Graft and Grit
Live
Stages

Ukraine's Cyber Lessons for EU Founders

A report details Ukraine's adaptation to thousands of cyberattacks, offering founders three core habits: map internal systems, learn from every incident

A report details Ukraine's adaptation to thousands of cyberattacks, offering founders three core habits: map internal...

Ukraine faced 4,315 registered cyber incidents in 2024, with 59 labelled as critical. A new report, Four Years on the Digital Frontline by IronCyber and SET University, argues the country's hard-won cybersecurity habits are directly applicable to European startup founders.

The report distills Ukraine's experience into three core principles. Founders must understand what is already inside their systems, learn systematically from incidents, and ensure operations can continue when primary systems fail.

Someone can lurk for months

Attackers held access inside Kyivstar, Ukraine's largest mobile operator, for at least seven months before the takedown. The visible service outage in December 2023 lasted just one day but affected roughly 24 million people.

The initial access often involves simple methods. By late 2023, about 40% of registered incidents in Ukraine involved extortion or theft of funds. Attackers used compromised credentials, exposed edge devices, or purchased access from brokers. Trusted tools can also be a vector. In 2024, Russian hackers distributed malware via Signal, disguised as a military app, and sent malicious files packaged as routine admin emails.

The report advises founders to answer two key questions before their next board meeting: how many systems are internet-accessible, and how long it would take to spot an outsider using valid credentials. "If you can’t answer the second, make it your top priority," the report states, noting that investors and potential buyers will ask the same.

Every incident builds a procedure

Ukraine's cybersecurity progress between 2015 and 2024 was not just about better tools. Teams treated every incident as material for improvement. Each attack was analyzed, with findings fed into new procedures, detection rules, and system hardening.

This cycle of adaptation yielded results. Serious incidents dropped from 364 in 2023 to just 59 in 2024. Even unfinished attacker work is valuable to study. In 2023, defenders found malware built to send commands to grid substation equipment that was still unreliable. Studying it provided months of warning.

The report suggests a practical step: pick three recent incidents from your sector, write up what happened, and walk your team through them. Many national cyber response teams publish this raw material for free.

Build for resilience

When systems fail, low-tech solutions can keep operations running. Ukrainian power engineers avoided total blackouts by manually isolating sections, rerouting power, and using mechanical overrides. For ransomware, having tested backups remains the only sure way to keep running without paying.

Adaptation extends to new technologies. Drone teams switched to fibre-optic tethers and developed optical navigation when radio and satellite links were jammed. Resilience also involves preparing for non-technical pressure. In Ukraine, stolen documents and technical drawings were published deliberately. By 2025, attackers were using AI to rapidly sift through exfiltrated data from compromised mailboxes.

Founders are urged to ensure they have backups they have actually restored from, a way for their product to run without its most critical dependency, and customer communication prepared in advance.

Protect hidden assets

Some attacks aim for disruption, but others seek silent theft. In 2024, Russian hackers targeted Ukrainian defence manufacturers for design data on weapons and protection technology. There was no ransom or visible outage. The damage is deferred, with stolen data enriching a competitor's research programme.

Many founders lock down production systems but leave design files, training data, and test results on shared drives with open access. The report advises doing the opposite: lock down sensitive development data and log every access attempt.

These lessons are not theoretical. The methods used against Ukraine are widespread. Microsoft’s 2025 Digital Defense Report found the 10 countries most affected by Russian cyber activity outside Ukraine were all NATO members, representing a 25% increase year-on-year. The report concludes by urging founders to map everything they depend on, not just what they own, as shared suppliers and service providers are how someone else's incident becomes yours.

Topics

#Stages

Related coverage

More from Stages