<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Nis2-En — TechCom</title>
    <link>https://techcom.org.ua/en/tag/nis2-en/</link>
    <description>Latest TechCom news and insights on enterprise IT solutions.</description>
    <generator>UB CMS</generator>
    <language>en</language>
    <lastBuildDate>Thu, 30 Jul 2026 06:09:53 +0300</lastBuildDate>
    <atom:link href="https://techcom.org.ua/en/tag/nis2-en/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>UAC-0057 toolkit analysis and mitigation strategies from CERT-UA</title>
      <link>https://techcom.org.ua/en/cybersecurity/cert-ua-new-uac-0057-toolkit-and-countermeasures/</link>
      <pubDate>Thu, 30 Jul 2026 06:09:53 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/cert-ua-new-uac-0057-toolkit-and-countermeasures/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;Ukraine&#39;s cyberspace remains a constant battleground. Today, June 6th, CERT-UA issued a warning highlighting new tooling employed by the UAC-0057 group. This arsenal, comprising OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES, signifies an evolution in threats and necessitates enhanced cybersecurity measures for Ukrainian organizations. This is particularly crucial for those operating critical infrastructure or engaging with European partners, as it demands the implementation of comprehensive incident response and risk management processes aligned with &lt;a href=&#34;https://techcom.org.ua/en/tag/nis2-en/&#34; class=&#34;igng-autolink&#34;&gt;NIS2&lt;/a&gt; directive requirements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AI security: preventing data leaks and prompt injection in services</title>
      <link>https://techcom.org.ua/en/cybersecurity/ai-security-platform-protecting-ai-services-from-prompt-injection-and-data-leaks/</link>
      <pubDate>Thu, 23 Jul 2026 23:44:35 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/ai-security-platform-protecting-ai-services-from-prompt-injection-and-data-leaks/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;By 2026, artificial intelligence (AI) has transitioned from an experimental technology to an integral part of business processes, particularly in the banking sector. From chatbots for support to fraud detection and risk analysis systems, AI services process vast amounts of confidential data and participate in decision-making. Consequently, their security has become a paramount concern. The rapid integration of AI into critical infrastructure and the rise of associated cyber threats make strengthening defenses an urgent task for 2026-2027.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DLP methodologies for protecting corporate content in remote work</title>
      <link>https://techcom.org.ua/en/cybersecurity/dlp-strategies-for-corporate-content-protection-in-distributed-work/</link>
      <pubDate>Mon, 13 Jul 2026 06:12:08 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/dlp-strategies-for-corporate-content-protection-in-distributed-work/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;h2&gt;Distributed work and challenges for DLP&lt;/h2&gt;&#xA;&lt;p&gt;Projections indicate that by 2026, over 70% of global companies will adopt hybrid work models, posing substantial challenges to traditional data protection strategies. Distributed infrastructure, the use of personal devices (BYOD), and the proliferation of cloud services increase the risks of confidential information leakage. Classic perimeter security measures are becoming insufficient, necessitating a shift towards more flexible and intelligent DLP solutions based on context and behavioral analysis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sovereign cloud and geopatriation: determining optimal workload jurisdiction</title>
      <link>https://techcom.org.ua/en/infrastructure/geopatriation-and-sovereign-cloud-when-to-move-workloads-closer-to-jurisdiction/</link>
      <pubDate>Wed, 08 Jul 2026 04:33:52 +0200</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/geopatriation-and-sovereign-cloud-when-to-move-workloads-closer-to-jurisdiction/</guid>
      <description>&lt;h2&gt;Uncontrolled Cloud IT Cost Growth: A First Signal to Review Architecture&lt;/h2&gt;&lt;p&gt;While cloud migration often promises cost optimization, the reality is more complex. Many organizations face uncontrolled increases in cloud provider bills. The issue rarely stems solely from the cost of gigabytes or compute hours. Unforeseen expenses are typically a symptom of a deeper architectural problem: a lack of discipline in resource management, blurred responsibilities, and chaotic deployment of workloads across global data centers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Zero Trust implementation for hybrid environments where traditional perimeters fail</title>
