In the face of constant external threats, including military aggression, cyberattacks, and energy crises, Ukrainian enterprises are forced to rethink their business continuity and disaster recovery (DR/BC) strategies. Traditional approaches based on monolithic infrastructures have proven insufficiently resilient. Multi-cloud and hybrid architectures offer new opportunities for risk diversification, enhanced fault tolerance, and adaptation to Ukraine's dynamic regulatory environment.
Unique Challenges and the Need for Multi-Cloud
Resilience against physical destruction, power outages, and intensified cyberattacks is critical for Ukrainian businesses. A single data center, even if well-protected, remains a single point of failure. Distributing infrastructure and data across multiple cloud providers or combining on-premises infrastructure with cloud services significantly reduces the risk of complete operational paralysis. A multi-cloud strategy ensures geographic diversification, which is vital in the face of unpredictable local threats. It also minimizes dependence on a single vendor, providing flexibility and the ability to switch quickly.
Regulatory Landscape and Data Sovereignty in Ukraine
When choosing cloud strategies, Ukrainian enterprises must consider specific national legislative requirements. The Law of Ukraine "On Cloud Services", adopted on February 17, 2022, and effective from September 16, 2022, regulates relations in the field of cloud computing, especially for the public sector. It defines cloud services (IaaS, PaaS, SaaS, SECaaS) and their delivery methods (private, community, hybrid cloud). A significant provision prohibits the processing of state secret information, official information, and data from state registries using cloud resources located outside Ukraine, in temporarily occupied territories, or those belonging to the aggressor state or sanctioned entities.
For financial institutions, Resolution of the National Bank of Ukraine Board No. 99 dated August 25, 2025, effective November 1, 2025, and mandatory from May 1, 2026, establishes requirements for provider selection, contract execution, risk management, data protection, and operational continuity. Cloud service agreements must clearly define security measures, continuity, reporting, and provider liability for subcontractors. Financial institutions are obligated to inform the NBU about the conclusion, amendment, or termination of such agreements.
Critical infrastructure entities must comply with the joint order of the State Service of Special Communications and Information Protection (SSSCIP) and the Security Service of Ukraine (SSU) No. 627/772 dated December 19, 2024 (with amendments of June 12, 2026), which updates the form and recommendations for cyber threat protection plans. These plans require risk assessment, consideration of critical dependencies, and adaptation to new threats, including military aggression. In the context of cloud services, a shared responsibility model applies: the provider is responsible for "security *of* the cloud" (infrastructure), and the user is responsible for "security *in* the cloud" (data, application configurations).
Architectural Models for Business Continuity
The choice of architectural model depends on RTO (Recovery Time Objective) and RPO (Recovery Point Objective) requirements, budget, management complexity, and regulatory constraints.
-
Active-Active: This model involves the simultaneous operation of identical infrastructures in two or more clouds/regions. All sites actively process traffic, ensuring the highest level of availability and minimal RTO/RPO. Advantages include high fault tolerance and rapid recovery. Disadvantages are high cost and complexity of data synchronization and management.
-
Active-Passive: This includes an active primary site and a passive backup, which can be a "hot standby," "warm standby," or "cold standby." If the active site fails, traffic is switched to the passive one. This model is a compromise between cost and recovery speed. RTO/RPO are higher than in active-active but lower than with traditional backups.
-
Multi-Region/Multi-Provider: Distributing infrastructure and data across different geographic regions of a single cloud provider or across different cloud providers. This ensures resilience against large-scale regional failures or issues with a specific provider. For Ukrainian enterprises, this is crucial for protection against physical destruction and energy crises. It is necessary to ensure compliance with data sovereignty requirements, possibly by using Ukrainian providers for sensitive data.
-
Hybrid Cloud: Combining on-premises infrastructure with public or private clouds. This allows sensitive data and critical systems to be kept on own servers (on-premises) or in certified Ukrainian data centers, while using public clouds for less critical or scalable workloads. This model provides maximum control over data and regulatory compliance while leveraging cloud flexibility.
Key Aspects of Implementation and Management
When implementing a multi-cloud or hybrid architecture, several factors must be carefully considered:
- RTO/RPO: Clearly define the acceptable recovery time and acceptable data loss for each business process. This forms the basis for selecting the architectural model and tools.
- Cost: Estimate the total cost of ownership (TCO), including not only direct cloud service costs but also migration, management, security, network infrastructure, and personnel training expenses.
- Management Complexity: Multi-cloud environments require specialized tools for orchestration, monitoring, automation, and security management. Investment in cloud management platforms (CMPs) and IT staff qualification is necessary.
- Data Sovereignty: Ensure compliance with Ukrainian legislation regarding data placement and processing. This may require using Ukrainian cloud providers for certain types of information or adopting hybrid approaches.
- Security: Develop and implement a comprehensive cybersecurity strategy that accounts for the distributed nature of a multi-cloud environment. This includes identity and access management, data encryption, threat monitoring, and timely incident response in accordance with SSSCIP requirements.
Strategic Decision: Balancing Resilience and Efficiency
Choosing the optimal multi-cloud or hybrid architecture for a Ukrainian enterprise is a strategic decision requiring in-depth analysis. There is no one-size-fits-all solution; each enterprise must find a balance between the required level of resilience, implementation and management costs, and regulatory compliance. The goal is to build a flexible, fault-tolerant, and secure infrastructure capable of withstanding various threats and ensuring uninterrupted operation under any circumstances.
To make an informed decision, it is recommended to:
- Assess the criticality of business processes and data.
- Define target RTO (Recovery Time Objective) and RPO (Recovery Point Objective) metrics.
- Analyze compliance with Ukrainian legislation (Law "On Cloud Services," NBU requirements, SSSCIP).
- Develop an architectural model (active-active, active-passive, multi-region/multi-provider, hybrid) considering potential threats.
- Evaluate the reliability and certifications of cloud providers, as well as the location of their data centers.
- Create a detailed risk management and incident response plan.
- Ensure continuous monitoring, testing, and optimization of the business continuity architecture.