Cybersecurity and information protection

Security engineering and comprehensive information protection for information and communications systems under Ukrainian regulatory requirements.

Scope

What is included

Licensed activities

Licensing applies to cryptographic information-protection services and the technical information-protection services defined by the Cabinet of Ministers of Ukraine. Work involving state secrets requires a company permit and individual security clearances.

Security policies

We define the security policy and access control rules for critical and restricted information.

Penetration testing

We simulate an attack and find vulnerabilities, including the human factor.

Protection and compliance

We design security controls, protection toolsets, access control and logging. We prepare systems for security authorisation, Ukrainian state expert review or another applicable conformity assessment.

Why protection

A system must be operated securelyThe information system is being built or already works, but access, logs, roles, change rules and responsibility must be organised.
A security assessment is requiredThe customer needs a clear organisational, technical and documentation scope for authorisation, state expert review or certification.
Access rights grew without one modelUsers, groups, delegation, administrators and integrations have rights that are hard to explain and control.
Resilience must be checkedBefore launch or after changes, configuration, vulnerabilities, human factor, logs and incident readiness must be checked.

What we align

Security governance

Policies, responsible roles, regulations, change model, asset accounting and requirement control.

Access and identity

Roles, groups, SSO/AD, multi-factor authentication, administrators, service accounts and delegation.

Data and documents

Information classification, storage, encryption, backups, archives, QES and retention rules.

Application systems

UnityBase, Intecracy Group products, APIs, integrations, action logs, module permissions and business operation control.

Infrastructure and cloud

Segmentation, servers, networks, DevOps, backup, updates, hardening and configuration control.

Monitoring and incidents

Logging, security events, alerts, response order, root cause analysis and corrective actions.

Stages and outcomes

01

Environment discovery

We survey the operating environment of the information and communications systems: applications, data, roles, integrations, infrastructure and access. Output — an inventory of protected assets and a map of critical dependencies.

02

Threat and requirement model

We define what information is protected and from which threats, and which regulations apply. Output — a threat and intruder model and a requirement list.

03

Security specification and design

We develop the protection plan and technical design, including the access model, segmentation, logging and backups. Output — a security specification and policy package.

04

Protection deployment

We configure protection tools, roles, logging, cryptographic controls and backups for the required assessment route. Output — an operating secure environment and configuration report.

05

Assessment and authorisation

Depending on the system type, we prepare the documentation package for Ukrainian state expert review of technical information protection, security authorisation or certification against an information-security standard.

06

Support and security service

We maintain regulations, updates, role changes, incident response and the information protection service. Output — a support model: SLA, monitoring and repeat checks.

why us

Why IQusion

Typical contractor

Risk
Security after the factSecurity is bolted on at the end, once the architecture is already fixed.
Role-less accessEveryone sees everything; access separation exists on paper at best.
No logsWho did what and when is unknown; investigation is impossible.
Claims without confirmationSecurity promises without an expert conclusion, authorisation or conformity certificate where the system requires one.

IQusion

Recommended
Security from line oneProtection requirements, roles and logs are built into the architecture, not added at the end.
Role model and Zero TrustLeast-privilege access with clear separation of rights.
Full loggingEvery action is recorded; incidents can be investigated and reproduced.
Verified complianceA Ukrainian state expert conclusion, security authorisation or certification, depending on the system class.
FAQ

Frequently asked questions

From the very start. Roles, access rights, logs and data protection are designed together with the architecture, not added at the end on request.
Where Ukrainian public-sector requirements apply, we use the ND TZI 2.5-004-99 regulatory framework for technical information protection. It covers confidentiality, integrity, availability and observability through defined functional security services and protection controls.
The system itself is not licensed. Licensing applies to cryptographic information-protection services and selected technical information-protection services defined by the Cabinet of Ministers of Ukraine. Work involving state secrets requires a special company permit, while security clearance is granted to individual employees.
Yes. We prepare information systems for assessment against Ukrainian protection requirements. Our protection tools have passed state expert review of technical information protection and received expert conclusions at assurance levels G-2 and G-3.
It indicates assurance in the correct implementation of functional security services on Ukraine’s G-1…G-7 scale. There is no separate “G-2 certificate”: the level is recorded in an expert conclusion following state expert review of technical information protection. The assessment route for a system depends on the data it processes and the organisation responsible for it.
By a role model and least-privilege principle: a user sees only what their function needs, with full action logging.
Full logging makes it possible to detect, investigate and reproduce an incident; each critical failure has a recovery plan.
For systems processing state information resources or restricted information, the applicable route may be security authorisation, certification against an information-security standard or assessment under Ukraine’s technical information-protection framework. Systems processing state secrets are subject to separate requirements. Earlier comprehensive information protection system projects continue under the relevant transitional rules.
experience

Scenarios from our practice

Anonymised examples: what held the customer back, what we changed and the outcome. We do not tie them to specific clients due to NDA.

State institution

Compliance with public-sector security requirements

Problem

An information system processed critical data but had not completed the required security assessment.

What we did

Implemented a secure environment with access control, logging and encryption, then completed the required assessment.

Result

The system completed the required assessment and received an expert conclusion.

Large organisation

No security policies

Problem

Access and security rules existed informally and responsibility was blurred.

What we did

Developed security policies and access rules around real processes.

Result

Rules are formalised and responsibility is clear.

Enterprise

Weak spots unknown

Problem

The organisation didn't know where its systems were vulnerable to attacks.

What we did

Ran penetration tests and provided a remediation plan.

Result

Vulnerabilities were fixed and protection strengthened.

Let’s discuss the task Describe the task — we’ll propose an approach, integrations and timing. Need technical support?
Contact us