Ukraine’s Cyberwarfare Capabilities and Doctrine: Resilience, Resistance and Operations Under Fire
An evidence-led journey through Ukrainian cyber power—from the attacks that accompanied Russia’s invasion to national cyber defense, military and intelligence operations, cloud resilience, volunteer action, battlefield systems, allied support, and the unfinished creation of dedicated Cyber Forces.
Begin one hour before the invasion: a satellite network goes dark
Evidence cutoff: 18 September 2026. In the early hours of 24 February 2022, as Russian forces prepared to cross Ukraine’s borders, malicious commands disabled thousands of modems on Viasat’s KA-SAT network. Ukrainian military and civilian users lost satellite connectivity; effects also reached customers elsewhere in Europe, including wind-energy equipment in Germany. The UK Viasat attribution, issued with allies, attributed the operation to Russia and placed its beginning roughly one hour before the invasion.
At the same time, Ukrainian government, finance, technology, energy, and communications organizations faced destructive malware, denial of service, defacements, credential theft, and espionage. WhisperGate had appeared in January. HermeticWiper was deployed on 23 February. Russian operators were not improvising after tanks moved; they had prepared access and effects before the conventional assault.
Yet Ukraine’s government did not digitally disappear. The armed forces continued to communicate. Officials addressed citizens and foreign partners. Banks, telecommunications, and public services adapted. Cyber operations imposed damage, friction, uncertainty, and recovery cost, but they did not deliver political capitulation or substitute for the conventional seizure of Kyiv.
This apparent contradiction is the foundation of Ukraine’s cyber story. Russia possessed access and destructive capability. Ukraine possessed institutions, experienced defenders, redundant communications, foreign support, and the ability to reconstitute services. Strategic effect depended on the interaction of both systems and on the battlefield outcome surrounding them.
Apply the practical definition of cyberwarfare. Viasat had identifiable authority, timing, mechanism, target context, and operational purpose. Its wider European effects also demonstrate why a cyber action’s boundary is not identical to a front line. But even synchronized action does not prove that every wiper was tactically coordinated with a particular missile or maneuver unit.
Ukraine therefore teaches a harder lesson than “cyberwar was overhyped.” Cyber operations were real and sustained; expectations of an independent digital knockout were wrong. Their value lay in intelligence, disruption, psychological pressure, and support to wider campaigns. Their limitations were exposed by resilience and by Russia’s failure to translate early military action into the rapid collapse it expected.
The doctrine was written before the invasion—and rewritten through experience
Ukraine entered 2022 with a painful apprenticeship. Russia’s seizure of Crimea and war in Donbas brought telecommunications interference, compromised media, espionage, and information operations. Cyberattacks disrupted electricity distribution in 2015 and 2016. NotPetya began through a Ukrainian software supply chain in 2017 and escaped into global business, causing enormous losses far beyond the intended theater. Ukraine became both target and laboratory.
The official 2021 Cybersecurity Strategy distilled that experience into three organizing principles: deterrence, cyber resilience, and cooperation. It sought an open and secure cyberspace, protection of rights, Euro-Atlantic integration, national incident management, critical-infrastructure defense, trained personnel, intelligence support, sanctions, exercises, and deeper public–private cooperation.
The strategy was not purely defensive. It directed formation of cyber forces inside the Ministry of Defence system and stated that Ukraine should gain the ability to conduct offensive operations in cyberspace. Deterrence included the capacity to resist, attribute, impose diplomatic or economic consequences, and answer aggression. Resilience meant that intrusion should not become national paralysis. Cooperation recognized that Ukraine could not defend global technology dependencies alone.
Full-scale war validated the framework while exposing gaps. A strategy can assign missions; it cannot instantly produce specialists, secure legacy networks, resilient suppliers, interoperable logs, or a settled command chain. Civilian agencies, the armed forces, intelligence services, local administrators, telecom operators, vendors, and foreign partners often had to coordinate while systems were being attacked and physical infrastructure destroyed.
The government’s three-year wartime cyber review reports 2,194 recorded incidents in 2022, 2,543 in 2023, and 4,315 in 2024, while incidents categorized as critical declined from 367 in 2023 to 59 in 2024. These figures indicate workload and changing classification; they do not mean every event was Russian, every attack succeeded, or severity can be compared without understanding collection and reporting changes.
