Few people have been more instrumental in protecting Ukraines private and government data, along with the countrys ongoing connectivity, than Shchyhol, who is the head of the State Service of Special Communications and Information Protection, the Ukrainian equivalent of the U.S. Cybersecurity and Infrastructure Security Agency. Since the hours before the ground invasion in February, when cyberattacks struck government and banking websites across Ukraine, Shchyhol has been coordinating with the U.S. and EU from a secure location in Kyiv, responding to cyberattacks while sharing with international allies his insights into strategies used by Russian hackers.
Overall, Ukraine has been doing much better in the cyberwar than expected few thought the country could repel a ground invasion and consistent cyberattacks simultaneously. There were certain losses: Russian forces eventually took control of the power plant near Zaporizhzhia, along with large swaths of the countrys southeast while establishing a botnet computer server near Kharkiv to spam cell phones with malicious text messages. Separate operations severely damaged governmental data centers. But despite constant aerial and cyber bombardment by Russian forces, SSSCIP has ensured those attacks were largely unsuccessful; civilians have been able to access government services and support directly from their mobile devices and computers.
I spoke with Shchyhol about the challenges of a digital war of attrition, how partner countries like the U.S. are assisting in that fight and what he sees as the future of cyberwarfare. We spoke through an interpreter over Zoom on June 27, less than a week after the European Commission and EU leaders granted Ukraine candidate status, the first step toward formal membership within the bloc.
This interview has been condensed and edited for clarity.
Kenneth R. Rosen: Viasat communications services went down as Russian forces invaded Ukraine, hindering communication by Ukrainian forces. But one of those high-speed satellite broadband connections was in my own home in northern Italy. Some 50,000 other European residents on the morning of the invasion found their internet routers inoperable. Its one instance Ive used to illustrate to my colleagues and peers the long reach of cyberattacks in the Russo-Ukrainian conflict. Was that a wake-up call for your European intelligence-sharing partners and a way for you as well to explain the difficulties faced by Ukraine?
Yurii Shchyhol: For Ukrainians, the first cyber world war started on Jan. 14, 2022, when there were attacks launched at the websites owned by state authorities. Twenty websites were defaced, and more than 90 information systems belonging to those government authorities were damaged.
In the early morning that day, I started talking to our European partners as well as our U.S. partners, their respective lines, ministries and government institutions, like CISA, and we started receiving and are still receiving assistance from them on a daily basis.
Right before the full-fledged invasion, the cyberattack, like you said, happened against Viasat. Some routers were deleted, especially those that were targeted to provide telecom services to the military units. In Germany, 5,000 wind turbines were attacked, so we can safely claim that it was not just a cyberattack on the whole of Ukraine, but against the civilized world.
So yes, youre right. The world has been awakened and we can observe that countries are more willing to cooperate on those issues and the level of cooperation will only intensify.
But what we need are not further sanctions and further efforts to curb cyberattacks, we also need for global security companies to leave the market of the Russian Federation. Only then can we ensure the victory will be ours, especially in cyberspace.
Rosen: While some of those cyberattacks were against government and military installations, others frequently hit telecommunications services, internet providers, hospitals, first responders and humanitarian aid organizations. What are some of the challenges faced by Ukraine in protecting such a wide, vulnerable attack surface?
Shchyhol: For the first four months of this invasion roughly more than 90 percent of cyberattacks were carried out against civilian sites. Of course, we were preparing ourselves for this, and in the last 18 months most of our preparations in advance were to be able to withstand widespread attacks against multiple targets. We ensured uninterrupted exchange of information between all [government and civil organizations], sharing information regarding the criteria for compromising networks. We also worked on building up the technical capabilities of government institutions so they could quickly gather server data, make copies, and share those copies with us [ahead of a Russian attack].
In all those efforts we had very strong support from our private sector. Its worth mentioning that a lot of private sector IT cybersecurity experts are either directly serving in the Armed Forces of Ukraine or my State Service or otherwise are indirectly involved in fighting against cyberattacks, and those private sector assistants of ours are world class experts who used to work in leading global companies taking care of their cybersecurity.
