Revera.Legal Ukraine and Belarus Enhance Cybersecurity Legislation Amid Rising Threats
Article Content
- •Ukraine's CERT-UA reported 6,000 cyber incidents in 2025, up from 2,500 in 2022.
- •New Ukrainian laws require state bodies to appoint Chief Information Security Officers.
- •Belarus has introduced penalties for cybersecurity violations, effective April 15, 2026.
In 2025, Ukraine's CERT-UA team managed around 6,000 cyber incidents, a significant rise from 2,500 in 2022, though major incidents decreased by 70%. This improvement is attributed to new cybersecurity laws, including Law No. 4336-IX, which aligns Ukraine's practices with the EU's NIS2 Directive. Key changes include mandatory Chief Information Security Officers for state bodies and critical infrastructure operators. Meanwhile, Belarus has introduced new liability provisions for cybersecurity violations through amendments to its Administrative Offences Code, signed into law on April 15, 2026. This law establishes specific penalties for cybersecurity breaches, particularly for critical information infrastructure. Both countries are focusing on enhancing their cybersecurity frameworks to better respond to ongoing threats in a hybrid warfare context. The full implementation of Ukraine's new cybersecurity norms is expected in 2026, while Belarus aims to enforce its new regulations promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…