Ukraine’s doctrine is therefore best read as a direction of travel implemented through combat learning. Denial, recovery, intelligence, disruption, alliance support, and public communication are mutually reinforcing. Offensive action is acknowledged, but public documents do not disclose targeting rules, authorization thresholds, deconfliction, or how cyber effects are integrated into operational plans.
Map the system before naming an “army”: institutions with different wartime missions
Ukraine’s national system is deliberately plural. The National Cybersecurity Coordination Center under the National Security and Defence Council coordinates at strategic level. The State Service of Special Communications and Information Protection—SSSCIP—leads major civilian cyber-protection functions; CERT-UA detects, analyzes, warns, and responds. The Security Service of Ukraine handles counterintelligence, cyberespionage, cyberterrorism, and sabotage investigations. The National Police addresses cybercrime, the National Bank coordinates finance-sector security, and the Ministry of Digital Transformation operates and develops digital-state services.
Within defense, the armed forces’ Communications and Cybersecurity Troops profile assigns them deployment and operation of communications and information systems, combat command-and-control support, interoperability, and defense against military aggression in cyberspace. The Ministry of Defence added a round-the-clock MoD Cyber Incident Response Center in 2024. The General Staff, service components, and military intelligence possess other capabilities whose detailed relationships are not public.
Defence Intelligence of Ukraine, commonly DIU or HUR/GUR, openly claims intelligence and disruptive operations against Russian systems. The SBU also reports operational successes but must simultaneously defend Ukraine against penetration, insiders, and hostile infrastructure. An incident may involve CERT-UA for malware analysis, SSSCIP for coordination, the SBU for counterintelligence and evidence, a ministry for restoration, a private vendor for telemetry, and foreign partners for intelligence.
Ukraine is still formalizing a dedicated military cyber force. The official Cyber Forces bill record shows Draft Law No. 12349 passed first reading on 9 October 2025. Committees recommended adoption in 2026, yet at the evidence cutoff the record still described it as awaiting second reading. It would create Cyber Forces and a command, define personnel and reserve arrangements, and provide a clearer military home for specialized activity.
This distinction prevents two errors. Existing Ukrainian offensive activity did not wait for a future service to exist. Conversely, public claims of operations do not prove that a unified Cyber Forces command already controls every military, intelligence, or volunteer actor. Institution-building during war must preserve access and tempo while clarifying authority, professional standards, target review, career paths, and integration with operational commanders.
The 2025 government 2025 joint-response framework established common interaction rules for CERT-UA, CSIRTs, and security and law-enforcement bodies. The 2025 national-system review provides a contemporary assessment of threats and wartime policy. Coordination mechanisms are capabilities in their own right: they reduce duplicated investigation and shorten the distance from warning to recovery.
The opening campaign: wipers, power, communications and the limits of synchronization
Russia’s opening cyber campaign targeted confidence and administrative capacity. Wipers masqueraded as ransomware to destroy systems while confusing initial response. Defacements claimed data had been lost. Espionage sought government and military information. Viasat disrupted communications at the moment invasion began. The goal was broader than technical damage: burden defenders, fracture trust, reduce command options, and reinforce the expectation of state collapse.
Microsoft’s Microsoft early-war study found destructive and espionage activity distributed across sectors and sometimes aligned with military objectives. It also observed that cloud and internet-connected endpoint defenses enabled rapid distribution of protective intelligence and code. The finding is not that cloud prevents war; geographic and administrative separation made some assets harder to destroy with a missile or one compromised data center.
Sandworm/APT44 remained the central Russian destructive actor. Google’s APT44 wartime assessment describes a GRU-sponsored organization spanning espionage, attack, and influence, with wartime operations increasingly integrated with conventional aims. But operational integration is a spectrum. Similar timing may reveal a shared campaign objective without proving real-time coordination at tactical level.
Energy shows both capability and friction. In April 2022, Ukraine and ESET disrupted Industroyer2 before its intended effect. A separate 2022 Ukrainian power operation began by June, reached a substation environment, and caused an unscheduled outage on 10 October by abusing native MicroSCADA functionality; a later wiper affected the IT environment. The case shows patient access, operational-technology knowledge, and use of legitimate control functions. It also contains signs of imperfect coordination between operational subteams.
