On the issue of assessing the vulnerability of critical infrastructure objects in wartime conditions
DOI:
https://doi.org/10.33405/2786-8613/2025/1/5/336731Keywords:
critical infrastructure facilities, vulnerabilities, risks, threats, cybersecurityAbstract
In modern conditions, especially during wartime, the issue of protecting critical infrastructure is of paramount importance. Assessing the vulnerability of such facilities allows identifying weaknesses in the security system, preventing potential attacks and ensuring effective planning of response measures within the framework of ensuring state security.
Despite the relevance of this issue, Ukraine currently needs to improve a comprehensive methodology for assessing the vulnerability of critical infrastructure facilities adapted to martial law conditions. Existing approaches are fragmented and, in some cases, outdated, having been developed in the context of peacetime. In addition, the practical implementation of infrastructure protection measures is often not systematic, which can affect the overall level of national security.
Thus, there is an urgent need for a scientifically based approach to assessing the vulnerability of CI that would take into account the specifics of modern military threats, include interdisciplinary methods of analysis and provide a basis for decision-making in the field of state security. Thus, the assessment of the vulnerability of critical infrastructure is of particular relevance in the current context.
The assessment of the vulnerability of critical infrastructure facilities involves an analysis of their security and physical safety, which includes physical protection measures, access control, surveillance and alarm systems, as well as effective interaction between the facility's security forces and the entities of the National System of Critical Infrastructure Protection of Ukraine, including the Armed Forces of Ukraine, the Security Service of Ukraine, the National Guard of Ukraine, the National Police of Ukraine, the State Emergency Service, the State Border Guard Service of Ukraine, local authorities, and other relevant entities.
The article discusses the issue of assessing the level of vulnerability of critical infrastructure facilities and proposes a systematic and multidimensional approach to threat analysis. The possible consequences of damage to critical infrastructure for the population, including the risks of social and political destabilization, are proved. Methods for assessing the vulnerability of critical infrastructure facilities and examples of their vulnerability in wartime are presented. The results of international practice are presented and an analysis of potential threats to critical infrastructure is conducted.
References
Nakaz Derzhavnoho komitetu yadernoho rehuliuvannia Ukrainy "Pro zatverdzhennia Poriadku provedennia otsinky vrazlyvosti yadernykh ustanovok ta yadernykh materialiv" № 169 [Order of the State Committee for Nuclear Regulation of Ukraine "On approval of the Procedure for carrying out the assess-ment of the vulnerability of nuclear facilities and nuclear materials" activity no.169]. (2010, November 30). Retrieved from: https://surl.li/ulwcqv (accessed 7 April 2025) [in Ukrainian].
Nakaz Administratsii Derzhavnoi sluzhby spetsialnoho zviazku ta zakhystu informatsii Ukrainy "Pro zatverdzhennia Metodyky ta Kryteriiv i pokaznykiv otsinky stanu zakhyshchenosti obiektiv krytychnoi infrastruktury" № 17 [Order of the Administration of the State Service for Special Communications and Information Security of Ukraine "On Approval of the Methodology and Criteria and Indicators for Estimat-ing the Status of Security of Indoor Infrastructure Objects" activity no. 17]. (2025, January 14). Retrieved from: https://surl.lu/vyxbiv (accessed 7 April 2025) [in Ukrainian].
Bobro D. H. (2015). Vyznachennia kryteriiv otsinky ta zahrozy krytychnii infrastrukturi [Definition of criteria for the assessment of threats to indoor infrastructure]. Stratehichni priorytety. Seriia: ekonomika, no. 4 (37), pp. 83–93. Retrieved from: https://surl.li/prjzyq (accessed 7 April 2025) [in Ukrainian].
Kaplia I. V., Tertyshnyi B. V. (2024). Metodyka otsiniuvannia zahroz obiektam krytychnoi infra-struktury pid chas vohnevoho vplyvu protyvnyka [Methodology for assessing threats to indoor infrastructure facilities during the enemy's fire impact]. Social Development and Security, no. 5 (14), pp. 215–221. DOI: https://doi.org/10.33445/sds.2024.14.5.21 [in Ukrainian].
