Surprisingly Useful AI Article Enhancements
A research paper produced by RMIT University’s Centre for Cyber Security Research and Innovation has examined Ukraine’s cyber defence strategy during its conflict with Russia, drawing lessons the authors argue are directly relevant to the Australian Army and broader national security planning.
The study, sponsored by the Australian Army Research Centre and the Department of Defence, involved interviews and workshops conducted across Estonia, Latvia and Lithuania, as well as analysis of Ukraine’s evolving cyber capabilities and its partnerships with Western technology companies, NATO and the EU.
Distinguished Professor Matt Warren, Director of the RMIT University Centre for Cyber Security Research and Innovation, framed the findings against the backdrop of a joint statement from Five Eyes cyber agencies on the risks posed by AI to cyber security.
“The Five Eyes cyber agencies joint statement is important because it warns us that AI is rapidly transforming cyber risk and accelerating the speed, scale and sophistication of attacks,” Professor Warren noted.
“The conflict between Russia and Ukraine confirms that effective cyber defence is a whole of society endeavour with industry and individual professionals, not solely a government undertaking.”
Ukraine’s cyber resilience
The paper traces how Ukraine developed its cyber capabilities over the decade preceding Russia’s full-scale invasion in February 2022, building on reforms driven by international partnerships with the US, EU and NATO.
The researchers found that despite Russia deploying a sustained and varied cyber campaign against Ukrainian critical infrastructure, government systems and civilian targets, the overall impact of these operations on Ukraine’s military capability and command structure was limited.
The paper attributes this to several factors: long-term institutional reform, the development of public-private partnerships, the mobilisation of civilian volunteers and the rapid integration of Western technology platforms.
“Ukraine could resist cyber invasion because it had prepared well in advance: the government and private companies had built strong working relationships through years of reform, citizens were actively involved and local industry pitched in,” Professor Warren observed.
Western technology companies’ role
A significant portion of the research examines the role of multinational technology companies in supporting Ukraine’s cyber defence.
Before the Russian invasion, Ukrainian law required certain government data to be stored on servers physically located within the country. A week before the military invasion, Ukraine’s parliament passed legislation allowing government and private sector data to be moved to the cloud.
That legislative change enabled partnerships with AWS, Microsoft, Google and Oracle to migrate government records into cloud infrastructure outside Ukraine’s borders. Ukraine’s Deputy Prime Minister Mykhailo Fedorov described the action as having saved the government and economy.
AWS provided its Snowball service to transfer large volumes of data outside the country, hosting more than 10 petabytes of data from 27 Ukrainian ministries and 18 universities. The company facilitated the migration of PrivatBank, Ukraine’s largest private bank, moving 270 applications and four petabytes of client data from 3,500 Ukraine-based servers to the cloud within 45 days. AWS committed more than US$105 million in support.
Microsoft provided free storage for all Ukrainian government entities, including the military, schools, universities and hospitals. As of November 2023, this amounted to US$540 million in free services, technical support, equipment and grants. Microsoft’s team worked with Ukrainian government personnel across 10 weeks to provide services spanning cyber defence to cloud migration.
Google Cloud launched training programs to support Ukrainian businesses and IT professionals, with a support fund of almost US$10 million financing Ukrainian start-ups. Google also donated 50,000 Chromebooks for use in Ukrainian schools.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Cyber tools and threat intelligence
Beyond cloud infrastructure, Western cyber security firms provided tools, threat intelligence and direct operational support.
ESET deployed its threat intelligence team to work with Ukraine’s Computer Emergency Response Team (CERT.UA) on threat detection and collaborated with Microsoft to disable targeted attacks against energy providers by the APT Sandworm hacking group.
Cloudflare supplied DDoS attack protection and zero trust network solutions to more than 60 organisations in Ukraine. Cisco Talos set up an internal Ukraine task unit at the outset of the invasion for threat hunting, extending all security licences for Cisco customers in Ukraine and providing US$1 million in industrial ethernet switches to stabilise electricity grids.
Palo Alto Networks’ Unit 42 worked with Ukraine’s State Cyber Protection Centre on sharing threat intelligence. Akamai provided API protection technology to defend government websites and critical infrastructure against DDoS campaigns.
“Western tech companies also played a big role. Firms like Microsoft, AWS, Google, Cloudflare, Cisco, Palo Alto and Starlink supplied vital technology, helped track cyber threats and kept the country connected,” Professor Warren commented.
The IT Army and civilian mobilisation
The research examines Ukraine’s mobilisation of civilian hackers through the IT Army of Ukraine, which grew to more than 300,000 volunteers within days of its creation in February 2022.