      <link>https://techcom.org.ua/en/cybersecurity/zero-trust-for-hybrid-infrastructure-where-the-network-perimeter-no-longer-works/</link>
      <pubDate>Mon, 06 Jul 2026 00:23:52 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/zero-trust-for-hybrid-infrastructure-where-the-network-perimeter-no-longer-works/</guid>
      <description>&lt;p&gt;The shift to hybrid infrastructures, combining on-premises resources with cloud services, has blurred the traditional boundaries of corporate networks. Oleh Kravchenko, a cybersecurity engineer, notes that under these conditions, the network perimeter—which has been the foundation of security for decades—is no longer a sufficient line of defense. The rise of remote work, the adoption of SaaS solutions, and BYOD policies demand a fundamentally new approach to security, where trust in any user or device is absent by default. This concept, known as Zero Trust, is becoming not just a recommendation but a mandatory requirement for protecting corporate data and systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Transitioning the public sector from baseline compliance to active cybersecurity</title>
      <link>https://techcom.org.ua/en/cybersecurity/from-compliance-to-proactive-cybersecurity-for-the-public-sector/</link>
      <pubDate>Wed, 01 Jul 2026 06:08:12 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/from-compliance-to-proactive-cybersecurity-for-the-public-sector/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;The Ukrainian government&#39;s Computer Emergency Response Team, CERT-UA, issued a warning on May 21st of this year regarding an updated toolkit used by the cyber group UAC-0057. This group is actively employing new malware, OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES, in phishing campaigns targeting Ukrainian public organizations, as detailed in a CERT-UA report. This event once again underscores the continuous evolution of cyber threats and the necessity for the public sector to reassess its cybersecurity strategies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Applying supply chain security principles to AI integrations</title>
      <link>https://techcom.org.ua/en/cybersecurity/supply-chain-security-lessons-for-ai-integrations/</link>
      <pubDate>Fri, 19 Jun 2026 13:52:35 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/supply-chain-security-lessons-for-ai-integrations/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;p&gt;Software supply chains are becoming increasingly complex, while dependence on third-party components continues to grow. In 2026, the industry faced a new wave of attacks targeting the npm open-source ecosystem, including the Mini Shai-Hulud campaign and the Miasma incident, during which packages within the &lt;strong&gt;@redhat-cloud-services&lt;/strong&gt; namespace were compromised. Researchers discovered malicious code designed to steal credentials, access tokens, and CI/CD infrastructure secrets. This incident once again demonstrates how vulnerable even large development ecosystems remain and highlights the growing importance of securing AI integrations and software supply chains.&lt;/p&gt;</description>
    </item>
    <item>
      <title>University data breach linked to Oracle PeopleSoft vulnerability</title>
      <link>https://techcom.org.ua/en/cybersecurity/oracle-peoplesoft-vulnerability-exploited-in-university-data-breach/</link>
      <pubDate>Fri, 12 Jun 2026 06:08:40 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/oracle-peoplesoft-vulnerability-exploited-in-university-data-breach/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;Between May 27 and June 9 of this year, a large-scale attack once again demonstrated the vulnerability of educational institutions. The ShinyHunters group, also known as UNC6240, successfully exploited the critical zero-day vulnerability CVE-2026-35273 in Oracle PeopleSoft software. This occurred even before Oracle published an official advisory on June 10, 2026 (Mandiant, 2026).&lt;/p&gt;&lt;p&gt;This incident exemplifies how cybercriminals leverage the time gap between vulnerability discovery and patch release, jeopardizing confidential data and operational resilience for organizations, particularly within the education sector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Android Microsoft 365 token theft: Zero Trust and NIS2 implications</title>
      <link>https://techcom.org.ua/en/cybersecurity/microsoft-365-android-token-theft-risks-and-nis2-compliance/</link>
      <pubDate>Thu, 04 Jun 2026 06:08:38 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/microsoft-365-android-token-theft-risks-and-nis2-compliance/</guid>
      <description>&lt;p&gt;Mobile devices have long ceased to be merely auxiliary work tools. Today, they provide full access to corporate email, documents, collaboration platforms, and business applications. As a result, mobile platforms are increasingly becoming attractive targets for cybercriminals. Recent security research has highlighted a vulnerability in certain Microsoft 365 applications for Android that could enable the theft of authentication tokens and unauthorized access to corporate resources.&lt;/p&gt;&#xD;&#xA;&#xD;&#xA;&lt;p&gt;Although Microsoft has already released security updates to address the issue, the incident reveals a broader challenge: even mature and widely trusted ecosystems can contain vulnerabilities capable of impacting corporate security. For organizations, this serves as another reminder of the importance of a comprehensive approach to mobile security and compliance with modern cybersecurity regulations, including the NIS2 Directive.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defending critical infrastructure against evolving cyber threat tactics</title>
      <link>https://techcom.org.ua/en/cybersecurity/cyber-threats-to-critical-infrastructure-defending-against-new-attacker-tactics/</link>
      <pubDate>Tue, 02 Jun 2026 19:41:58 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/cyber-threats-to-critical-infrastructure-defending-against-new-attacker-tactics/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;This year, cybersecurity for Ukrainian hospitals, local government bodies, and FPV operators has become an even higher priority. According to CERT-UA, throughout March-April 2026, an intensification of cyberattacks on local government bodies and communal healthcare institutions, including clinical and emergency medical hospitals, was recorded (cert.gov.ua, moz.gov.ua, zor.gov.ua). These incidents highlight not only an increase in the number of threats but also a shift in attacker tactics, necessitating a review of existing defense strategies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implementing Zero Trust in legacy environments: migration versus adaptation</title>
      <link>https://techcom.org.ua/en/cybersecurity/zero-trust-for-legacy-systems-migration-or-adaptation/</link>
      <pubDate>Tue, 26 May 2026 06:05:19 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/zero-trust-for-legacy-systems-migration-or-adaptation/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;h2&gt;Cybersecurity challenges for legacy systems&lt;/h2&gt;&#xD;&#xA;&lt;p&gt;According to Gartner research, by 2026, over 50% of organizations investing in Zero Trust solutions will not achieve expected results due to focusing solely on new systems and neglecting legacy infrastructure. Legacy systems, often the backbone of critical business operations, pose a significant risk due to the absence of modern authentication, authorization, and network segmentation mechanisms. Amidst the growing number of cyberattacks and strengthening regulatory requirements like NIS2, protecting these systems becomes a priority.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Addressing cybersecurity challenges in hybrid infrastructure</title>
      <link>https://techcom.org.ua/en/infrastructure/cybersecurity-for-hybrid-infrastructure-challenges-and-solutions/</link>
      <pubDate>Mon, 25 May 2026 06:07:08 +0300</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/cybersecurity-for-hybrid-infrastructure-challenges-and-solutions/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;By 2026, over 85% of large enterprises will adopt hybrid cloud strategies, increasing demands for comprehensive information security systems (ISS). Growing data volumes, distributed infrastructure, and the constant evolution of cyber threats require companies to rethink their security approaches. Ensuring compliance with regulations like ISO/IEC 27001 and NIS2 is becoming critically important for maintaining operational resilience and customer trust.&lt;/p&gt;&#xA;&#xA;&lt;h2&gt;Architectural complexities and fragmentation&lt;/h2&gt;&#xA;&lt;p&gt;Hybrid infrastructure, combining on-premises servers, private, and public clouds, creates unique challenges for ISS. Each component has its own security mechanisms, leading to fragmented control and potential gaps. This complicates centralized security policy management, monitoring, and incident response. For example, different cloud providers may have incompatible APIs for identity and access management, necessitating the development of complex integration solutions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Securing enterprise data within multicloud architectures</title>
      <link>https://techcom.org.ua/en/infrastructure/data-security-in-a-multicloud-world/</link>
      <pubDate>Tue, 19 May 2026 06:08:05 +0300</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/data-security-in-a-multicloud-world/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;h2&gt;Challenges of hybrid and multicloud infrastructure&lt;/h2&gt;&lt;p&gt;By 2026, over 80% of large enterprises will adopt hybrid and multicloud strategies, significantly complicating the cybersecurity landscape. The distribution of data and applications across on-premises, private, and public clouds (Azure, AWS, Google Cloud) introduces new challenges in maintaining a unified level of protection. Key issues include fragmented security policies, monitoring complexity, identity and access management, and ensuring compliance with regulations such as ISO/IEC 27001 and Ukrainian CIS standards.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Protocols for data security during employee offboarding by 2026</title>
      <link>https://techcom.org.ua/en/cybersecurity/securing-data-during-employee-offboarding-by-2026/</link>
      <pubDate>Mon, 18 May 2026 06:12:10 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/securing-data-during-employee-offboarding-by-2026/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;According to analytical reports, by 2026, up to 70% of corporate data breaches will be linked to insufficiently effective employee offboarding processes. This highlights the critical need to review and strengthen access management policies after termination. Despite significant investments in perimeter security and threat detection systems, internal risks, particularly those arising from the improper disconnection of former employees from corporate systems, remain one of the most serious vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mitigating 2026 insider threats via AI-enhanced offboarding</title>
      <link>https://techcom.org.ua/en/cybersecurity/ai-powered-offboarding-defending-against-insider-threats-in-2026/</link>
      <pubDate>Mon, 04 May 2026 06:05:48 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/ai-powered-offboarding-defending-against-insider-threats-in-2026/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;Approximately 60% of corporate data breaches in 2025 were recorded after an employee&#39;s termination – while their access formally remained active. Insider threats originating from current or former employees, contractors, or partners remain one of the most complex cybersecurity challenges. With the evolution of hybrid work models and the widespread use of cloud services, traditional offboarding approaches are becoming insufficient for effectively protecting sensitive data. In 2026, companies will increasingly turn to AI-based solutions to automate and enhance employee offboarding processes, minimizing risks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ensuring NIS2 and ISO/IEC 27001 compliance in cybersecurity</title>
      <link>https://techcom.org.ua/en/cybersecurity/cybersecurity-and-compliance-with-nis2-and-isoiec-27001/</link>
      <pubDate>Wed, 29 Apr 2026 06:07:31 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/cybersecurity-and-compliance-with-nis2-and-isoiec-27001/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;In October 2024, the NIS2 directive became effective in the EU, expanding the scope of cybersecurity requirements to a significantly larger number of sectors than its predecessor. This means companies working with European clients or as part of their supply chains must bring their systems and processes into compliance with the new standards. Simultaneously, the international standard ISO/IEC 27001 remains a fundamental tool for building and maintaining an effective information security management system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trends in AI and VoIP business communications for 2026</title>
      <link>https://techcom.org.ua/en/infrastructure/voip-and-ai-communications-for-business/</link>
      <pubDate>Mon, 20 Apr 2026 06:05:51 +0300</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/voip-and-ai-communications-for-business/</guid>
      <description>&lt;p&gt;Traditional analog PBX systems increasingly fail to meet modern business requirements for scalability, flexibility, and integration with corporate applications. Their maintenance is costly, while their functionality is often limited. VoIP (Voice over Internet Protocol) fundamentally transforms business communications by converting voice calls into digital data transmitted over IP networks. This approach delivers a range of benefits that have become essential for modern organizations.&lt;/p&gt;&#xD;&#xA;&#xD;&#xA;&lt;ul&gt;&#xD;&#xA;&lt;li&gt;&lt;strong&gt;Cost reduction:&lt;/strong&gt; lower international and long-distance calling expenses through the use of existing internet infrastructure.&lt;/li&gt;&#xD;&#xA;&lt;li&gt;&lt;strong&gt;Scalability:&lt;/strong&gt; rapid addition or removal of users and expansion of functionality without significant capital investments.&lt;/li&gt;&#xD;&#xA;&lt;li&gt;&lt;strong&gt;Flexibility and mobility:&lt;/strong&gt; access to corporate telephony from anywhere via IP phones, softphones, or mobile applications.&lt;/li&gt;&#xD;&#xA;&lt;li&gt;&lt;strong&gt;Integration:&lt;/strong&gt; seamless connectivity with CRM, ERP, document management systems, and other business applications through APIs.&lt;/li&gt;&#xD;&#xA;&lt;/ul&gt;&#xD;&#xA;&#xD;&#xA;&lt;h2&gt;AI in Communications: A New Level of Interaction&lt;/h2&gt;&#xD;&#xA;&#xD;&#xA;&lt;p&gt;Artificial Intelligence (AI) is transforming business communications far beyond traditional automation. Modern AI solutions can analyze large volumes of data, understand natural language, predict customer behavior, and personalize interactions. This not only improves operational efficiency but also enhances customer experience.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Methodologies for FinOps and cloud expenditure management</title>
      <link>https://techcom.org.ua/en/infrastructure/finops-and-cloud-cost-management-strategies/</link>
      <pubDate>Mon, 20 Apr 2026 06:05:26 +0300</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/finops-and-cloud-cost-management-strategies/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;p&gt;The head of the development department at a major financial institution faced a challenge: despite all efforts to optimize the architecture, the monthly cloud services bill continued to grow, regularly exceeding the planned budget by 15-20%. Analysis revealed that the causes were not only unaccounted-for peak loads but also inefficient resource utilization, redundant capacity, and a lack of transparency in cost allocation across various projects. This scenario, unfortunately, is typical for many companies migrating to the cloud without a clear cost management strategy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Regulatory demands and the critical first 24 hours of incident response</title>
      <link>https://techcom.org.ua/en/cybersecurity/incident-response-first-24-hours/</link>
      <pubDate>Mon, 30 Mar 2026 12:36:33 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/incident-response-first-24-hours/</guid>
      <description>&lt;p&gt;The first 24 hours after detecting a compromise are the most stressful for any organization. When critical services fail and signs of unauthorized access appear, IT teams naturally want to &#34;put out the fire&#34; quickly: restart servers, restore from backups, and return to normal. However, this approach, focused solely on rapid technical recovery, is now outdated and dangerous for business survival.&lt;/p&gt;&lt;p&gt;Modern incident response is inextricably linked to regulatory requirements. Attempting to immediately erase traces of an intruder destroys digital evidence (forensics), complicates investigations, and prevents timely notification of regulators. This article explores how to synchronize threat containment measures with strict compliance requirements during the first, most critical day after a breach.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implications of the NIS2 Directive for IT Contractors</title>
      <link>https://techcom.org.ua/en/cybersecurity/nis2-and-cybersecurity-what-the-new-eu-directive-means-for-it-contractors/</link>
      <pubDate>Tue, 17 Mar 2026 09:00:00 +0300</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/nis2-and-cybersecurity-what-the-new-eu-directive-means-for-it-contractors/</guid>
