Skip to content

Supply Chain Risk Management in the Cloud for Ukraine's Critical Infrastructure: Architectural Solutions

In the current environment, where cyber threats are global in scale and the hybrid war against Ukraine continues, ensuring the resilience of critical infrastructure is a strategic priority. The increasing dependence on cloud services and external providers creates new, complex attack vectors through the supply chain. This requires CIOs, CISOs, and enterprise architects not only to understand the risks but also to develop and implement robust architectural solutions and supply chain risk management (SCRM) strategies in cloud environments.

New Cybersecurity Requirements for Supply Chains in Ukraine

Ukrainian legislation is actively adapting to new realities, strengthening cybersecurity requirements, especially for providers working with the public sector and critical information infrastructure (CII) entities. Key regulatory acts defining these changes are Orders of the State Service of Special Communications and Information Protection No. 836 and No. 75.

Order of the State Service of Special Communications and Information Protection dated 17.12.2025 No. 836 establishes requirements for providers to implement security measures in accordance with the risk level associated with the supply of goods, works, and services to owners or administrators of information and communication systems that process state information resources or official information, and information constituting state secrets, of critical information infrastructure entities. This document introduces a flexible model based on four risk levels determined by the criticality criteria of goods, works, services, and the involvement of the provider's information and communication system in processing state data. For the first (minimal) risk level, providers must implement 17 basic security measures, confirming their implementation declaratively. For higher levels (second, third, and fourth), confirmation of IT system protection is required in one of three ways: possession of a security authorization, a certificate of conformity to an information security standard (e.g., ISO/IEC 27001), or a valid attestation of conformity for a comprehensive information security system (KSZI).

Order of the State Service of Special Communications and Information Protection dated 30.01.2026 No. 75 approves the Catalog of Cybersecurity Measures, Basic Cybersecurity Measures, the form of a cybersecurity plan, and methodological recommendations for implementing cybersecurity measures. This order replaces previous recommendations and introduces a modern differentiated approach to cybersecurity based on cybersecurity risk management. The implementation of basic cybersecurity measures is mandatory for all critical infrastructure operators and owners of systems processing state information resources or restricted-access information. The document also mandates an annual assessment of the current state of cybersecurity and the determination of the target state, taking into account the results of risk management.

Challenges of Supply Chain Risk Management in Cloud Environments

The transition to cloud services offers significant advantages in flexibility and scalability but simultaneously creates new challenges for supply chain risk management, especially for critical infrastructure. Key difficulties include:

  • Ecosystem Complexity: Cloud environments often involve numerous providers (IaaS, PaaS, SaaS), subcontractors, and integrators, complicating full visibility and control over the entire supply chain.
  • Ambiguity of Responsibility: The shared responsibility model in the cloud can lead to misunderstandings about who is responsible for certain security aspects, especially at the boundary between the cloud service provider and the user.
  • Threat Dynamism: Cyber threats are constantly evolving, and supply chain attacks are becoming increasingly sophisticated, often targeting less protected providers to gain access to the target infrastructure.
  • Geographic Distribution: Data and services can be located in different geographical locations, making it difficult to comply with national regulatory requirements and data sovereignty.
  • Insufficient Transparency: Obtaining complete and up-to-date information about security measures and compliance with standards from all supply chain participants can be a challenging task.

Architectural Approaches to Integrating SCRM into the Cloud

To effectively manage supply chain risks in cloud environments for Ukraine's critical infrastructure, proactive architectural solutions are needed that comply with both national and international standards, such as NIST SP 800-161. This standard provides guidance on identifying, assessing, selecting, and implementing risk management processes and mitigation measures throughout the supply chain.