This is how cyber campaign design should be evaluated. Ask whether access existed at the required time, whether the digital effect supported a maneuver or strategic message, whether physical attack made cyber redundant, how quickly the defender restored service, and what intelligence was consumed to gain the result. An outage is not automatically a strategic success; a blocked operation can still force costly defensive change.
Ukraine survived because defense was active before the opening strike. Years of indicators, exercises, segmentation, external hunting, vendor telemetry, and administrator experience shortened the time between detection and action. Russia remained capable of serious damage. Ukraine made that damage less decisive.
Resilience became an operational weapon: move, distribute, recover, communicate
Ukraine’s most consequential cyber capability may be its ability to keep functioning. Before and after the invasion, government teams copied data, moved workloads, diversified hosting, hardened identity, created alternate communications, and accepted help from global technology companies. Public cloud placed selected services and backups beyond physical attack on Ukrainian data centers. It did not remove dependency; it exchanged local concentration for foreign providers, connectivity, identity, licensing, and allied political support.
Resilience operated in layers. Telecom providers rerouted traffic and repaired equipment under bombardment. Satellite terminals supplied alternate connectivity. Government services used distributed architecture. Administrators kept offline or separated backups. Manual processes remained available for some public functions. CERT-UA and vendors exchanged indicators at operational speed. Public messaging told citizens whether an outage was an attack, what still worked, and where to find alternatives.
International assistance was unusually deep. Foreign governments conducted pre-invasion defensive hunting and shared intelligence. Technology companies supplied telemetry, cloud capacity, domain protection, endpoint tools, and incident expertise. The Tallinn Mechanism and EU programs coordinated longer-term civilian assistance. The Ramstein-format IT Coalition supplies military communications, licenses, data-center upgrades, and support for systems including DELTA, Army+, and Reserve+, as described in the military IT Coalition review.
Bilateral commitments are becoming institutional. The UK–Ukraine cyber partnership includes detection, deterrence, disruption, resilience, technological development, and digital government. This network gives Ukraine capabilities no domestic agency could reproduce alone. It also creates strategic questions about sovereignty, commercial access to sensitive telemetry, postwar funding, procurement, and continued support.
Resilience should not be romanticized. The state still faces legacy systems, uneven local-government security, shortages of specialists and licensed tooling, supplier compromise, electricity loss, damaged fiber, insider threats, and the exhaustion of defenders. More recorded incidents and fewer catastrophic outcomes may reflect improvement, but attackers also shift toward espionage, accounts, mobile devices, and suppliers when hardened central systems become difficult.
The operational lesson is mission-first. Identify cyber key terrain: identity, DNS, telecom control, cloud administration, military messaging, logistics, registers, and the people who administer them. Decide what must survive, what can degrade, which manual path remains, how long restoration may take, and who can authorize emergency change. Security tries to stop entry; resilience denies the enemy the outcome.
Kyivstar and the state registers: when civilian dependencies become battlefield pressure points
On 12 December 2023, Ukraine’s largest mobile operator went offline. The official Kyivstar incident statement said essential technology-network services were blocked and CERT-UA, the SBU, and the operator were investigating together. Roughly 24 million mobile customers were affected. Air-raid warning systems in dozens of localities lost a communications dependency and had to use alternatives.
Ukrainian investigators later said the Russian operators had been present for months and attributed the operation to Sandworm/GRU Unit 74455. A Russian persona claimed massive destruction, but attacker claims about server counts and erased backups should not substitute for forensic evidence. The observed facts are already significant: a core telecom dependency was disrupted for days during war, downstream services were affected, and national roaming had to be managed to prevent overload.
Kyivstar demonstrates civilian harm and reverberating effects. A mobile network is not merely consumer infrastructure. It connects families, emergency alerts, payments, authentication, field personnel, businesses, and government. Alternative sirens and other operators limited harm, but the incident revealed how one provider sits inside many mission chains.
A year later, another dependency failed. On 19 December 2024, a Russian-attributed attack led the Ministry of Justice to suspend multiple state registers. The official state-register attack briefing described preserved data, prioritized restoration, paper handling of civil-status acts, paused administrative deadlines, and an SBU war-crime investigation. Business registration, notarial work, property processes, customs, and connected services experienced consequences until systems returned.
