How Ukraine Turned a Nation-State Cyberwar Into a Masterclass in Operational Resilience
Former foreign minister Dmytro Kuleba details how pre-planned contingencies — not ad-hoc crisis management — kept Ukrainian government and business functions alive under sustained Russian attack.

Dmytro Kuleba ran Ukraine's foreign ministry from 2020 to 2024. He watched Russian operators knock out the country's largest mobile network with a single compromised employee account. He also watched the country get back up.
Kuleba spoke at Infosecurity Europe, walking delegates through the operational logic that Ukraine developed under fire. The central argument: resilience is not a repair capability. It is the institutional muscle memory built before the crisis arrives.
The KyivStar incident is worth revisiting. In December 2023, Russian threat actors penetrated the telco through one employee's account, reached the core of the network, and took it down. KyivStar restored service within days — an outcome Kuleba called 'the unimaginable.' He credited prior preparation, not improvisation. According to Kuleba, major successful cyberattacks on Ukrainian infrastructure have been rare since.
The foreign ministry's own continuity planning began in November 2021, three months before the full-scale invasion. Kuleba's team mapped every system, identified every dependency, and pre-answered questions that organisations typically scramble to answer mid-crisis — including how diplomats would communicate if messaging platforms went dark. When Russian forces crossed the border, the ministry evacuated services abroad without losing a day to triage. 'We did not waste a single second on figuring out what is possible and what is impossible,' Kuleba said, 'because we knew all of that in advance.'
The more operationally unsettling disclosure involved civilian CRM systems. Russian intelligence services, Kuleba said, have been breaking into the loyalty and scheduling platforms of barbers, gyms, and supermarkets to build pattern-of-life profiles on Ukrainian officials and their families. The goal is targeting — for surveillance, kidnapping, or coercion. He described one case in which an official's son was abducted; the father was subsequently blackmailed into passing intelligence.
The vector was partly structural. For years before the invasion, Russian companies offered Ukrainian businesses attractively priced CRM platforms. Whether that was commercial opportunism or a coordinated intelligence-service operation, Kuleba declined to definitively say. The effect was the same: pre-positioned access inside the daily-life data of Ukrainian civilians.
'Even such an innocent programme as a check-in system at a restaurant can help your enemy to kill someone,' he said.
The policy takeaway Kuleba pushed hardest applies well beyond wartime Ukraine. Contingency planning loses budget fights because it competes against projects with measurable near-term returns. Kuleba's counter: if a company or government body has not pre-mapped its environment, the crisis moment does not reveal the plan — it reveals the absence of one. 'You will be punched in the face,' he said. 'You plan not to follow the plan but to know your environment perfectly.'