Key architectural approaches include:

  1. Isolated Cloud Segments and Microsegmentation: Deploying critical systems and data in highly isolated cloud segments or virtual private clouds (VPCs) with strict microsegmentation. This minimizes the attack surface and limits attacker movement in case of a compromise of one of the providers or services.
  2. Rigorous Vendor Vetting and Continuous Monitoring: Implementing comprehensive vendor vetting programs that include assessing their security policies, compliance with standards (e.g., ISO 27001, NIST SP 800-161), financial stability, and business continuity plans. Continuous third-party risk monitoring is necessary using automated tools to track changes in the risk profiles of vendors and their subcontractors.
  3. Integrating SCRM into the Software Development Lifecycle (SDLC) and CI/CD: Embedding supply chain security controls at all stages of software and service development and deployment. This includes vulnerability scanning in source code, containers, third-party libraries, and automated security configuration checks.
  4. Utilizing Cloud-Native Security Services: Maximizing the use of built-in cloud services for identity and access management (IAM), security monitoring (SIEM, Cloud Security Posture Management - CSPM), data protection (encryption, DLP), and network security (firewalls, WAF). These services are often integrated and provide better visibility and automation.
  5. Zero Trust Identity and Access Management: Implementing a Zero Trust architecture where no user or device is trusted by default, regardless of its location. Every access request must be authorized and verified.
  6. Ensuring Data Sovereignty and Residency: Selecting cloud providers that offer data hosting within Ukraine or in jurisdictions with appropriate data protection requirements, and ensuring compliance with national regulatory acts.

Risk Minimization and Compliance Strategies

In addition to architectural solutions, effective supply chain risk management requires the implementation of comprehensive strategies:

  • Developing an SCRM Policy: Creating a clear supply chain risk management policy that defines roles, responsibilities, risk assessment and monitoring procedures, and incident response plans arising from vendor issues.
  • Differentiated Risk Approach: Applying a differentiated risk management approach that considers the four risk levels defined by the State Service of Special Communications and Information Protection. This allows resources to be focused on the most critical vendors and services.
  • Regular Audits and Assessments: Conducting regular internal and external security audits of vendors, as well as assessments of their systems and processes for compliance with the requirements of Orders No. 836, No. 75, and NIST SP 800-161.
  • Business Continuity and Disaster Recovery (BCDR) Planning: Developing and testing BCDR plans that include supply chain disruption scenarios, ensuring rapid recovery of critical functions.
  • Training and Awareness Raising: Conducting regular training for employees on supply chain risks and the importance of adhering to security policies.
  • Using Predictive Analytics and AI: Employing modern technologies such as predictive analytics and artificial intelligence for early detection of potential risks and responding to changes in the supply chain.

Decision Support Tools

For effective selection of architectural solutions and supply chain risk management strategies in cloud environments for Ukraine's critical infrastructure entities, considering the new national regulatory requirements, it is advisable to use a comparative table of architectural approaches for integrating SCRM into cloud environments. Such a table might include:

Each approach (e.g., isolated cloud segments, rigorous vendor vetting, continuous third-party risk monitoring) should be evaluated based on the following criteria:

  1. Compliance with State Service of Special Communications and Information Protection Risk Levels: How the approach helps meet the requirements for each of the four risk levels defined by Order No. 836.
  2. Compliance with NIST SP 800-161: Which NIST SP 800-161 controls and requirements the architectural approach supports or enhances.
  3. Impact on Flexibility and Scalability: An assessment of how the approach affects the ability to quickly deploy and scale cloud services.
  4. Implementation and Maintenance Complexity: An assessment of the resources required for the implementation and support of the approach.
  5. Cost: Estimated expenses related to implementation and operation.
  6. Effectiveness Against Supply Chain Cyber Threats: How well the approach protects against typical supply chain attacks.

Such a tool would allow IT department heads and system architects to systematize information, visualize the advantages and disadvantages of each solution, and make an informed decision that ensures a balance between cloud innovation and the necessary level of cybersecurity for Ukraine's critical infrastructure.

In the face of constant cyber threats and a dynamic regulatory environment, proactive and architecturally sound supply chain risk management in the cloud is not just a requirement but a critical necessity for ensuring national resilience. Implementing comprehensive strategies that combine national regulatory requirements and best international practices will enable Ukrainian critical infrastructure enterprises to effectively counter modern challenges.

Sources

  1. 01asters.uaUkraine Enacts New Cybersecurity Law
  2. 02avellum.com.uaUkraine introduces Critical Infrastructure Law
  3. 03e-governance.academyUkraine boosts its critical infrastructure cyber resilience
  4. 04chambersandpartners.comPeculiarities of cloud service operations in Ukraine | Article | Chambers and Partners

Does any of this match your situation?

Tell us where you are now — we will suggest a practical route for infrastructure, cloud or security.

Discuss a project