From the frontline: Ukraine’s cyber security learnings for EU founders
In December 2015, Russian hackers managed to cut electricity for about 225,000 customers across three Ukrainian regions. They had been inside those networks for months, and nobody had noticed. By 2024, Ukraine faced 4,315 registered incidents in a single year, with 59 of them labelled as critical. The previous year saw 2,543 attacks, with 364 […] The post From the frontline: Ukraine’s cyber…
In December 2015, Russian hackers infiltrated Ukraine's networks and controlled electricity for about 225,000 customers across three regions for months without being detected. By 2024, Ukraine recorded 4,315 incidents, with 59 deemed critical and 364 serious. These findings are detailed in "Four Years on the Digital Frontline", a report by IronCyber and SET University.
From these experiences, Ukraine has developed three key practices: recognizing existing intrusions, learning from past incidents, and maintaining operations during disruptions.
Ukraine's lesson applies to European firms. In 2023, one mobile operator, Kyivstar, had its systems controlled by attackers for at least seven months before being identified. The intrusion was discovered when service was interrupted for about one day in December, affecting around 24 million users. Most attacks in Ukraine during this period were linked to extortion or theft of funds, often exploiting compromised credentials, exposed devices, or third-party access.
Even software itself can be a target; in September 2024, Russian hackers distributed malware via Signal disguised as a military app called GRISELDA. They also sent concealed connections back to their systems through seemingly routine email attachments. Neither of these attacks required any sophisticated methods; instead, they relied on users trusting these tools.
Before attending your next board meeting, you need to know two things: the number of systems accessible from the internet and how quickly you would detect an unauthorized user with valid credentials. If you cannot answer the latter, this should be your top priority. Each incident, even those not fully resolved, should be analyzed and turned into procedures, detection rules, and hardening measures.
Ukrainian cybersecurity has improved not just through technology but also by learning from each incident. Defenders found malware designed to control grid substation equipment in 2023, which had not yet become fully functional. This provided invaluable two-month warning. To stay resilient, backup systems should still function even if the primary fails.
Additionally, sharing stolen documents and technical drawings can act as a deterrent. By mid-2025, AI would be used by cybercriminals to quickly sift through exfiltrated data and compromised mailboxes for valuable information. Therefore, maintaining reliable backups, ensuring critical dependencies can operate independently, and preparing customer communication ahead of crises are all crucial.
The main threat is not always evident. In 2024, Russian hackers targeted Ukrainian defense manufacturers for their design data, including sensitive information about weapons and protection technologies. There was no ransom demand, encryption, or visible system failure. The stolen data was used for research purposes only, with no ransom or visible damage.
Founders should ensure sensitive development data is securely protected and all access is logged. Microsoft's 2025 Digital Defense Report found that the 10 countries most impacted by Russian cyber activities outside Ukraine, all NATO members, experienced a 25% increase in attacks from the previous year. Four steps can be taken immediately, without significant financial investment: detailed documentation of all incidents, including near misses, benchmarking against industry reports, and recording the decision-making process during crisis management.
It's also essential to understand all dependencies, not just owned systems, as another party's incident could affect your operations.
Written by urgent.news from EU-Startups's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.