Greg Rattray on Resilience Lessons Learned in Ukraine

Greg Rattray has spent thirty years inside American cyber defense—as an Air Force officer building early Pentagon-industry partnerships against Chinese espionage, as a White House cybersecurity director, and later as JPMorgan’s global head of information security. In February 2022, as Russian tanks crossed into Ukraine, he did what he’d done throughout his career: he helped architect a partnership to support Ukraine’s cyber defense. Within weeks he’d assembled the Cyber Defense Assistance Collaborative, or CDAC—a coalition that now numbers more than twenty technology and cybersecurity companies, working directly with Ukrainian defenders to protect their country amid war.


“Leaders need to be willing to tell people the truth: that a service might not be there tomorrow, that data might be compromised, and that individuals and institutions need to think about how to live—and keep functioning—without perfect digital availability.”


Looking back to the outbreak of the war, what made you decide to build a partnership to help Ukraine’s cyber defense?

Two things, really. Across that whole career, I kept seeing the value of collaborative defense: the Air Force and the rest of the defense department working with industry to protect defense secrets from Chinese espionage, and later, at JPMorgan, helping architect what became the systemic risk-sharing center. I came to believe that certain problems just go better when you tackle them together.

With Ukraine specifically, I’d already worked with their National Security and Defense Council on cyber strategy. When the conflict began to take shape, I knew Ukraine was going to need cyber help, although it turned out they handled resilience far better than any of us expected. The aggression was so egregious that I felt I had to try something. I asked the Ukrainians what they needed, called the leaders of a series of American companies, and they agreed to do what they could. That’s how it started: the Ukrainians needed help, the Russians had done something egregious, and it required everyone—government and private sector—to figure out what they could do.

What can a company do to support a country under cyberattack that a government can’t?

Speed. In the first six months and even beyond, the private sector could move in ways governments simply couldn’t. We provided tools, training, collaborative calls, intelligence sharing, all at the unclassified level. There’s no clearance process, no resourcing fight. Governments did a great deal for Ukraine on the digital front, but it moved far more slowly, because governmental support must go through many levels. The companies in the collaborative operate the leading-edge technologies themselves, so they can hand tools directly to Ukrainian operators and talk through exactly how to use them. By fall of 2022, people were already asking whether this model could apply elsewhere.

CDAC is now a coalition of more than 20 companies. Where has it delivered the most impact, and where do you wish it could go further?

The clearest early win was situational awareness. Global technology companies have visibility across networks that almost no single government has, and in those first months we fed intelligence support and attack-surface monitoring straight to Ukraine’s national CERT and to military, non-military, and critical infrastructure defenders. That helped them understand where Russian attacks were coming from and make fast decisions. Training has mattered enormously too; SANS Institute has done a huge amount of work over the last eighteen months building up Ukrainian defenders’ skills.

 Where I wish we could go further is structural funding. CDAC has always run on voluntary commitments. There’ve been a couple of small, funded projects, but nothing at the scale of tens or hundreds of millions of dollars that Ukraine needs now to build hardened, sovereign data centers at home instead of relying entirely on cloud providers abroad. What a private-sector collaborative can do voluntarily has a ceiling. The open question is who resources the deeper work from here.

Ukraine has been a testing ground for cyberattacks for nearly a decade. What changed for you personally when the invasion began?

Honestly, my own expectations changed. Like most experts, I assumed that Russia’s sophisticated offensive cyber capability would knock Ukraine’s digital environment offline. That didn’t happen. Viasat went down early, and the Ukrainians rebuilt around it within days. Data centers were bombed, and they moved to cloud-based services. To this day, I talk to Ukrainians sitting in the dark because the power’s out, but their internet still works. That’s the consistent pattern, not the exception.

These events get described in technical terms. What does it look like on a personal level for those defending a country’s networks as part of a war effort?

Incident responders run on adrenaline at first, but you can’t sustain that for years. Ukrainian defenders are weary, but not remotely ready to give up. They’ve gotten smarter about what’s sustainable, accepting that not everything comes back online immediately. And they’ve gotten fast: war sharpens attention and accelerates learning in a way training exercises never can. Even exhausted, they know their networks and recognize an anomaly almost instinctively. The part that worries me most isn’t technical; it’s manpower. Cyber defenders are being pulled from their posts to the physical frontline. That’s a strain no software fixes.

Ukraine has faced some of the most disruptive cyberattacks ever recorded. How has that affected civilians?

Less than you’d expect, and that surprised me. Ukraine had already built a lot of digital services into daily life before the war, with strong leadership pushing government digitization. When the war started, the digital environment was one of the more stable parts of people’s lives, even as power, heating, and physical safety became constant worries. For Ukrainians, cyber is one of the few things that’s kept working.

CDAC received the International Partnership Award at the Institute for Security and Technology’s Cyber Policy Awards. Your colleague Ankur Rawat said the recognition belongs to “the people of Ukraine who are right now on the frontlines.” What have you learned about who defends a country when its networks are the target?

That it’s broader than the people staring at the screens in the Security Operations Center. It’s the network operators, the responders, and increasingly, it has to include the users of digital services, too. People need to understand that their bank account might be briefly disrupted by an attack and not panic as if the world has ended. That’s part of what whole-of-nation digital resilience actually means: hardened infrastructure, sound policy, sustained investment, and international collaboration behind the people doing the daily work.

What’s the single most important lesson Ukraine can teach the rest of the world?

Resilience: how you detect an attack fast, contain it, and restore service quickly—and how you build organizations that can absorb a hit and keep functioning. That’s underemphasized almost everywhere else, including in corporate risk management globally. As a former bank CISO, I think constantly about what a large financial institution or government network could learn from what Ukrainians now do instinctively, because they’ve faced so many attacks. The challenge is systematizing it: turning ten Ukrainians with ten different stories into the three most important, transferable lessons. Effective militaries know how to learn from experience and fold it back into training. That structured learning is exactly what CDAC is trying to build now.

Cyber incidents are a human rights crisis, though they’re still viewed mostly through a technical lens. When did you truly recognize the human toll behind the systems?

It’s been an erosion I’ve watched over years in financial services and healthcare especially. Ransomware attacks on hospitals, outages that block people from their insurance—none of these are abstract. People are genuinely afraid their bank accounts or medical care could be disrupted, and that fear itself is a cost, even before an attack lands. Adversaries understand that friction is cheap to cause and expensive to defend against. What worries me most now is AI accelerating that erosion, and the possibility—which we’ve only glimpsed, as Costa Rica did during its ransomware crisis—of a sustained, weeks-long outage of a truly critical system. I don’t think the probability of such an attack repeating is falling.

If you could change one thing in the next twelve months, what would it be?

I’d want the providers of digital services—governments, corporations, critical infrastructure operators—to start being honest with the people who depend on them. Right now, we all quietly assume a digital service will simply always work, with no breaches and no downtime. That assumption is wrong. The friction is growing and AI is going to make it worse. Leaders need to be willing to tell people the truth: that a service might not be there tomorrow, that data might be compromised, and that individuals and institutions need to think about how to live—and keep functioning—without perfect digital availability. I’ve spent thirty years trying to prevent that reality. But it also must be something everyone starts preparing for, as a matter of basic societal resilience, the way Ukraine has been forced to learn it.

Next
Next

Kristin King on Cyberattacks Inside Our Food Chain