On May 14, 2024, the Intecracy Group consortium held a specialized online event — the Intecracy Expert Webinar. The main topic of discussion was the comprehensive protection of information systems in the state and corporate sectors amidst growing digital threats and constant cyberattacks. The keynote speaker of the event was the well-known expert Mykhailo Vihovskyi, who shared practical experience and spoke about modern approaches to building cybersecurity systems. The online webinar brought together information security specialists, IT department heads, system administrators, and representatives of government agencies seeking to significantly improve the security level of their digital resources and ensure the stability of critical infrastructure.
The event was led by IQusion IT LLC, an Intecracy Group member.
A Comprehensive Approach: Combining Technical and Regulatory Requirements
Modern threats in the field of cybersecurity require organizations to abandon fragmented solutions in favor of a systemic vision and long-term planning. Mykhailo Vihovskyi emphasized in detail that the security of information systems cannot be limited to merely installing antivirus software or configuring firewalls on the network perimeter. Effective cybersecurity today is based on a trinity of crucial components: modern technical tools, clearly regulated organizational procedures, and full regulatory compliance of the enterprise's activities.
Special attention during the webinar was paid to the creation and certification of Complex Information Security Systems (KSZI). In Ukraine, for government bodies and many corporate structures, building a KSZI is not just a recommendation but a legislative requirement. However, as the speaker noted, a formal attitude to this process does not create real protection. It is necessary to integrate regulatory requirements into the daily business processes of the organization, making them part of the overall risk management strategy.
“True cybersecurity begins where technical tools are synchronized with the organizational culture of the institution. Building a KSZI is not about obtaining a certificate of compliance for the sake of a checkbox. It is an ongoing process of design, implementation, and audit, where every employee understands their role in the overall defense system. Only by combining strict technical policies with regulated organizational measures can we minimize the risks of successful attacks on critical infrastructure,” emphasized Mykhailo Vihovskyi.
Technical Mechanisms and Architectural Solutions
During the webinar, the architectural aspects of building secure systems were discussed in detail. Mykhailo Vihovskyi explained exactly how technical measures should interact with organizational rules. In particular, he spoke about access control, encryption of communication channels, and real-time security event monitoring. An important element is the implementation of SIEM (Security Information and Event Management) class systems, which allow automating incident detection and promptly responding to network anomalies.
However, technical tools without proper administration and regulations quickly lose their effectiveness. For example, firewall configuration rules must be regularly reviewed in accordance with changes in the organization's business processes. This requires clear job descriptions and incident response plans, which are an integral part of the organizational component of the KSZI. Only under such conditions will technical protection function as a single, well-coordinated mechanism.
Organizational Measures as the Foundation of Resilience
Organizational measures often remain overlooked by technical specialists, although they determine the viability of the entire security system. Mykhailo Vihovskyi focused in detail on employee training, the development of internal security policies, and control over their execution. The human factor remains one of the weakest links in any cybersecurity system, and attackers actively exploit this vulnerability.
Regular cyber hygiene training, phishing simulation attacks, and clear instructions on actions to take upon detecting suspicious activity can significantly reduce the likelihood of credential compromise. The speaker noted that even the most modern defense system is powerless if users do not follow basic security rules and are not aware of the consequences of their actions.
“We must understand that attackers look for the easiest path. If the technical perimeter is securely protected, they will try to exploit human weaknesses or gaps in organizational procedures. That is why organizational measures, such as a clear access management policy and regular auditing of user actions, are just as important as configuring cryptographic protection,” noted Mykhailo Vihovskyi.
Regulatory Landscape and Compliance with Standards
The state and corporate sectors operate within strict legislative frameworks. Building a KSZI requires strict compliance with state standards and regulatory acts in the field of information protection. The speaker explained how to correctly navigate all stages of creating a comprehensive system: from developing technical specifications and design to passing state expertise and obtaining a certificate of compliance.
Concluding his speech, Mykhailo Vihovskyi urged the webinar participants to view cybersecurity not as an expense item, but as an investment in the stability and continuity of operations. The combination of technical tools, organizational regulations, and compliance with regulatory requirements allows for the creation of a truly reliable shield for information systems of any level of complexity, ensuring robust protection of state and corporate secrets.