Rosen: When I last spoke with your colleague Victor Zoha, in February, he described the UA30 Cyber Center training facility your special service developed for the private sector. How has that grown since and was that instrumental in training the IT experts?
Shchyhol: This training center of ours launched into operation more than one year ago and over that period of time we conducted more than 100 training sessions for civilian contractors, private sector, military operators, all focused on cybersecurity. We conducted a number of hackathons and competitions. Even though we conducted a few training sessions after the beginning of the renewed conflict, the location of the training center is not safe. So were not using it that much right now.
This center was aimed to deepen the knowledge-sharing between the private sector and the government, those tasked with overseeing information protection across various government bodies and institutions. Its a hub that fosters the knowledge of the private sector. We treat it as a competence center that allows all the industries and sectors involved to grow by helping each other.
Rosen: Were referring to the efforts of private citizens, in part, when we talk about the private sector. Perhaps for the first time ever, hundreds of private citizens from across Ukraine and the world have volunteered to prevent, counteract and launch their own attacks in cyberspace in defense of Ukraine. The unifying force in defense of one country, which as far as campaigns go, continues to be rather unique. What has been the impact of the so-called civilian IT Army on Ukraines ability to defend against cyberattacks?
Shchyhol: This is the first time in the history of Ukraine, for sure, probably in the world, when the private sector, the cyberprofessionals, are not only doing what they can professionally defending the cyberspace of their country but they are also willing to defend it by any means. What youre referring to is an army currently comprised of more than 270,000 volunteers who are self-coordinating their efforts and who can decide, plan and execute any strikes on the Russian cyber infrastructure without even Ukraine getting involved in any shape or form. They do it on their own.
Other cybersecurity experts, under the guidance of my State Service, have been helpful in providing consultations to government institutions as to how to properly arrange the cybersecurity efforts, especially in the energy sector and critical infrastructure sites. Thats probably the reason none of the cyberattacks that were carried out in the past four months of this invasion has allowed the enemy to destroy any databases or cause any private data leakage.
Rosen: What are some of the lessons, over these last four months, of these ongoing attacks, that perhaps werent known or anticipated before February?
Shchyhol: In terms of their technical capabilities, so far the attackers have been using modified viruses and software that weve been exposed to before, like the Indestroyer2 virus, when they targeted and damaged our energy station here. Its nothing more than a modification of the virus they developed back in 2017. We all have to be aware that those enemy hackers are very well-sponsored and have access to unlimited finances, especially when they want to take something off the shelf and modify it and update it.
Rosen: At the beginning of our conversation you said that international technology companies should withdraw from the Russian Federation and youve written that the world should restrict Russias access to modern technologies. Such an effort to restrict their access, youve written, should be viewed as an international security priority. What technology specifically? Hardware, like servers and data processing computers? Or software, like those sold by western countries for law enforcement and data manipulation? Telecommunications?
Shchyhol: Any equipment that allows their software to be installed on servers, by way of restricting the use of those services globally so they wouldnt have access to them.
Were also urging the international organizations such as the ITU (International Telecommunication Union) that Russia should no longer be its member. Why? Because they otherwise can get access to innovations, research results by virtue of attending conferences, common meetings. So we are very much strongly in favor of getting Russia out of those organizations, especially those watchdogs that oversee the telecommunications industry of the world. They should not be able to participate in any events and get any IT information.
Rosen: Noting that you already work closely with NATOs cybersecurity command, and the international community, what does this further restriction, cooperation and a more efficient cyber-umbrella look like?
Shchyhol: The cyber-umbrella is something that should be placed over the whole world, not just Ukraine. It should be like an impenetrable wall. Russia would not gain access to any modern IT developments, not have access to innovations or new designs coming from the U.S., U.K. and Japan.
This is something that would pummel Russias ability to develop for themselves. Of course, they could design their own software, but without access to modern IT developments and without the ability to install it on any modern hardware those efforts would soon become obsolete.
