Current challenges, particularly the full-scale war, are forcing Ukrainian enterprises to fundamentally rethink their approaches to storing and processing critical corporate data. Maximum resilience to incidents and rapid recovery are becoming priorities. This naturally leads to the consideration of multicloud and multi-regional strategies that ensure geographical diversification of infrastructure.
However, such a strategy creates complex legal and architectural challenges. The key issue is compliance with Ukrainian legislation on data sovereignty and ensuring the legal validity of electronic documents stored outside the country. This conflict between the pursuit of resilience and compliance requirements necessitates clear solutions.
The Imperative of Multicloud Resilience
Geographically distributed, multicloud infrastructure is the cornerstone of a modern resilience strategy. Storing data and computing resources in different data centers, regions, or even across different cloud providers significantly reduces the risks associated with local incidents such as cyberattacks, natural disasters, or military actions. This ensures high availability of services and data, minimizes downtime, and allows for rapid recovery of business-critical systems.
For Ukrainian enterprises operating under increased risks to physical infrastructure, multicloud is not just an option but a strategic necessity. It provides a reliable foundation for business continuity, protecting it from unforeseen events and ensuring the availability of key operations.
Ukrainian Legislation: Navigating Data Sovereignty
Ukrainian legislation is actively evolving in the area of cloud services and data sovereignty. A key act is the Law of Ukraine "On Cloud Services" No. 2075-IX, which came into effect in September 2022. This law defines legal relations in the field of cloud computing and establishes specific requirements for the use of cloud services, particularly for government bodies.
An important milestone was Resolution of the Cabinet of Ministers of Ukraine No. 154 of February 11, 2025, which regulates the provision and use of cloud services related to the processing of state information resources or confidential information. This resolution allows government bodies to store registers abroad and not transfer them to Ukraine after the end of hostilities, which is a significant step towards ensuring resilience. However, the Law "On Cloud Services" previously prohibited the processing of information containing state secrets and the placement of state registers in data centers outside Ukraine or in temporarily occupied territories. It also prohibits the use of technical means belonging to the aggressor state or sanctioned entities.
For the private sector, data localization requirements are generally less stringent than for state information resources. However, when dealing with personal data, compliance with the Law of Ukraine "On Personal Data Protection" and general information protection requirements defined by the Law "On Cloud Services" is necessary. The Ministry of Digital Transformation of Ukraine is also actively working on updating its cloud strategy, focusing on cyber resilience, hybrid and distributed cloud architecture, and Secure-by-Design principles.
Ensuring the Legal Validity of Electronic Documents
The legal validity of electronic documents is critical for business continuity and compliance. In Ukraine, this is regulated by the Laws of Ukraine "On Electronic Documents and Electronic Document Management" No. 851-IV and "On Electronic Trust Services" No. 2155-VIII.
A key element is the qualified electronic signature (QES), which is equivalent to a handwritten signature and carries a presumption of its correspondence to a handwritten signature. Each electronic copy of a document signed with a QES is considered an original. This means that electronic documents created and signed using Ukrainian qualified electronic trust services retain their legal validity regardless of the physical location of the servers on which they are stored, provided that all other legislative requirements for information protection and data integrity are met.
Architectural and Legal Solutions for Balance
It is crucial for CIOs, CTOs, and CISOs to develop an architecture that simultaneously ensures resilience and compliance. This requires an integrated approach:
- Hybrid and Multicloud Architecture: Placing critical data and applications in a hybrid environment that combines Ukrainian data centers (for data requiring strict localization) and foreign cloud platforms (to ensure geographical diversification and resilience).
- Data Segmentation: Clear demarcation of data based on sensitivity level and sovereignty requirements. Information not subject to strict localization restrictions can be stored abroad.
- Use of Ukrainian Qualified Electronic Trust Services: To ensure the legal validity of electronic documents, regardless of their storage location, it is necessary to use QES issued by accredited Ukrainian providers.
- Encryption and Key Management: Implementing robust data encryption methods both at rest and in transit, with key management in a controlled environment.
- Contractual Relationships with Providers: Thoroughly reviewing the terms of contracts with cloud providers regarding responsibility, data protection, jurisdiction, and audit capabilities. A new draft law from the Ministry of Digital Transformation aims to provide greater flexibility in contractual relationships, moving away from a rigid "Standard Contract."
- Regular Audits and Risk Assessments: Continuous monitoring of the architecture and processes for compliance with legislation and cybersecurity best practices.
Checklist for Evaluating Cloud Providers and Architectural Solutions
When choosing cloud providers and developing an architecture for storing and processing critical corporate data, IT operations managers and enterprise architects should consider the following points:
- Does the provider have certifications for compliance with international security standards (ISO 27001, SOC 2 Type II)?
- Does the provider ensure geographical diversification of regions and availability zones for maximum resilience?
- Does the provider offer tools for data encryption and key management that comply with Ukrainian standards?
- Does the architecture allow for clear segmentation of data by sensitivity level and localization requirements?
- Does the provider support integration with Ukrainian qualified electronic trust services for signing electronic documents?
- Do the provider's contract terms comply with Ukrainian legislation regarding data protection and party liability?
- What data recovery and business continuity mechanisms does the provider offer in case of incidents?
- Does the provider offer transparent audit and reporting mechanisms regarding security and compliance?
- Does the provider have experience working with Ukrainian enterprises and understand the specifics of Ukrainian legislation?
Integrating these aspects into the SL Global Service strategy will enable the creation of a robust and legally sound multicloud architecture that meets both resilience needs and the requirements of Ukrainian legislation.