Feature Interview: How Sandworm prepared Ukraine for a cyber war
Aug 20, 2023
auto_awesome
Head of Cyber and Information Security at SBU, Illia Vitiuk, discusses Russia's cyber warfare on Ukraine and how Ukraine has countered attacks. Topics include power grid hacks, telco disruptions, and SBU strategies to combat Russian intelligence services.
Ukraine's cybersecurity measures evolved from past attacks, enhancing defense strategies.
Critical industry support and international collaborations bolstered Ukraine's cyber defenses post-invasion.
Russia's cyber warfare lacked coherence, highlighting vulnerabilities in their aggressive approach.
Deep dives
Overview of Ukrainian Cybersecurity Department's Responsibilities
The head of the Cybersecurity Department of the Security Service of Ukraine plays a crucial role in countering cyber threats, safeguarding critical IT infrastructure, and combating malicious information campaigns primarily originating from Russia. The department functions as a blend of a counterintelligence agency, enforcer of cybersecurity, and cyber defense entity, akin to a mix of NSA and FBI responsibilities in the US. Their tasks include incident response, investigation, attribution, and ensuring the protection of critical IT systems.
Preparedness and Experience from Previous Cyber Attacks
Ukraine's readiness for the recent Russian aggression stemmed from a history of cyber warfare dating back to 2014, which brought about valuable experience and lessons. Destructive cyber attacks aimed at power infrastructure and transport systems in previous years provided crucial insights into defense strategies. The Ukrainian cybersecurity measures evolved through legislation improvements, cybersecurity strategy updates, and reinforcement of tools and techniques to counter aggressive cyber activities.
Technological Enhancements and Collaborations for Cyber Defense
Post-Russian invasion, Ukraine received critical support from industry giants like Microsoft and Cisco, providing tools, telemetry sensors, and dedicated teams to enhance cyber defenses. Cooperation with US Cyber Command facilitated inspections of vital infrastructure, along with hardware and software assistance. The emphasis on cloud migration augmented data protection, showcasing the significance of international collaborations and technological advancements in fortifying cybersecurity measures.
Discovery and Response to Advanced GRU Sandroid Malware
The detection of sophisticated Android malware targeting military systems underscored the evolving nature of cyber threats faced by Ukraine. The malicious malware customized for military situational awareness applications like Delta and Crapiva showcased meticulous planning and covert infiltration attempts. Additionally, the rapid response and decisive actions in identifying and neutralizing the malware through joint efforts depicted a strategic approach to combating intricate cyber threats.
Evaluating Russia's Cyber Strategies and Impact on Ukrainian Cyber Defense
Russia's cyber assaults aimed at causing chaos and disruption during the invasion underscored a multifaceted cyber warfare approach. The apparent lack of a coherent strategy and reliance on widespread attacks to sow confusion revealed vulnerabilities in Russia's cyber operations. Despite facing increasing cyber threats, Ukraine's proactive stance in coordination with global cybersecurity entities demonstrated resilience and adaptability in countering sophisticated cyber incursions.
In this joint Risky Business and Geopolitics Decanted feature interview, Patrick Gray and Dmitri Alperovitch talk to Illia Vitiuk, the Head of the Department of Cyber and Information Security of the Security Service of Ukraine (SBU) about the cyber dimension to Russia’s invasion.
From turning off Ukraine’s power grid with a cyber attack in 2015 to the Viasat hack in 2022, Russia’s intelligence services are world renowned for executing creative destructive cyber campaigns. Despite this, after a year and a half of Russia waging war on Ukraine its power grid is up, its telcos are functioning and its banks are still processing transactions.
How has Ukraine been able to withstand Russia’s onslaught in the cyber domain? Vitiuk joins us to reveal insights into how Russian intelligence services are operating in Ukraine, and how the SBU is countering them.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode