Section 2. IMPLEMENTATION OF THE CYBERSECURITY STRATEGY OF UKRAINE FOR
2016 - 2020
The adoption of the Cyber Security Strategy of Ukraine in 2016 was an important step in
introducing long-term planning approaches in this area, and therefore, the very fact of its
adoption were a positive result.
Over the years, efforts have been made to establish and develop a national cybersecurity
system. An important stage in its institutionalization was the adoption of the Law of Ukraine
"On the Basic Principles of Cyber Security of Ukraine", which is the legal basis for creating a
national cyber security system and its main actors in the field of cyber security.
Regulatory support for cyber security of critical information infrastructure has been
improved, the procedure for its definition and general requirements for its cyber security
have been adopted.
Centers (subdivisions) for cybersecurity or cyber defense have been established in the State
Service for Special Communications and Information Protection of Ukraine, the Security
Service of Ukraine, the National Bank of Ukraine, the Ministry of Infrastructure of Ukraine,
and the Ministry of Defense of Ukraine (Armed Forces of Ukraine).
The National Telecommunication Network is being developed, secure data processing
centers (data centers) are functioning, the National Center for Reserving State Information
Resources is being formed, and a system for identifying vulnerabilities and responding to
cyber incidents and cyberattacks has been launched.
In order to improve the coordination of the activities of cybersecurity entities, a working
body of the National Security and Defense Council of Ukraine was established - the National
Cybersecurity Coordination Center, the solutions of which contribute to solving the most
complex problems in this area.
Cooperation with foreign partners is actively developing, Ukraine's cooperation with the EU
and NATO is deepening, and cyber exercises are being conducted with the participation of
other states and international organizations.
An annual event, Cyber Security Month, has been launched.
At the same time, the activities of the subjects of the national cybersecurity system remain
insufficiently coordinated and aimed at performing only current tasks. According to the
results of expert assessments, the state of implementation of the Strategy according to
certain indicators does not exceed 40%. The issues of operative exchange of information on
cyber threats, effective training system and effective model of public-private partnership
remain unresolved. The organization and conduct of research in the field of cybersecurity is
defined by all experts as unsatisfactory.
The experience gained during the duration of the Strategy made it possible to identify a
number of systemic problems that either complicated or prevented its effective
implementation.