We also have dire need for more competency and skills and knowledge; we dont have enough qualified staff. In order to raise more qualified personnel, we need to ensure the expedient exchange of information and coordination between professional and government institutions. That should be the global project for the next five to 10 years. Today the enemy can attack Ukraine, tomorrow the United States, or any other country helping to defend our land. Cyberspace is a unified space for everyone, not divided by borders. Thats why we need to learn to operate there together, especially in recognition of this attack on the civilized world perpetrated by Russia.
Rosen: How have U.S. Cyber Command and the National Security Agency operations been able to assist Ukraine with those aims in mind?
Shchyhol: Its an ongoing, continuous war, including the war in cyberspace. Thats why I wont share any details with you, but let me tell you that we do enjoy continuous cooperation. There is a constant synergy with them, both in terms of providing us with the assistance that we need to ensure proper protection and safety of our websites and our cyberspace, especially of government institutions and military-related installations, but also they help us with their experts, some of whom are on-site here in Ukraine and are providing on-going consultations.
Like in further supply of heavy weapons and other forms of weaponry, the same is true for cybersecurity. We expect that level of assistance, of those supplies, will only increase because only in this manner can we together ensure our joint victory against our common enemy.
Rosen: Weve talked a great deal about the hidden cyberwarfare, of a war without borders, but what digital communications devices, or physical gear and assets, sent by the U.S. in aid packages have been helpful and why?
Shchyhol: The most helpful so far was the SpaceX technology, the Starlinks, weve been sent. So far weve received more than 10,000 terminals. What those have helped us with was a relaunch of destroyed infrastructure in those communities were liberating, providing backup copying services to regional and local governments whose digital services [like healthcare cards, tax and travel documents, vehicle and home registrations] are accessed by Ukrainian civilians. It has also aided the repair of critical infrastructure sites.
Second to this have been the servers and mobile data centers. Those have allowed us in a very short time span to arrange backup copies of our government institutions, agencies, state registries, and locate them in safe regions, or at least locations that the enemy couldnt easily access. Its allowed for the continuous operation of our government.
And, the third I wouldnt say its the last as we dont have time for the exhaustive list are software and technologies that weve received access to now [that were too expensive before the invasion]. After the invasion, industry leaders started providing software free of charge or allowing us full access like Amazon, which provided Ukraine with a private cloud, allowing us to administer data from the state registries.
It goes without saying that were not only consuming someone elses services especially when they come free of charge. Even now, when the war is still raging, were taking care of our cybersecurity by investing more funds into procuring what we need. Last week, the government allocated additional funds from the national budget to finalize the preparation of a national backup center. Were ready to buy if its exactly what we need.
Rosen: Most of those vendors are Western-based companies. In April, the U.S., U.K., Canada, Australia and New Zealand, part of the Five Eyes intelligence sharing cooperative, said that Russia was planning a largescale cyberattack against those countries supporting Ukraine. Back then there was no shortage of protracted fears in the security industry that a global cyberwar could trigger Article 5 of NATO. But that constant threat to Western nations seems to have been downgraded in the news cycle along with coverage of the war.
Shchyhol: Russia is already attacking the whole world. Those cyberattacks will continue regardless of whats happening on land. Ukraine can win this war with conventional weapons, but the war in cyberspace will not be over. Ukraine is not capable of destroying Russia as a country, its more likely to destroy itself.
Thats why we all have to be ready for the following scenario to unfold: Those western countries and companies that are supporting the Ukrainian fight against Russia will be and are already under the constant threat of cyberattacks. This cyberwar will continue even after the conventional war stops.
The fact that in the last two months there was a relative lull in the number and quality of cyberattacks of our enemy, both against Ukraine and the rest of the world, only follows the usual Russian tactics, which are that they are accumulating efforts and resources, readying themselves for a new attack which will be coming. It will be widespread, probably global. Right now our task here is not to miss it, to stay awake and aware to that threat.
Here is the original post:
The Man at the Center of the New Cyber World War - POLITICO
- Google researchers have cracked a key internet security tool - Recode [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Letter: Internet security is in jeopardy - INFORUM [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- New internet security device launched to safeguard schools against child abuse - Phys.Org [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Everything You Need to Know About Cloudbleed, the Latest Internet Security Disaster - Gizmodo [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Data from internet-connected teddy bears held ransom, security expert says - Fox News [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Emsisoft Internet Security 2017.2.0.7219 - TechCentral.ie [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- What you need to know about 'Cloudbleed,' the latest internet security bug - Globalnews.ca [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Google cracks longtime pillar of internet security - MarketWatch [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- BullGuard | Internet Security and Antivirus protection ... [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet Storm Center - SANS Internet Storm Center [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Internet-connected 'smart' devices are dunces about security - ABC News [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Derry internet security expert warns that advanced internet technology 'a risk to us all' - Derry Now [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Firewall Test, Web Tools and Free Internet Security Audit ... [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security in the spotlight: How is the internet safer today than it was 20 years ago? - Mobile Business Insights (blog) [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Jim Mullen: Unsocial internet security | Columnists | auburnpub.com - Auburn Citizen [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Internet security company launches a perfume line to promote cybersecurity - Mashable [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Internet security - Wikipedia [Last Updated On: March 12th, 2017] [Originally Added On: March 12th, 2017]
- Are you undermining your web security by checking on it with the wrong tools? - The Register [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Bruce Schneier on New Security Threats from the Internet of Things - Linux.com (blog) [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Carpe Diem: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Motivation Monday: home internet security - KFOX El Paso [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Medical records of 26m patients at risk because of GP surgeries' failing internet security - The Sun [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Free Internet Security | Why Comodo Internet Security Suite ... [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Internet Security Software | Trend Micro USA [Last Updated On: March 18th, 2017] [Originally Added On: March 18th, 2017]
- Fix crap Internet of Things security, booms Internet daddy Cerf - The Register [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- Internet of Things security: What happens when every device is smart and you don't even know it? - ZDNet [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- CUJO is cuter than Wall-E, and it's the only internet security device you'll ever need - Yahoo News [Last Updated On: March 21st, 2017] [Originally Added On: March 21st, 2017]
- The Senate just voted to undo landmark rules covering your Internet privacy - Washington Post [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- What the Cloudbleed disaster says about the state of internet security - Information Age [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Google Has Declared Symantec Harmful To Internet Security - UPROXX [Last Updated On: March 25th, 2017] [Originally Added On: March 25th, 2017]
- Internet Security Analysts: North Korea Is Planning a Global Bank Heist - Breitbart News [Last Updated On: March 28th, 2017] [Originally Added On: March 28th, 2017]
- Internet Security Firm Confirms WikiLeaks 'Vault 7' At Least 40 Cyberattacks Tied to the CIA - The Ring of Fire Network [Last Updated On: April 14th, 2017] [Originally Added On: April 14th, 2017]
- Homeland Security warns of 'BrickerBot' malware that destroys unsecured internet-connected devices - ZDNet [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- A Global Industry First: Industrial Internet Consortium and Plattform Industrie 4.0 to Host Joint IIoT Security ... - Business Wire (press release) [Last Updated On: April 20th, 2017] [Originally Added On: April 20th, 2017]
- Mucheru urges private sector to boost investment in internet security - The Standard (press release) [Last Updated On: April 25th, 2017] [Originally Added On: April 25th, 2017]
- Cloudflare debuts a security solution for IoT - TechCrunch [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Russian-controlled telecom hijacks financial services' Internet traffic - Ars Technica [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- Avira Internet Security Suite v15.0.26 - TechCentral.ie [Last Updated On: April 28th, 2017] [Originally Added On: April 28th, 2017]
- NSA To Limit Some Collection Of Internet Communication - NPR [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- Report Indicates '10 Concerts' Facebook Trend Could Compromise Your Internet Security - Complex [Last Updated On: April 29th, 2017] [Originally Added On: April 29th, 2017]
- "Improving the World" through Internet Security: Chatting with David Gorodyansky, CEO of AnchorFree - Huffington Post [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Don't Fall For This Tech Support Scam Targeting PC Users - KTLA [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Yikes! Antivirus Software Fails Basic Security Tests - Tom's Guide [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Watch Hackers Sabotage an Industrial Robot Arm - WIRED [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Decoding Internet Security: Spear phishing - Washington Post [Last Updated On: May 5th, 2017] [Originally Added On: May 5th, 2017]
- From the Desk of Jay Fallis: To internet vote, or not to internet vote - BarrieToday [Last Updated On: May 7th, 2017] [Originally Added On: May 7th, 2017]
- Crippling cyberattack continues to spread around the world - Los Angeles Times [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- Cyber Security Experts: Russia Disproportionately Targeted by Malware - Voice of America [Last Updated On: May 14th, 2017] [Originally Added On: May 14th, 2017]
- The Latest: 29000 Chinese institutions hit by cyberattack - ABC News [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- Cyberattack Aftershock Feared as US Warns of Its Complexity - New York Times [Last Updated On: May 15th, 2017] [Originally Added On: May 15th, 2017]
- This week's poll: Priorities for improving internet security - The Engineer [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Akamai Releases First Quarter 2017 State of the Internet / Security Report - PR Newswire (press release) [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Do Macs get viruses? - PC Advisor [Last Updated On: May 18th, 2017] [Originally Added On: May 18th, 2017]
- Massive Ransomware Attack Underscores Threats To Internet Security - Benzinga [Last Updated On: May 19th, 2017] [Originally Added On: May 19th, 2017]
- Security News This Week: Hoo-Boy, Mar-a-Lago's Internet Is Insecure - WIRED [Last Updated On: May 20th, 2017] [Originally Added On: May 20th, 2017]
- Internet security firm calls for law to compel information sharing to ... - The Star, Kenya [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- Check It Out: No need to unplug after reading books on internet security - The Columbian [Last Updated On: May 22nd, 2017] [Originally Added On: May 22nd, 2017]
- How to beat security threats to 'internet of things' - BBC News - BBC News [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Best Mac antivirus 2017 - Macworld UK [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Avira, Kaspersky Top Windows 10 Antivirus Tests - Tom's Guide [Last Updated On: May 25th, 2017] [Originally Added On: May 25th, 2017]
- Paranoid about internet security? Here are the most secure OS options - The American Genius [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- Blockchain Offers Hope for the Broken Internet - Fortune [Last Updated On: May 28th, 2017] [Originally Added On: May 28th, 2017]
- New uses for RFID and security for the internet of things - Phys.Org [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Security Best Practices for the Internet of Things - Web Host Industry Review [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Internet infrastructure security guidelines for Africa unveiled - Premium Times [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- In addressing internet security issues, make sure to provide solutions - Minneapolis Star Tribune [Last Updated On: May 31st, 2017] [Originally Added On: May 31st, 2017]
- Whistic Partners with the Center for Internet Security to Extend the ... - PR Web (press release) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet Security Alliance: NIST framework metrics should focus on threats - Inside Cybersecurity (subscription) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China cyber-security law will keep citizens' data within the Great Firewall - The Register [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Cyber security: Africa gets Internet security guidelines - TheNewsGuru [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- China to Implement Its First Law on Internet Security After Ransomware Attack - Sputnik International [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Decoding Internet Security: Ransomware - Washington Post [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- Internet security upgrade on course - Business Daily (press release) (blog) [Last Updated On: June 1st, 2017] [Originally Added On: June 1st, 2017]
- What's the Safest Laptop For Internet Security? - HuffPost [Last Updated On: June 2nd, 2017] [Originally Added On: June 2nd, 2017]
- Every Day Is Internet Security Day - The Chief-Leader [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- 5 Reasons why internet security is crucial in 2017 - Techworm [Last Updated On: June 3rd, 2017] [Originally Added On: June 3rd, 2017]
- Are Pop-Ups An Internet Security Threat? - Good Herald [Last Updated On: June 4th, 2017] [Originally Added On: June 4th, 2017]
- 3 Ways Software Programs Can Help With Internet Security in 2017 - Geek Snack [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Inside Social Security: Make every day your internet security day - Santa Ynez Valley News [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- SOCIAL SECURITY: Every day is internet security day - Palm Beach Post [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]