Summary
The core message of the keynote was that Ukraine’s experience shows cyber defence of critical infrastructure can no longer be treated as a purely technical or nationally contained problem: in a hybrid war, cyberattacks are synchronized with kinetic strikes, intelligence activity, electronic warfare, and information operations, and the practical value lies in building proactive, shared security between government and industry. Ivan Kalabashkin, deputy head of the Cyber Department at the Security Service of Ukraine, thanked the Netherlands and introduced the SBU as a uniquely combined counterintelligence, intelligence, and law-enforcement agency. Since the beginning of the full-scale war, he said SBU cyber specialists have encountered more than 16,000 severe cyberattacks on governmental networks and critical infrastructure, adding that DDoS is no longer treated as an attack in this context because the most serious threats target critical networks and have shifted from quantity to quality.
Kalabashkin traced Ukraine’s lessons back before 2022. In December 2015, an attack on the power grid using BlackEnergy malware and KillDisk showed that information systems could no longer be treated as secondary components of industrial processes, because damage to IT directly affected OT. In 2017, the NotPetya attack demonstrated the global risk of supply-chain compromise: it was planned and targeted against Ukraine, he said, but victims appeared around the world, including seaports and logistics companies. With the 2022 full-scale invasion, Russia abandoned isolated cyber campaigns in favor of a persistent synergy of missile strikes, attack drones, subversive activity, human intelligence, electronic warfare, and information-psychological operations.
The session then focused on recent attacks and their societal consequences. The Kyivstar attack deprived more than 20 million users of communication and affected civilian life far beyond mobile convenience: people could not call ambulances, use ATMs, or make cashless payments. Kalabashkin said this led Ukraine to treat such cyberattacks as war crimes when they target and intimidate civilian populations. A later attack on Ministry of Justice registers created cascading risks around civil-status records, property information, fraud, forged ownership records, lawsuits, financial losses, and social panic, including the inability to obtain a death certificate. The Ukrainian railway attack took down digital services, but operational functions continued because IT and digital services had been segmented from operational services, a measure he said the government had forced and that proved decisive.
In closing his presentation, Kalabashkin emphasized proactive defence, understanding adversary intent, information sharing, and a single security perimeter between government and industry. He connected Ukraine’s experience to the conference motto, “we are all connected,” warning that cyber conflict does not respect borders. The following remarks by Deputy Foreign Minister and Chief Digital Transformation Officer Andrii Droniuk reinforced the same frame: cyberspace increases both interdependence and vulnerability, Ukraine represents the world’s first full-scale hybrid conflict in which cyberattacks are systematically synchronized with military and information operations, and recent strikes on Kyiv data centers disrupted civilian digital services including air-raid warning systems. Citing Microsoft’s Digital Defense Report, he said Ukraine ranked third worldwide and first in Europe in the first half of the year among countries whose organizations and end users were most frequently targeted, while stressing that each attack has made Ukraine more experienced, proactive, and protected.
Key Topics
5 key topics from Ivan Kalabashkin and Andrii Droniuk at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Segment IT and digital services from operational systems.
- Share threat information across government and industry early.
- Treat civilian-impacting cyberattacks as potential war crimes.
- Prepare for cascading effects across registers, payments, and emergency services.
- Act proactively by tracking adversary intent, not only incidents.
“Peace is not the absence of war.”
Up Next


Next in agenda
Closing day 2



Also on ukraine
European Security: Technological Innovation in Warfare



Also on cybersecurity
