Cybersecurity in Ukraine: Modern challenges and talent shortages
For Ukrainian businesses, selecting the optimal cybersecurity model is a strategic decision. Attacks are becoming more sophisticated, demanding 24/7 monitoring and rapid response. The proliferation of hybrid IT infrastructures, combining on-premises and cloud resources, creates a broader attack surface. Ukrainian legislation is actively evolving in critical infrastructure protection, requiring companies to comply with new standards and regulations 1.
A critical factor is the significant shortage of qualified cybersecurity professionals in Ukraine. Finding and retaining specialists capable of developing complex defense strategies, 24/7 monitoring, and incident response is increasingly challenging. This compels IT department heads to seek alternative models for organizing cybersecurity.
In-house SOC: Advantages, challenges, and resource requirements
Implementing an in-house Security Operations Center (SOC) involves establishing an internal team of specialists for monitoring, analyzing, and responding to incidents. This model provides the highest level of control, allowing a company to tailor strategies and tools to its unique needs and risks. An in-house SOC enables deep integration of security processes with business operations, ensuring a quick understanding of incident context 2.
Establishing and maintaining an in-house SOC requires significant upfront investments, estimated from hundreds of thousands to millions of dollars. This includes purchasing hardware, software licenses (SIEM, SOAR, EDR), and building infrastructure. Operational costs are also substantial: high salaries for analysts, continuous staff training, and technology maintenance and updates. Ensuring 24/7 coverage demands a significant number of specialists. For companies with critical infrastructure or high regulatory requirements, an in-house SOC may be justifiable but requires a mature IT security function and a substantial budget 3.
Pros and cons of an in-house SOC
- Pros: Full control, deep integration with business processes, customization for unique needs, maximum data confidentiality.
- Cons: High initial investments and operational costs, difficulty retaining qualified staff, lengthy deployment time, scalability challenges.
MSSP: Flexibility, expertise, and rapid deployment
A Managed Security Services Provider (MSSP) offers outsourcing of cybersecurity functions, allowing companies to engage external experts for monitoring, detection, and response to threats. This model provides access to specialized expertise and advanced technologies without significant upfront investments in internal infrastructure and personnel. MSSPs typically offer 24/7 services, addressing the challenge of round-the-clock coverage and talent shortages 4.
MSSP advantages include rapid deployment, scalable services, and predictable operational costs. For small and medium-sized businesses, as well as companies with limited resources, an MSSP is an optimal solution, allowing them to focus on core activities while delegating complex cybersecurity tasks to external specialists. Key factors for choosing an MSSP provider include: Service Level Agreement (SLA), certifications (ISO 27001, SOC 2), industry-specific experience, geographical coverage, technology stack (SIEM, SOAR, EDR), and reputation and client reviews. It is crucial to carefully select a provider to avoid potential vendor lock-in and ensure an adequate level of data control.
Pros and cons of MSSP
- Pros: Low initial investments, access to broad expertise and technologies, 24/7 monitoring, rapid deployment and scalability, predictable costs.
- Cons: Limited control over processes, potential vendor dependency, necessity for careful selection and contract management.
Hybrid model: Combining control and external expertise
A hybrid cybersecurity model offers a compromise between full outsourcing and an in-house SOC. It combines internal resources and expertise with external MSSP services. For example, a company might maintain an internal Tier 1/2 SOC for primary analysis and response to common incidents, while an MSSP provides Tier 3 services for advanced threat analysis, proactive threat hunting, or responding to complex incidents requiring specialized knowledge. This approach allows retaining control over critical processes while gaining access to deep expertise and the scalability of an external provider.
Implementing a hybrid model requires clearly defining areas of responsibility between the internal team and the MSSP, as well as establishing effective communication channels and tool integration. This optimizes resource utilization, allowing internal specialists to focus on strategic tasks and unique risks, while routine or highly specialized tasks are delegated to the external provider.
Pros and cons of the hybrid model
- Pros: Balance of control and expertise, cost optimization, flexibility in task allocation, leveraging strengths of both models.
- Cons: Complexity in management and coordination, need for clear delineation of responsibilities, potential integration issues.
Practical recommendations for Ukrainian businesses
Choosing the optimal cybersecurity model for a Ukrainian business begins with a thorough assessment of internal capabilities, IT infrastructure status, and the maturity level of cybersecurity processes. It is crucial to conduct a comprehensive risk audit and identify critical assets, as well as regulatory requirements.
When making a decision, consider the following steps:
- Budget assessment: Compare initial investments and operational costs for an in-house SOC and an MSSP. Account for not only direct but also hidden costs (training, staff turnover, downtime).
- Personnel potential analysis: Evaluate the availability and feasibility of attracting qualified cybersecurity specialists in the Ukrainian market.
- Level of control: Determine how important full control over security processes is for your company and whether you are willing to delegate some functions to an external provider.
- Scalability and speed: Consider how quickly you need to deploy or scale cybersecurity solutions.
- Compliance with regulatory requirements: Ensure that the chosen model allows compliance with Ukrainian standards and legislation, particularly the Law of Ukraine “On the Basic Principles of Cybersecurity” and current regulatory documents in information protection and cybersecurity 5.
Softline IT, as a system integrator, has experience in implementing cybersecurity solutions, from current state audits to agreed-upon change plans.
Comparison table ‘In-house SOC vs. MSSP’
| Criterion | In-house SOC | MSSP | Recommendations |
|---|---|---|---|
| Initial Investments | High | Low | If the budget is limited, MSSP is a more accessible option. |
| Operational Costs | High | Medium/High | MSSP offers predictable costs, simplifying planning. |
| Access to Expertise | Limited | Broad | MSSP provides access to a team of specialists with diverse experience. |
| Level of Control | Full | Limited | An in-house SOC ensures maximum control over processes. |
| Scalability | Complex and slow | High and fast | MSSP allows for rapid scaling of services according to needs. |
| Deployment Speed | Long | Fast | MSSP can be deployed significantly faster. |
| Regulatory Compliance | Requires internal effort | Often built into provider services | MSSP can assist in meeting regulatory requirements. |
| Focus on Core Business | Diverts resources | Allows focus on business | MSSP frees up internal resources for core activities. |
Softline IT helps teams plan and implement cybersecurity, from an assessment of the current environment to an agreed change plan.
Sources used
- 01ukrainianlawfirms.comCybersecurity and Data Protection in Wartime Ukraine - Ukrainian Law Firms↗
- 02cynet.comMSSP vs. SOC: 6 Key Differences and How to Choose - Cynet↗
- 03msspproviders.ioMSSP vs In-House Security Team: Which Is Right for You?↗
- 04pently.ioManaged SOC vs. MSSP vs. In-House↗
- 05lbsherald.orgRegulation of CyberSecurity of Ukraine's Critical Infrastructure: Legal Aspects and Standards of Sustainable Protection↗