      <description>&lt;p&gt;The EU NIS2 Directive came into force in October 2024, significantly expanding the scope of entities required to comply with cybersecurity mandates. For Ukrainian companies providing services to EU clients, NIS2 serves as a practical benchmark.&lt;/p&gt;&lt;h2&gt;Scope of NIS2&lt;/h2&gt;&lt;p&gt;NIS2 covers &#34;essential&#34; and &#34;important&#34; entities across 18 sectors, including energy, transport, healthcare, digital infrastructure, cloud providers, and manufacturing. IT contractors serving these sectors fall under the directive&#39;s purview due to supply chain requirements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026 Electronic Document Management: AI-driven archiving and support</title>
      <link>https://techcom.org.ua/en/electronic-document-management/ai-assistants-and-archiving-automation-in/</link>
      <pubDate>Fri, 06 Mar 2026 11:21:34 +0200</pubDate>
      <guid>https://techcom.org.ua/en/electronic-document-management/ai-assistants-and-archiving-automation-in/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;h1&gt;Electronic Document Management 2026: AI Assistants and Archiving Automation&lt;/h1&gt;&#xD;&#xA;&#xD;&#xA;&lt;p&gt;At the end of reporting periods, legal and administrative departments process large volumes of documents: contracts, addenda, invoices, and acts. Each document must be classified, validated, enriched with metadata, and archived. These operations are still often manual or semi-automated, making them time-consuming and prone to errors, delays, and data inconsistencies.&lt;/p&gt;&#xD;&#xA;&#xD;&#xA;&lt;p&gt;Modern document management approaches rely on AI/ML technologies to automate these processes. These are no longer experimental tools but applied solutions already used in enterprise ECM and DMS systems (Enterprise Content Management / Document Management Systems).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Achieving NIS2 compliance and multi-cloud cost optimization via AI</title>
      <link>https://techcom.org.ua/en/infrastructure/optimizing-multi-cloud-costs-with-ai-and-nis2-compliance/</link>
      <pubDate>Fri, 13 Feb 2026 17:46:19 +0200</pubDate>
      <guid>https://techcom.org.ua/en/infrastructure/optimizing-multi-cloud-costs-with-ai-and-nis2-compliance/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;In October 2024, the NIS2 Directive came into effect, significantly expanding the scope of critical infrastructure entities and strengthening cybersecurity requirements. For many Ukrainian companies working with European clients or integrated into European supply chains, this necessitates adapting IT strategies, particularly concerning cloud cost management and security. By 2026, with the proliferation of multi-cloud architectures, controlling cloud financial flows and ensuring regulatory compliance will become increasingly critical.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2026 outlook for SCADA systems and Industrial IoT</title>
      <link>https://techcom.org.ua/en/bpm-en/industrial-iot-and-scada-trends-for-2026/</link>
      <pubDate>Fri, 30 Jan 2026 13:03:46 +0200</pubDate>
      <guid>https://techcom.org.ua/en/bpm-en/industrial-iot-and-scada-trends-for-2026/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;In 2026, Industrial Internet of Things (IoT) and Supervisory Control and Data Acquisition (SCADA) systems continue to evolve, transforming operational efficiency and security in critical infrastructure, manufacturing, and energy sectors. According to industry observations, a significant portion of enterprise clients are actively implementing hybrid models that combine on-premises SCADA with cloud platforms for IoT device analytics and management.&lt;/p&gt;&#xA;&#xA;&lt;h2&gt;IT and OT convergence: new challenges and opportunities&lt;/h2&gt;&#xA;&lt;p&gt;The traditional gap between IT (Information Technology) and OT (Operational Technology) is rapidly narrowing. Data from IoT sensors and SCADA systems are no longer just monitored but are integrated into corporate ERP and MES systems, feeding analytical platforms and decision support systems. This convergence demands new approaches to architecture, data governance, and, most importantly, cybersecurity. Standards such as ISO/IEC 27001 are becoming mandatory not only for IT but also for OT environments, especially in the context of NIS2, which extends to critical infrastructure operators.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cybersecurity for AI: The emergence of DLP standards by 2026</title>
      <link>https://techcom.org.ua/en/cybersecurity/dlp-for-ai-systems-the-new-cybersecurity-reality-of-2026/</link>
      <pubDate>Tue, 27 Jan 2026 09:52:55 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/dlp-for-ai-systems-the-new-cybersecurity-reality-of-2026/</guid>
      <description>&lt;h2&gt;Rising Risks of Data Leaks in AI Systems&lt;/h2&gt;&lt;p&gt;By 2026, over 70% of new AI systems will experience data breaches due to inadequate Data Loss Prevention (DLP) solution integration. Artificial intelligence, integrated into corporate processes, handles vast amounts of sensitive information—from customer personal data to trade secrets and intellectual property. This data is both the fuel for AI and its most vulnerable point. Traditional DLP systems, designed to protect structured data in conventional enterprise systems, often prove ineffective against complex attack vectors targeting AI models and their training datasets.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Zero Trust for legacy systems: replacement or adaptation by 2026?</title>
      <link>https://techcom.org.ua/en/cybersecurity/zero-trust-for-legacy-systems-adaptation-or-full-replacement-by-2026/</link>
      <pubDate>Fri, 23 Jan 2026 11:27:45 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/zero-trust-for-legacy-systems-adaptation-or-full-replacement-by-2026/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xA;&lt;p&gt;According to Microsoft, 80% of cyberattacks in 2023 were linked to compromised credentials, highlighting the ineffectiveness of traditional perimeter security models. The Zero Trust concept, which mandates continuous verification of access to resources regardless of their location, is no longer just a recommendation but a necessity. However, its implementation in environments dominated by legacy systems, developed decades ago without consideration for modern threats, presents a significant challenge.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Addressing offboarding as a critical cybersecurity vulnerability</title>
      <link>https://techcom.org.ua/en/cybersecurity/offboarding-the-weakest-link-in-business-cybersecurity/</link>
      <pubDate>Fri, 16 Jan 2026 15:46:29 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/offboarding-the-weakest-link-in-business-cybersecurity/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;p&gt;Imagine this scenario: a valuable developer with access to critical repositories and production systems leaves the company. The offboarding procedure is limited to returning a laptop and signing a clearance form. Months later, during an internal audit, it&#39;s discovered that their Gitlab account is still active, and access keys to cloud services were never revoked. This isn&#39;t a hypothetical situation but a real vulnerability that threatens thousands of companies daily.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implementing Zero Trust for Hybrid Infrastructure Security</title>
      <link>https://techcom.org.ua/en/cybersecurity/zero-trust-and-its-role-in-hybrid-infrastructure-protection/</link>
      <pubDate>Thu, 08 Jan 2026 09:39:00 +0200</pubDate>
      <guid>https://techcom.org.ua/en/cybersecurity/zero-trust-and-its-role-in-hybrid-infrastructure-protection/</guid>
      <description>&lt;!-- wp:freeform --&gt;&#xD;&#xA;&lt;p&gt;Imagine this scenario: a remote employee connects to the corporate network via VPN. The traditional security model often grants them broad access to internal resources after a single authentication. But what if their device is compromised, or their credentials are stolen? This is precisely where the fundamental weakness of outdated approaches lies, opening the door for attackers to move laterally within the network. In hybrid infrastructures, where data and applications are distributed across on-premises servers, private, and public clouds, this risk is amplified.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Leveraging Cloud Solutions for 2025 Business Agility</title>
      <link>https://techcom.org.ua/en/bpm-en/cloud-solutions-driving-business-agility-in-2025/</link>
      <pubDate>Tue, 12 Aug 2025 10:00:00 +0300</pubDate>
      <guid>https://techcom.org.ua/en/bpm-en/cloud-solutions-driving-business-agility-in-2025/</guid>
      <description>&lt;p&gt;Cloud migration has evolved from a technological trend into a business imperative. By 2025, companies will face new regulatory requirements, such as the Data Act and NIS2, while simultaneously seeking to optimize costs through FinOps approaches.&lt;/p&gt;&#xA;&lt;h2&gt;Multi-Cloud Strategy&lt;/h2&gt;&#xA;&lt;p&gt;Experts recommend a multi-cloud approach as the foundation of an operational model. This strategy allows for workload distribution across Azure, AWS, and GCP, ensuring resilience and flexibility.&lt;/p&gt;&#xA;&lt;blockquote&gt;&lt;p&gt;“Multi-cloud is not about technology; it’s about business resilience. Companies that rely on a single provider risk losing flexibility.”&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
