Understanding the regulatory landscape for IoT in critical infrastructure in Ukraine
The Internet of Things (IoT) is transforming critical infrastructure by integrating thousands of sensors, controllers, and actuators into sectors like energy, water supply, transport, and industry. Each new connected device expands the attack surface, creating new cybersecurity challenges. In Ukraine, the protection of critical infrastructure is governed by the Law of Ukraine “On the Basic Principles of Cybersecurity of Ukraine” and the Law of Ukraine “On Critical Infrastructure.” These laws obligate critical infrastructure operators to ensure cyber protection, report cyber incidents, and bear responsibility for non-compliance.
Ukraine is actively harmonizing its legislation with European standards, particularly with the EU NIS2 Directive (Network and Information Security Directive 2). This directive, which came into force on January 16, 2023, expands the scope and sets stricter requirements for risk management, incident reporting, and supply chain security for critical sectors. The implementation of NIS2 into Ukrainian legislation is part of Ukraine's commitments under the EU Ukraine Facility Plan and a crucial step for integration into the EU digital market. Draft Law No. 11290, adopted on March 27, 2025, aims to reform the national cybersecurity system and incorporates NIS2 recommendations, particularly regarding the creation of national cyber incident response systems and information exchange.
Strategic planning for IoT cybersecurity: From risks to compliance
Effective strategic planning for IoT cybersecurity begins with a deep understanding of the risks specific to these systems. Traditional cybersecurity tools are often not adapted to protect IoT, IoMT (Internet of Medical Things), and OT (Operational Technology) devices used in critical infrastructure. Vulnerabilities can arise from unsecured firmware and weak credentials to a lack of encryption and uncontrolled remote access.
To develop an IoT cybersecurity strategy, it is recommended to use international risk management frameworks such as the NIST Cybersecurity Framework (CSF) and ENISA recommendations. The NIST CSF is a technology-neutral framework that helps organizations of any size and sector manage cyber risks, covering the functions of Identify, Protect, Detect, Respond, and Recover. The Govern function is at the core, as it determines how an organization will implement the other five functions. ENISA also provides detailed cybersecurity recommendations for OT and ICS (Industrial Control Systems), covering risk management, threat modeling, security measures, and incident response, adapted for industrial systems.
Security by Design principles are critical for IoT systems. This means integrating security measures at all stages of a device's lifecycle – from design and development to deployment and disposal. For example, network segmentation and access control are fundamental architectural decisions to enhance the security of IoT devices in critical infrastructure. Network segmentation divides it into smaller, isolated parts, limiting the spread of an attack, while access control ensures that only authorized users and systems can interact with devices.
Key components of an IoT cybersecurity compliance program
To ensure compliance with regulatory requirements and effective protection of critical infrastructure IoT systems, a comprehensive program including several key components is necessary:
- Incident response planning: The NIS2 Directive requires documentation and timely reporting of any significant security incidents, including those involving IoT devices. Ukrainian legislation also mandates reporting cyber incidents. Incident response plans for IoT systems must consider the specifics of operational technologies (OT) and industrial control systems (ICS/SCADA), where continuity of operations and the safety of physical processes are priorities.
- Supply chain security: NIS2 emphasizes the need to document cybersecurity measures throughout the supply chain of IoT devices and components. This involves assessing the security of critical suppliers and incorporating cybersecurity requirements into contracts. Ensuring supply chain security is a comprehensive strategy covering the protection of facilities, information flows, and transportation.
- Data protection: IoT devices collect vast amounts of data, often sensitive. The protection of this data must comply with requirements such as GDPR (General Data Protection Regulation) and Ukrainian legislation on personal data protection. This includes data encryption, multi-factor authentication (MFA), and regular security audits.
- Continuous audit and monitoring: Regular audits and penetration testing (pentesting) are essential for identifying vulnerabilities and assessing the effectiveness of security measures. Continuous monitoring of anomalies in network traffic and device activity helps to promptly detect and respond to threats.
Failure mechanism: Uncontrolled remote access
One typical failure mechanism in IoT cybersecurity in critical infrastructure is uncontrolled remote access. Many IoT devices and ICS/SCADA systems in critical infrastructure were developed decades ago without proper consideration of modern cyber threats, making them vulnerable to unauthorized remote access. If remote access to these devices is not secured with robust authentication, authorization, and encryption mechanisms, attackers can gain control over critical operational processes. This can lead to manipulation of indicators, system shutdowns, or even physical damage to equipment, as occurred during attacks on Ukrainian energy infrastructure in 2015 and 2016. Even with network segmentation, without implementing gateways that filter commands at the application data level, an attacker within a segment can freely manipulate physical controllers.
