How Russian Intelligence operatives have attacked Ukraine in cyberspace: Interview with Ukrainian Security Service
Aug 21, 2023
auto_awesome
Dmitri Alperovitch, Patrick Gray, and Illia Vitiuk discuss Russia's cyber attacks on Ukraine, including turning off the power grid in 2015 and hacking satellite communications. They explore Ukraine's successful defense strategies, collaboration with Western companies, intelligence collection on battlefield systems, and tactics used by Russian intelligence operatives.
Ukraine's experience with Russian cyberattacks has led to the development of effective defense strategies and close cooperation with international partners.
Russia's cyber tactics have evolved from disruptive attacks to reconnaissance and information campaigns, emphasizing the need for ongoing support to secure critical infrastructure.
Deep dives
The Scope of Responsibility of the Cybersecurity Department
The Cybersecurity Department of the Security Service of Ukraine (SPU) is responsible for countering cyber threats, ensuring the security of critical IT infrastructure, and addressing information campaigns, particularly those originating from Russia. The department acts as a combination of counterintelligence, law enforcement, and cybersecurity agency, encompassing functions similar to those of the FBI and NSA in the United States. Its responsibilities include incident response, attribution, investigation, and criminal prosecution of cyberattacks. The department also focuses on protecting critical IT systems from potential vulnerabilities, ensuring they are not compromised by Russian software or any external threats.
Ukraine's Preparedness and Experience in Cyber Defense
Ukraine has gained significant experience and preparatory measures in cyber defense due to its encounters with Russian aggression dating back to 2014. The country faced destructive cyber attacks against power and transportation infrastructure, including incidents like the BlackEnergy attack that caused a six-hour blackout for 40 million people. Ukraine has leveraged this experience to strengthen its legislation, adopt cybersecurity strategies, develop effective tools, and improve its defenses. The continuous exposure to cyber threats has enabled Ukraine to adapt quickly and effectively respond to attacks. This experience has also shaped the country's policies, coordination mechanisms, and cooperation with international partners.
Russia's Cyber Tactics and Ukraine's Defense Strategies
Russia's cyber tactics have evolved over time, fueled by special services like GRU and FSB. While they initially focused on disruptive attacks targeting critical infrastructure, including power grids, railroads, and industrial control systems, their recent approach has shifted towards reconnaissance, information campaigns, website defacements, and psychological disinformation. Ukraine's defenses have proven successful due to its ability to adapt, gain deeper understanding of Russian tactics, and establish effective cooperation between the government, military, intelligence agencies, and international partners. This collaborative approach, combined with the nation's resilience, has thwarted many Russian cyber operations. However, the growing scale and sophistication of attacks emphasize the need for ongoing support and continuous improvement to secure critical infrastructure.
International Collaboration and Assistance in Ukraine's Cybersecurity
Ukraine has received extensive assistance from international partners, including cybersecurity companies, governments, and organizations. Companies like Microsoft and Cisco have provided free tools, sensors, and dedicated personnel to help Ukraine tackle cyber threats. US Cyber Command has supported Ukraine through joint inspections of critical infrastructure, providing hardware, software, and expertise. Other countries and organizations have also contributed resources and expertise. Ukraine encourages further collaboration and welcomes assistance in areas such as cloud migration, hardware, software, advanced threat detection, security operations centers, and capacity building. The aim is to establish a robust and gold-standard cybersecurity system capable of countering the evolving, aggressive cyber potential wielded by Russia.
In this joint Geopolitics Decanted and Risky Business feature interview, Dmitri Alperovitch and Patrick Gray talk to Illia Vitiuk, the Head of the Department of Cyber and Information Security of the Security Service of Ukraine (SBU) about the cyber dimension to Russia's invasion.
From turning off Ukraine's power grid with a cyber attack in 2015, to the Viasat satellite communications hack in 2022, Russia's intelligence services are world renowned for executing creative destructive cyber campaigns. Despite this, after a year and a half of Russia waging war on Ukraine its power grid is up, its telcos are functioning and its banks are still processing transactions.
How has Ukraine been able to withstand Russia's onslaught in the cyber domain? Illia Vitiuk joins us to reveal insights into how Russian intelligence services are operating in Ukraine, and how the SBU is countering them.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode