for large-scale disruptions that allow for the rapid restoration of critical operations. Companies that have well-developed and regularly tested BCP/DRP plans return to normal operations much faster after cyberattacks or other emergencies.

Finally, the adoption of international cybersecurity standards and frameworks is the foundation for building a reliable defense system. Such standards include:

  • ISO 27001 (Information Security Management Systems);
  • NIST Cybersecurity Framework;
  • PCI DSS (Payment Card Industry Data Security Standard).

Adhering to these standards provides proven methodologies for information security management, risk assessment, and the implementation of effective controls. This not only increases internal resilience but also strengthens the trust of partners and clients, which is especially important for Ukrainian companies operating in international markets.

According to Anton Marrero, a member of the supervisory board and management board of Intecracy Ventures, "investments in cybersecurity today are not expenses, but a strategic investment in the future. Ukrainian companies are demonstrating an impressive ability to adapt, and these lessons will become the foundation for building a powerful national cyber resilience that will serve as an example to the world."

Four years of full-scale war have been a harsh but valuable test for Ukrainian business in the context of cybersecurity. From the transformation of attack vectors to the deep restructuring of Security Operations and the strengthening of state support—every aspect of cyber resilience has undergone significant changes. Ukrainian companies have shown an extraordinary capacity for adaptation, innovation, and learning under unprecedented pressure. The lessons learned during this period form a solid foundation for the further development of national cyber resilience, which will not only protect businesses from current threats but also facilitate their growth and integration into the global digital economy. Constant vigilance, investment in technology and human capital, and active cooperation with the state and international partners will remain key elements of this strategy.

Frequently Asked Questions

What is cyber resilience in the context of war?

Cyber resilience during wartime is the ability of a company or organization to continuously provide its services and protect data, even under intensive and targeted cyberattacks. This includes not only technical protection but also processes for recovery, response, and adaptation to new threats.

How have the main cybersecurity threats changed over the last four years?

Over the last four years, the main threats have evolved from being primarily financially motivated to being destructive, aimed at disrupting operations and destroying data. There has been an increase in targeted attacks on critical infrastructure, as well as the use of wipers and sophisticated disinformation campaigns.

Why is cooperation with the state important for business cybersecurity?

Cooperation with the state is critical for business cybersecurity because it provides for the exchange of threat intelligence, access to national cyber defense systems, and the harmonization of regulatory requirements. State bodies, such as the NCCC, provide analytical support and coordinate actions to strengthen national cyber resilience.

What key investments should Ukrainian companies make to strengthen cyber resilience?

Ukrainian companies should invest in modern solutions for threat detection and response (EDR, SIEM), cloud services to increase fault tolerance, as well as staff training and the development of internal expertise. Investments in business continuity planning and disaster recovery are also essential.

Are there international standards that help Ukrainian companies improve cyber resilience?

Yes, international standards such as ISO 27001 (information security management systems) and the NIST framework (US National Institute of Standards and Technology) are valuable benchmarks. Their implementation helps Ukrainian companies systematize cybersecurity processes, increase the level of protection, and meet global compliance requirements.