Integrating international standards into the national context
To strengthen IoT cybersecurity, organizations in Ukraine can adapt international best practices and standards. The ISA/IEC 62443 series of standards is fundamental for the cybersecurity of industrial automation and control systems, covering risk assessment, security architecture development, implementation of protective measures, and security lifecycle management for OT systems, including IoT components. ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS), which is a valuable tool for data protection and risk reduction. The Ukrainian version of this standard – DSTU ISO/IEC 27001:2023 – ensures national compliance.
Harmonizing internal policies and procedures with NIS2 requirements and Ukrainian legislation is key. This involves developing and implementing security policies, conducting regular risk assessments, implementing incident response plans, and ensuring business continuity. An important element is also training and raising personnel awareness regarding IoT cybersecurity best practices and regulatory requirements. Law No. 4336-IX, adopted on March 27, 2025, provides for the creation of specialized cybersecurity units in government agencies and critical infrastructure facilities, as well as systematic cybersecurity training and drills.
Checklist for critical infrastructure IoT systems' cybersecurity compliance readiness
| Criterion | Status |
|---|---|
| Has a complete inventory of all IoT devices in critical infrastructure been conducted? | ☐ Yes / ☐ No |
| Have all IoT systems been identified and classified by criticality level and potential risks? | ☐ Yes / ☐ No |
| Has an IoT risk management policy been developed and implemented, compliant with NIST CSF or ENISA? | ☐ Yes / ☐ No |
| Are there clear procedures for the secure deployment and configuration of new IoT devices? | ☐ Yes / ☐ No |
| Is network segmentation ensured to isolate IoT devices from other critical systems? | ☐ Yes / ☐ No |
| Are authentication and authorization mechanisms implemented for access to IoT devices and data? | ☐ Yes / ☐ No |
| Are firmware and software updates for IoT devices performed regularly? | ☐ Yes / ☐ No |
| Has an IoT-specific cybersecurity incident response plan been developed and tested? | ☐ Yes / ☐ No |
| Is the security of the IoT device and component supply chain assessed? | ☐ Yes / ☐ No |
| Does the processing of data from IoT devices comply with personal data protection requirements (GDPR, Ukrainian legislation)? | ☐ Yes / ☐ No |
| Are regular audits and penetration tests conducted for IoT systems? | ☐ Yes / ☐ No |
| Is there a responsible person or team for IoT cybersecurity in critical infrastructure? | ☐ Yes / ☐ No |
| Is staff training conducted on IoT cybersecurity best practices and regulatory requirements? | ☐ Yes / ☐ No |
| Are NIS2 and Ukrainian legislative requirements integrated into internal IoT cybersecurity policies and procedures? | ☐ Yes / ☐ No |
AZIOT provides comprehensive solutions for integrating and managing IoT systems, enabling critical infrastructure organizations to effectively implement cybersecurity strategies and ensure regulatory compliance. The AZIOT platform supports a wide range of protocols such as MQTT, Modbus, BACnet, KNX, Zigbee, Z-Wave, LoRaWAN, Matter, SCADA, BMS, and ERP, providing centralized monitoring, control, and automation of IoT device security. With edge processing, Unity Base, rules/scenario capabilities, dashboards, auditing, and access control, AZIOT helps integrate disparate systems into a manageable whole, which is critical for cybersecurity compliance. Additional capabilities for enterprise system integration and management are available through Intecracy solutions and inbase.com.ua solutions.
Ensuring IoT cybersecurity in critical infrastructure is not just a technical task but a strategic imperative that requires continuous management attention and an integrated approach. Proactive compliance with regulatory requirements, adaptation of international standards, and implementation of robust architectural solutions will not only help avoid significant penalties and operational disruptions but also strengthen the resilience and trust in critical systems.
Source list
- intecracy.comІзоляція IoT у критичній інфраструктурі: безпека без втрати керованості | Intecracy Group
- ituonline.comIndustrial Control Systems and SCADA in the Age of IoT – ITU Online IT Training
- softwaretoolbox.comWhat is ICS/SCADA Security? | Software Toolbox
- wezom.com.uaКібербезпека для енергетичних та промислових систем | Wezom
- protocol.uaСтаття 6. Кіберзахист критичної інфраструктури - Про основні засади забезпечення кібербезпеки України - Закони України | Protocol
- csirt.csi.cip.gov.uaНормативно-правова база у сфері захисту об'єктів критичної інфраструктури України
- corewin.ua
- cip.gov.ua