Wartime Resilience and Emergency Cloud Migration: The Ukrainian Experience
Overview of Building Resilient Infrastructure and Cloud Migration
Research Team and Scope: The study was conducted by a team including Sergey Pudin and Natalia Mishina, focusing on recommendations for resilient infrastructure.
Shift in Infrastructure Assumptions: Historically, infrastructure was designed under the assumption of maintained physical control. The rise of hybrid working and the Ukrainian wartime experience demonstrate that physical control is no longer a guaranteed requirement for operational relevance.
Primary Threat Identification: The main threat identified in the Ukrainian experience is not merely data compromise, but the loss of physical access to digital assets and services.
Emergency Cloud Migration: This has become a key mechanism for ensuring digital resilience and the continuity of governmental and critical services during conflicts.
Goal of the Study: To analyze cloud migration as a tool for wartime resilience and to formalize the concept of "Control Without Physical Presence." * Control Without Physical Presence: Maintaining control over digital assets through logical, cryptographic, and optimization mechanisms even when physical control over the infrastructure is lost.
Review of Regulatory Requirements and Data Classification
Comprehensive Review: The study includes a review of changes in regulatory requirements within both Ukraine and the European Union.
Customer Classification: Classification of data center customers, subscribers, and users to tailor security responses.
Infrastructure Threats: Addresses threats associated with the "hijacking" of Internet number resources under wartime conditions.
The Shift from Cyber to Physical Threats
Case Study: UAE and Bahrain Strikes: On Sunday, March 4th, Iranian Shahed drones struck two Amazon Web Services () data centers in the United Arab Emirates. The same morning, strikes nearby damaged a third data center in Bahrain.
Implication: This illustrated how threats transition from the cyber domain to the physical domain.
The Royal United Services Institute (RUSI) Perspective: RUSI emphasizes that attacks on data centers pose a direct threat to the sovereignty of digital infrastructure.
Pre-Invasion Cyberattacks: Large-scale cyberattacks on Ukrainian government, banking, and digital services began even before the full-scale Russian invasion in .
Emergency Migration vs. Classical Transformation
Preventive Migration: One of the most critical decisions was the preventive migration of state registries to foreign cloud infrastructure, ensuring continued public services despite physical destruction.
Key Differences in Motivation: * Classical Cloud Transformation: Primarily used as a cost optimization tool. * Wartime Cloud Migration: Used as a mechanism for the emergency preservation of control over digital systems.
Collaborative Efforts: Significant coordination occurred between government institutions, the private sector, and international technology companies. * Partnerships with companies like Microsoft enabled the rapid migration of hundreds of government databases to secure clouds. * Critical sectors such as banking, energy, and telecommunications implemented independent emergency migration scenarios.
Five Basic Response Strategies for Loss of Physical Control
The study formalized five strategies for situations involving the loss of physical control of data centers. Choice of strategy depends on business function, data type, jurisdiction, ownership model, and information sensitivity.
Migration: Moving assets to a new environment.
Logical Denial: Restricting access to the system through logical means.
Security Destruction: Wiping or destroying data to prevent adversary access.
Physical Denial: Rendering the physical hardware unusable.
Sovereign Fallback: Reverting to a baseline state of sovereign control or alternative systems.
Application Examples:
For classified government systems, a combination of Migration, Secure Destruction, and Sovereign Transfer is appropriate.
For less critical workloads, Logical Denial and Delayed Integration are sufficient.
Strategic Importance of Internet Number Resources (INRs)
Definition of Wartime Critical Assets: In conflict, critical assets extend beyond servers to include Internet Number Resources (), specifically prefixes and Autonomous System Numbers ().
Importance of Routing: These resources are necessary for the global routing system. Control over them is often used for political influence, information warfare, or direct cyberattacks (attribution issues).
Preventive Measures for Routing Security: * Route Origin Authorization (): Utilizing digital certification. * Global Routing Monitoring: Real-time tracking of routing incidents. * Role-Based Account Management: Managing entries in routing registry databases. * Regular Auditing: Continuous review of Internet number resources.
Historical Context and Regulatory Adaptation in Ukraine
Occupation and Resource Theft: Since the beginning of Russian aggression in , there were sporadic attempts to change country attributes from "" to "" for companies in occupied territories. These were initially tolerated by registries.
Widespread Hijacking (): During the invasion, these cases became widespread.
Voluntary Registry Lock: Introduced in under pressure from Ukrainian ISPs, this allows for a preventive restriction on any changes to the legal attribution of resources for an extended period, defending Internet sovereignty.
Redefining Digital Sovereignty
Emergency Digital Sovereignty: This model suggests that during existential threats, sovereignty is not defined by the physical location of a server.
New Definition factors: 1. Control over access rules. 2. System management. 3. Cryptographic protection of data.
Strategic Trade-offs: Temporary dependence on foreign "hyperscalers" is acceptable to ensure survival. While "vendor lock-in" is a risk, resource concentration in large cloud ecosystems enables infrastructure availability during the first phase of a crisis.
Long-term Mitigation: Dependencies must be managed with multi-cloud strategies, interoperability requirements, and sovereign fallback mechanisms.
Hybrid Resilience Architecture
The emerging model for digital resilience in Ukraine consists of a three-layered architecture:
Hyperscalers: Provide scalability and survivability.
Content Delivery Network () Platforms: Support perimeter resilience.
National Operators: Maintain jurisdictional continuity.
Economic Impact and Growth
Cloud Consumption Statistics: In , the consumption of Infrastructure as a Service () and Platform as a Service () in Ukraine was valued at approximately Euros.
Wartime Increase: Consumption is projected to increase to Euros by , representing a tripling of the market during the full-scale war.
Digital Ramp Time: This growth is driven by the "digital ramp time" for Ukraine, indicating that wartime cloud migration is a complex model of state adaptation to systematic instability rather than just a technical process.