On May 14, 2024, the Intecracy Group consortium held a specialized online event in the format of the Intecracy Expert Webinar. The webinar focused on comprehensive protection of information systems in the public and corporate sectors amid growing digital threats and continuous cyberattacks.
The event was led by IQusion IT LLC, a member of Intecracy Group. The speaker was the well-known expert Mykhailo Vihovskyi, who shared practical experience in building modern cybersecurity systems. The online webinar brought together information security specialists, heads of IT departments, system administrators, and representatives of government institutions.
Protection as an architectural issue, not a standalone tool
A central point of the presentation was that cybersecurity should not be treated as a set of isolated products or one-time configurations. For government bodies and businesses, protection of information systems has to be embedded in IT infrastructure architecture and connected with risk management, access administration, and control over internal procedures.
This perspective is especially relevant for organizations that are modernizing infrastructure, conducting architectural audits, or implementing new digital services. At these stages, it becomes clear whether technical mechanisms, organizational procedures, and regulatory requirements are aligned and capable of supporting one another in practice.
KSZI and the integration of technical and regulatory requirements
A separate part of the webinar was dedicated to the creation and certification of Complex Information Security Systems (KSZI). Mykhailo Vihovskyi emphasized that for Ukrainian government bodies and many corporate organizations, building a KSZI is not merely a recommendation but a requirement that must work within the real operating processes of an institution.
According to the speaker, formally obtaining a certificate of compliance cannot replace consistent work on data protection. Regulations, technical policies, access control, and audit procedures must become part of day-to-day operations rather than remain documents prepared only for verification.
“True cybersecurity begins where technical tools are synchronized with the organizational culture of the institution. Building a KSZI is not about obtaining a certificate of compliance for the sake of a checkbox. It is an ongoing process of design, implementation, and audit, where every employee understands their role in the overall defense system,” emphasized Mykhailo Vihovskyi.
Technical mechanisms and infrastructure modernization
The practical part of the discussion addressed architectural solutions that support the resilience of information systems. These included access control, encryption of communication channels, real-time monitoring of security events, and implementation of SIEM (Security Information and Event Management) systems.
Mykhailo Vihovskyi explained that such instruments are effective only when properly administered. For example, firewall rules have to be reviewed in line with changes in business processes, while incident response plans must be clear to the teams responsible for them. In this model, protection is not a static configuration but a managed and continuously reviewed process.
Organizational discipline and standards compliance
The speaker also focused on the human factor, personnel training, internal security policies, and auditing of user actions. Regular cyber hygiene training, phishing simulations, and clear instructions for responding to suspicious activity help reduce the risk of account compromise.
He noted that attackers often look for the simplest route into an organization. If the technical perimeter is well protected, they may try to exploit human weaknesses or gaps in procedures. Therefore, organizational measures such as access management rules and regular review of user actions are as important as cryptographic protection settings.
In conclusion, Mykhailo Vihovskyi encouraged webinar participants to view cybersecurity as an investment in stability and business continuity. For the state and business, this means combining technology, procedures, and compliance with legal requirements into a single protection system. This report is based on information from 1.