These cases show resilience as governance, not only backup restoration. Authorities must suspend deadlines so citizens do not lose rights, define which paper acts remain valid, prevent fraud during partial availability, synchronize dependent systems, verify restored data, and explain uncertainty. A technically restored database can still produce legal or social harm if transactions made during the outage are mishandled.
For defenders, the control objective is dependency-aware recovery: privileged-access isolation, tested offline backups, separate recovery credentials, supplier controls, immutable logging, configuration reconstruction, degraded-mode procedures, and exercises that include lawyers, communications staff, sector regulators, and local authorities. A cyber incident becomes national when its second- and third-order consequences outrun the technical team.
Ukraine strikes back: intelligence operations, public claims and the volunteer boundary
Ukraine is not only a defender. Its 2021 strategy anticipated offensive operations, and wartime agencies now speak openly about them. The DIU cyberspace operations record claims more than one hundred large-scale operations inside Russia since the full-scale invasion. Public announcements describe access to military, tax, transport, financial, industrial, and communications systems, theft of data, disruption, and destruction.
A January 2024 DIU military-server claim said a Russian Ministry of Defence special-communications server was disabled, stopping exchange among users of that system. The target and proposed effect are militarily plausible. But an official belligerent’s statement is not independent validation. Duration, affected units, alternative communications, recovery time, intelligence gained, and battlefield consequence were not publicly established.
This is where cyber attribution must work in both directions. Ukrainian acknowledgment strongly supports responsibility for a claimed operation; it does not validate every damage figure. Anonymous Ukrainian-aligned personas may collaborate with an agency, operate independently, exaggerate an effect, or reuse leaked data. Russian reporting may minimize damage or correctly expose a weak claim. Analysts need telemetry, victim response, infrastructure, timing, independent observation, and consistent tradecraft.
The IT Army of Ukraine emerged immediately after the invasion through a public call associated with the Ministry of Digital Transformation. Volunteers received target lists through online channels and conducted denial-of-service, data collection, defacement, and messaging activity. It created participation and imposed defensive workload on Russia, but scale was often measured by subscribers rather than active skilled operators. Low-level traffic and publicity could also interfere with covert access or confuse assessment.
The Ukraine frontline cyber-defense study notes both contributions and weaknesses: decentralized volunteers helped resistance, some skilled participants entered formal services, and activity could generate “white noise” or interfere with sophisticated operations. The unresolved legal status raises questions of state responsibility, civilian direct participation in hostilities, distinction, target review, evidence preservation, and protection if captured.
Professionalization should preserve useful talent while moving sensitive operations into accountable structures. Authorized operators need clear objectives, approved targets, conflict deconfliction, legal review, access records, proportionality and civilian-impact assessment where applicable, and procedures for retaining intelligence before disruption. The discipline of cyber access stewardship matters more than public proof of activity: premature destruction can sacrifice an intelligence source for a temporary headline.
The 2026 assessment: cyber power fused with a digital battlefield, but not a digital superweapon
Ukraine’s war has erased the comfortable boundary between enterprise security and combat operations. Smartphones hold unit chats, locations, photographs, and authentication tokens. DELTA and other battlefield-management systems combine intelligence and targeting information. Drone manufacturers, training organizations, logistics platforms, satellite links, and commercial messaging are operational dependencies. Russian actors target captured devices, Signal and Telegram data, drone personnel, recruits, and battlefield credentials, as the 2025 defense-industry threat study documents.
Cyber defense now intersects with electronic warfare, spectrum management, deception, drones, space services, intelligence, and fires. Jamming can deny a link without compromising software. Malware can steal a unit location that later enables physical attack. A drone-platform account can be more operationally valuable than a ministry homepage. A defender must connect identity telemetry and incident response to the pace of field operations without centralizing every tactical system into one brittle target.
Four evidence bins produce a defensible 2026 assessment:
- Demonstrated: experienced national institutions; repeated response under attack; cloud and communications adaptation; CERT-UA reporting; military cyber-defense and communications organizations; allied and private support; restored telecom and government services; and public defensive coordination.
- Assessed: the contribution of particular controls to Russian failure, the extent of operational synchronization, and relationships between state bodies and aligned groups, supported with stated confidence.
- Claimed: many Ukrainian intelligence operations and damage figures inside Russia, which establish intent and sometimes responsibility but require independent confirmation of effect.
