Ukraine’s Cyber Warfare Experience Offers Critical Lessons for Global Cyber Defence
Ukraine has accumulated extensive experience defending against Russian cyber operations. Its evolving approach highlights why real-time intelligence sharing, dependency mapping and practical cyber exercises matter for organisations worldwide.
Xcademia Team
Xcademia Research Team

Ukraine's experience defending against Russian cyber operations is providing an unusually detailed view of how cyber warfare can evolve during a sustained conflict. The lessons extend beyond Ukraine, with implications for governments, critical infrastructure operators, technology companies and cybersecurity teams worldwide.
According to the Atlantic Council, Ukraine registered 2,194 Russian cyber attacks in 2022. By 2024, that figure had risen to 4,315. Yet during the same period, incidents classified as critical or high severity fell from 1,048 to 59.
The figures point to an important distinction: a higher volume of attacks does not necessarily mean proportionally greater damage when defensive capabilities and experience improve.
The Atlantic Council argues that Ukraine's experience should be studied not simply as a record of wartime incidents, but as a practical cybersecurity resource that can help other organisations improve their ability to identify and respond to threats.
From crisis response to accumulated cyber defence experience
When Russia launched its full-scale invasion in February 2022, Ukrainian cyber defence teams faced an unprecedented operational environment.
The Atlantic Council describes Ukrainian security operations centre analysts working extended shifts as teams dealt with a volume of incidents for which established playbooks were not available.
The experience has since produced a large body of documented cyber incidents and operational knowledge.
This accumulated experience is particularly valuable because cyber operations associated with Russia can have effects beyond Ukraine. The article notes that Russian cyber operations targeting Ukraine have sometimes reappeared elsewhere, operated in parallel or produced effects across the wider Euro-Atlantic environment.
For defenders outside Ukraine, this creates an opportunity to use Ukrainian experience as an early detection resource.
Cyber intelligence needs to move faster
One of the article's central arguments is that Ukrainian cyber data should be treated as a detection resource rather than simply as news.
Cybersecurity teams often receive threat information through periodic reports and briefings. However, attacks can develop much faster than traditional information-sharing processes.
The Atlantic Council argues that countries and organisations need to be capable of comparing information with international counterparts within hours rather than weeks.
This is not only a technical challenge. It is also an organisational one.
Institutions may have access to relevant information but still struggle to coordinate an effective response in real time. The article identifies this as a structural gap in cyber defence, particularly when critical infrastructure protection is affected by limited funding and staffing.

Why incident data matters beyond Ukraine
The broader lesson is the value of converting operational experience into usable defensive knowledge.
The article highlights research indicating that Russian cyber operations against Ukraine can reappear elsewhere or affect organisations across the wider Euro-Atlantic environment.
For cybersecurity teams, this means incident information can have value beyond the organisation in which an attack originally occurs.
Sharing indicators, attack patterns and lessons from previous incidents can help other defenders recognise related activity earlier.
The development reflects a wider shift in cybersecurity towards collaborative defence. Instead of treating incident response as an isolated organisational function, governments and businesses increasingly need mechanisms that allow relevant information to move between trusted partners.
Digital dependencies can create indirect exposure
Another important lesson concerns the technology dependencies surrounding an organisation.
A company or public institution does not necessarily need to be the original target of a cyber operation to experience its consequences.
Organisations depend on networks, cloud services, software providers, communications systems, suppliers and other digitally connected services. A disruption or compromise affecting one part of this ecosystem can create consequences elsewhere.
The Atlantic Council therefore argues that organisations should map what they depend on digitally, rather than focusing exclusively on assets they directly own.
For security leaders, this expands the scope of risk assessment.
Understanding the technology estate is important, but understanding the external services and relationships that support that estate can be equally important.

International cooperation needs to become more practical
The article also points to international cooperation as a key element of cyber defence.
A joint advisory issued by Western agencies in April 2026 described Russian military intelligence targeting Western logistics and technology companies supporting Ukraine. The agencies also assessed that the campaign likely involved attempts to compromise internet-connected cameras around border crossings, military installations and railway stations in Ukraine and neighbouring NATO states.
These examples demonstrate why cyber incidents cannot always be viewed within national boundaries.
A campaign directed at one region can involve technology, infrastructure or organisations connected to another.
The Atlantic Council argues that international partners therefore need mechanisms for exchanging information and coordinating responses rapidly.
Moving from information sharing to joint exercises
Sharing reports is only one part of the solution.
The article proposes multilateral cybersecurity exercises led by Ukraine as one way to translate Ukraine's operational experience into practical training.
International cyber exercises already take place, and Ukrainian specialists participate in some of them. However, the article argues that Ukraine has not yet been given a sufficiently large role in designing the scenarios.
Ukraine's experience could provide a foundation for realistic exercises based on documented cyber warfare incidents.
Ukrainian cybersecurity companies have also spent years converting experience from Russian cyber attacks into training material, according to the Atlantic Council.
This creates a potential pathway from incident experience to structured professional training.

Building cybersecurity leadership capacity
Ukraine is also developing its own cybersecurity training infrastructure.
The Atlantic Council notes that Ukraine's State Service of Special Communications and the Ministry of Digital Transformation launched the CISO Campus initiative, a national platform focused on training cyber defence leaders.
Ukrainian universities are also offering specialised training based on developments in cyber warfare.
This highlights another important aspect of cyber resilience: technical tools are only part of the equation. Organisations also need people capable of interpreting threats, coordinating responses and applying lessons from previous incidents.
What global organisations can learn
Ukraine's experience offers several practical lessons for organisations outside the conflict.
First, attack volume and impact should be assessed separately.
A growing number of attempted attacks does not automatically translate into greater operational damage. Tracking severity and outcomes alongside incident volume can provide a more useful picture of defensive effectiveness.
Second, threat intelligence needs to be actionable.
Information about attacks becomes more valuable when security teams can use it to identify related activity and strengthen detection.
Third, organisations need to understand their digital dependencies.
Security assessments should consider important external technology and service relationships, not only internally owned infrastructure.
Fourth, international information sharing needs speed.
When related attacks can cross borders or affect interconnected organisations, exchanging information within hours can be more useful than relying exclusively on periodic briefings.
Fifth, realistic exercises can turn experience into readiness.
Documented incidents can provide the foundation for scenarios that allow security teams to practise detection, coordination and response.
A broader lesson for cybersecurity
The Atlantic Council describes Russia's full-scale invasion of Ukraine as a watershed moment for cybersecurity.
The article's broader argument is that Ukraine's practical experience should be used more extensively through joint training, shared incident analysis and applied research between Ukrainian and Western institutions.
The development highlights a broader industry shift toward cybersecurity collaboration. Threats increasingly move through interconnected digital environments, while defensive knowledge can also be shared across organisational and national boundaries.
For enterprises, this could mean placing greater emphasis on operational intelligence, dependency mapping, cross-organisational coordination and practical exercises.
Ukraine's experience demonstrates the value of learning from real incidents. The challenge for the international cybersecurity community is turning that experience into repeatable defensive capability.
Source: Atlantic Council
About the Author