Murasov R. K., Nikitin A. V., Meshcheriakov I. V., Pidhorodetskyi M. O., Poplavets S. I. (2023). Metodyka otsiniuvannia zahroz i ryzykiv dlia obiektiv krytychnoi infrastruktury za stsenariiamy rozvytku nadzvychainykh sytuatsii [Methodology for assessing threats and risks for critical infrastructure objects un-der emergency development scenarios]. Suchasni informatsiini tekhnolohii u sferi bezpeky ta oborony, no. 3 (48), pp. 35–43. DOI: https://doi.org/10.33099/2311-7249/2023-48-3-35-43 [in Ukrainian].
Murasov R. K., Melnyk Ya. V. (2023). Otsiniuvannia zakhyshchenosti kiberprostoru obiektiv krytych-noi infrastruktury Ukrainy [Assessment of the congestion of cyberspace by the objectives of Ukraine's infrastructure]. Suchasni informatsiini tekhnolohii u sferi bezpeky ta oborony, no. 1 (46), pp. 41–44. DOI: https://doi.org/ 10.33099/2311-7249/2023-46-1-41-44 [in Ukrainian].
Zakon Ukrainy «Pro krytychnu infrastrukturu» № 1882-ІХ [Law of Ukraine about Indoor Infrastruc-ture activity no. 1882-ІХ]. (2021, November 16). Vidomosti Verkhovnoi Rady Ukrainy, no. 5, art. 13. Re-trieved from: https://zakon.rada.gov.ua/laws/show/1882-20#Text (accessed 7 April 2025) [in Ukrainian].
Toliupa S., Parkhomenko I., Antonyuk V. (2021). Method for Identification of Critical Information Infrastructure Objects of the State. In: Proceedings of the 1st International Workshop on Cyber Hygiene – CyberHygiene 2021. CEUR Workshop Proceedings, vol. 3179, pp. 262–271 [in English].
Nakaz Administratsii Derzhavnoi sluzhby spetsialnoho zviazku ta zakhystu informatsii Ukrainy "Pro zatverdzhennia Metodychnykh rekomendatsii shchodo katehoryzatsii obiektiv krytychnoi infrastruktury" № 23 [Order of the Administration of the State Service for Special Communications and Information Security of Ukraine "For approval of methodological recommendations for the categorization of indoor infrastructure facilities" activity no. 23]. (2021, January 15). Retrieved from: https://surli.cc/kznhgg (accessed 7 April 2025) [in Ukrainian].
Postanova Kabinetu Ministriv Ukrainy "Pro zatverdzhennia Poriadku vedennia Reiestru obiektiv krytychnoi infrastruktury, vkliuchennia takykh obiektiv do Reiestru, dostupu ta nadannia informatsii z noho" № 415 [Resolution of the Cabinet of Ministers of Ukraine "On approval of the Procedure for maintaining the Register of indoor infrastructure facilities, including such facilities in the Register, and access to and provision of information from it" activity no. 415]. (2023, April 28). Retrieved from: https://surl.li/lmhjfw (accessed 7 April 2025) [in Ukrainian].
Postanova Kabinetu Ministriv Ukrainy "Pro zatverdzhennia Poriadku provedennia monitorynhu rivnia bezpeky obiektiv krytychnoi infrastruktury" № 821 [Resolution of the Cabinet of Ministers of Ukraine "On approval of the Procedure for monitoring the level of security of indoor infrastructure facilities" activity no. 821]. (2022, July 22). Retrieved from: https://surl.li/qgwnjm (accessed 7 April 2025) [in Ukrainian].
Onopriienko O. S., Sporyshev K. O. (2018). Zmist zavdan syl Natsionalnoi hvardii Ukrainy pry vynyknenni nadzvychainoi sytuatsii vnaslidok avarii na hidrotekhnichnykh sporudakh [The task force of the National Guard of Ukraine in the event of an emergency situation resulting from an accident on hydrotechnical structures]. Derzhavne upravlinnia: udoskonalennia ta rozvytok, no. 5, pp. 243 – 247 [in Ukrainian].