- Unknown: classified access, tool inventories, force size, intelligence-to-operations workflow, targeting authorities, deconfliction, collateral-risk controls, and the reliable contribution of cyber effects to battlefield outcomes.
Ukraine’s strengths are unusual: eleven years of live defense; a large technical community; high political commitment; digital public services; fast state–industry communication; global vendor telemetry; foreign intelligence and assistance; and an adversary whose repeated operations provide hard lessons. Its constraints are severe: destroyed infrastructure, power interruption, human fatigue, uneven local capacity, supplier risk, corruption and procurement concerns, dependence on foreign platforms, and the institutional ambiguity a new Cyber Forces law is intended to reduce.
Legal discipline remains part of capability. Ukraine’s Ukrainian IHL practice report records Ministry of Defence engagement on international humanitarian law and cyber operations. Applying distinction, proportionality, precautions, and military necessity to cyber activity is difficult when civilian and military systems share cloud, telecom, and identity dependencies. Difficulty is not an exemption; it increases the need for target-system understanding and reverberating-effects analysis.
Defenders elsewhere should not copy Ukraine’s emergency architecture without its context. They should copy the habits: know essential missions, practice degraded operations, pre-negotiate provider help, retain independent communications, hunt before crisis, distribute recoverable data, protect administrator identities, include suppliers, communicate quickly, and measure recovery rather than attacks blocked. They should also study Russia’s cyberwarfare capabilities, because Ukraine’s system developed against a specific and adaptive adversary.
Finally, cyber and information effects must be separated without being isolated. Russian wipers and defacements sought psychological impact; Ukraine’s public communication helped prevent an outage from becoming evidence of state collapse. Ukrainian messaging and hack-and-leak activity can likewise become cyber-enabled influence operations. Truth, timing, credibility, and recovery shape the audience effect as much as malware.
Ukraine’s cyber journey is therefore one of strategic endurance. It did not stop every intrusion, protect every citizen, or make conventional defense optional. It learned to make networks recoverable, partnerships operational, communications redundant, evidence shareable, and technical failure less decisive. Its offensive capacity is real but incompletely observable; its dedicated-force architecture remains in development. The clearest demonstrated capability is the ability to keep fighting, governing, and adapting while one of the world’s most capable cyber adversaries tries to prevent all three.
Frequently asked questions
What are Ukraine’s principal cyberwarfare capabilities?
Ukraine has an experienced national incident-response system, military communications and cyber-defense troops, security and intelligence services that conduct cyber operations, mature public–private and international partnerships, rapidly adapted cloud and continuity architecture, and a large technical workforce shaped by more than a decade of Russian attacks. Ukrainian military intelligence publicly claims more than one hundred major operations inside Russia, but independent verification of individual effects varies.
Does Ukraine have a published cyberwarfare doctrine?
Ukraine’s 2021 Cybersecurity Strategy is the clearest public foundation. It organizes the national system around deterrence, cyber resilience, and cooperation; directs creation of cyber forces; and explicitly anticipates offensive operations. Wartime practice has developed faster than the published institutional model, and detailed military authorities, targeting rules, and operational doctrine remain classified.
Has Ukraine created a dedicated Cyber Forces service?
The armed forces already contain Communications and Cybersecurity Troops and other operational cyber elements. Draft Law No. 12349 would establish dedicated Cyber Forces and a command. Parliament approved it in first reading in October 2025, and committees recommended adoption in 2026, but the official bill record at the evidence cutoff still listed it as awaiting second reading. Existing operations should not be confused with completion of that proposed structure.
Is the IT Army of Ukraine part of the Ukrainian military?
It emerged after the full-scale invasion as a loosely coordinated volunteer movement encouraged through Ukrainian official channels, but it has not had the transparent status, discipline, or command chain of a regular armed-force unit. Some skilled volunteers later joined formal institutions. Attribution, civilian participation in hostilities, target review, and accountability must be assessed operation by operation.
Why did Russian cyber operations not cause a rapid Ukrainian collapse in 2022?
Russia did conduct consequential espionage, wiper, satellite, telecommunications, energy, and influence operations. Their strategic effect was limited by years of Ukrainian experience, rapid warning and remediation, distributed communications, cloud migration, backups, manual alternatives, private-sector support, international assistance, and the failure of Russia’s conventional invasion to produce the political collapse its cyber activity could have reinforced.