The IT Army conducted operations including a DDoS attack on Russia’s Chestny Znak food and logistics traceability system in April 2022, disrupting perishable food sales nationally over four days. In another operation, hackers gained access to a state TV channel during prime time to broadcast messages in support of Ukraine.
The paper notes that while volunteer cyber units demonstrated capacity to contribute to cyber resilience, questions remain about how to integrate non-military units into military operations, coordinate dispersed global volunteers and implement security vetting.
Starlink and communications infrastructure
SpaceX’s Starlink satellite system has been operational in Ukraine since March 2022, providing thousands of terminals including battery power systems to maintain internet connectivity as Russia targeted communications infrastructure.
By July 2022, 15,000 terminals were operating in Ukraine, supporting military operations by connecting special operations units to command centres. The system became integrated into Ukraine’s military communications architecture for command and control of combat operations, including the use of drones and unmanned maritime surface vehicles.
However, the paper notes limits to the advantage, with investigations revealing Russian forces acquired Starlink systems through illicit networks and began employing them on front lines.
Diia platform and digital governance
The research highlights Ukraine’s Diia digital platform, launched in 2020, as an example of how government-industry collaboration on digital infrastructure contributed to national resilience.
Ukraine became the first nation to introduce a digital passport with equal legal value to physical documents. The Diia platform now offers over 125 government services online, with more than 14 million users in 2025.
During the conflict, Diia allowed civilians to report property damage, claim assistance for displaced persons and contribute to national security through a chatbot enabling users to share real-time intelligence on Russian troop movements.
Baltic state experiences
The research team conducted workshops in Estonia, Latvia and Lithuania, examining how these former Soviet states have developed their own cyber defence capabilities in response to Russian threats.
Estonia, which experienced a national cyber attack from Russia in 2007, has developed a “total defence” concept with a constitutional role for civilians in the event of an attack. Its National Defence League has established cyber units with approximately 300 members and 50 per cent female representation.
Latvia has expanded its CERT.LV capabilities, with Canadian NATO cyber units deepening partnerships with Latvian counterparts. Lithuania’s Ministry of Defence aims to establish the nation’s first Cyber Defence Force in 2025 and is introducing legislation to institutionalise volunteer defence forces with embedded cyber units.
Implications for Australia
The paper raises direct questions about Australia’s preparedness, asking whether the country could rely on Western IT companies to provide required cyber services and infrastructure during a future conflict, and whether Australia’s small cyber industry and defence industrial base could support national defence commitments.
The researchers note that while government agencies such as the Australian Signals Directorate, Defence Science and Technology and the Australian Cyber Security Centre engage with industry and research institutions, the level of structured cooperation seen in Ukraine may not exist in Australia.
“For Australia, trusted cyber relationships must be built before a crisis occurs,” Professor Warren emphasised.
“We need to consider a national public-private cyber partnership model, relationship management for multinationals, a national Australian cyber reserve and developing deeper European ties to learn from their lived experience.”
Recommendations
The paper puts forward five recommendations for the Australian Army and government.
The first calls for development of an Australian public-private cyber partnership model that formally integrates private sector capabilities with government and Defence, including joint strategic planning, regular joint exercises and vetting of private sector staff.
The second recommends establishing clear boundaries and incentives for multinational partnerships to balance commercial interests with national security needs, supported by formalised agreements detailing scope of services, performance standards and security standards.
The third proposes developing contractual frameworks to allow global privately owned infrastructure, such as satellite systems, to be used by the Australian Army and Defence to augment existing capabilities.
The fourth calls for development of a national cyber reserve force of vetted, trained personnel who can be mobilised in times of crisis, noting Australia faces a national cyber security shortage of 30,000 professionals.
The fifth recommends developing deeper relationships with European partners, including consideration of membership in Lithuania’s Regional Cyber Defence Centre, to learn from the lived experience of the Baltic states and Ukraine.
The paper also identifies the Australian Civil-Military Centre as a potential mechanism for coordinating whole-of-society responses but notes its current focus remains largely on traditional disaster management and regional security, with limited emphasis on integrating private sector partnerships in a cyber security context.
The study, titled Cyber Security – Partnership between Defence, Society and Private Companies, was produced by RMIT University staff including Professor Matthew Warren, Dr Adam Bartley, Professor Aiden Warren, Dr Malka N Halgamuge, Valerii Paziuk, Tom Saxton, Meredith Jones, Amal Varghese, Lee-ann Phillips and Laki Kondylas. The research was completed in December 2024.
Last Updated on June 27, 2026 by Nick Ross