Herasymenko O. M. (2024). Zahrozy obiektam krytychnoi infrastruktury Ukrainy v umovakh voiennoho stanu [Threats to indoor infrastructure facilities of Ukraine under martial law]. Naukovyi visnyk Uzhhorodskoho natsionalnoho universytetu. Seriia: pravo, vol. 3 (84), pp. 257–263 [in Ukrainian].
Nazarenko O. L., Godlevskyi S. O., Danko V. V., Fedorenko V. O. (2025). Protecting Ukraine's critical infrastructure from drone threats: The role of security and defence forces. Actual Issues of Modern Science. European Scientific e-Journal, 37. Ostrava. Retrieved from: https://eiid.eu/ftpgetfile.php?id=248 (accessed 17 April 2025) [in English].
Nazarenko O. L. (2025). Osoblyvosti okhorony obiektiv krytychnoi infrastruktury pidrozdilamy Natsionalnoi hvardii Ukrainy [Features of the protection of indoor infrastructure facilities are provided by the National Guard of Ukraine]. Proceedings of the 2th International scientificand practical conference "Aktualni problemy diialnosti skladovykh sektoru bezpeky i oborony Ukrainy v umovakh osoblyvykh pravovykh rezhymiv: potochnyi stan ta shliakhy vyrishennia" (Ukraina, Kharkiv, March 20, 2025). Kharkiv : NA NHU, pp. 370‒371 [in Ukrainian].
Yaremenko O. I., Strakhnitskyi Ya. O. (2022). Vyznachennia ta upravlinnia zahrozamy u strukturi derzhavnoi polityky zakhystu krytychnoi infrastruktury [The designation of this administration poses a threat to the structure of state policy on the protection of critical infrastructure]. Universytetski naukovi zapysky, vol. 3 (87), pp. 73–82. DOI: DOI: https://doi.org/10.37491/UNZ.87.6 [in Ukrainian].
Shaptala S. O., Romanenko Ye. O., Khrashchevskyi R. V. (2023). Vykorystannia lazeriv dlia protydii bezpilotnym litalnym aparatam [Using lasers to protect unmanned aerial vehicles]. Nauka i tekhnika sohodni. Seriia: tekhnika, no. 11 (25), pp. 617 – 629. Retrieved from: https://surl.li/ejtqpz (accessed 17 April 2025) [in Ukrainian].
Shumyhai O. V., Yermolenko O. V. (2020). Suchasnyi stan bahatofunktsionalnykh zasobiv ta kompleksiv radioelektronnoi borotby [Current state of multifunctional devices and complexes of radio-electronic warfare]. Zbirnyk naukovykh prats Derzhavnoho naukovo-doslidnoho instytutu vyprobuvan i sertyfikatsii ozbroiennia ta viiskovoi tekhniky, vol. 3 (5), pp. 119‒125. DOI: https://doi.org/10.37701/dndivsovt.5.2020.14 [in Ukrainian].
Murasov R., Melnyk Ya., Marko V. (2022). Porivniannia isnuiuchykh metodyk otsiniuvannia zahroz i ryzykiv dlia potentsiino-nebezpechnykh obiektiv krytychnoi infrastruktury v zoni vedennia boiovykh dii [Comparison of existing methods for assessing threats and risks for potentially dangerous objects of indoor infrastructure in the zone of conducting combat operations]. Suchasni informatsiini tekhnolohii u sferi bezpeky ta oborony, no. 3 (45), pp. 32–36. DOI: https://doi.org/10.33099/2311-7249/2022-45-3-32-36 [in Ukrainian].
Ozkan C., Singelee D. (2024). Evidence-Based Threat Modeling for ICS // arXiv preprint arXiv:2411.19759. Retrieved from: https://arxiv.org/abs/2411.19759 (accessed 17 April 2025) [in English].
Kovalchuk V. V., Sydorenko I. M. (2024). Systema kiberzakhystu obiektiv krytychnoi infrastruktury v umovakh viiny [Cybersecurity system for indoor infrastructure facilities in the conditions of the virus]. Naukovyi visnyk KINHU, vol. 2, pp. 43–48. DOI: https://doi.org/10.59226/2786-6920.2.2024.43-48 [in Ukrainian].