Maxim Rivtin, CEO of Cityhost. ua: We analyze the benefits of the National Bank to financial institutions before vikoristannya k

Today, 19:29 | Science and Health
photo HiTech.Expert
Text Size:

The use of dark technologies gives Ukrainian businesses the opportunity to quickly adapt IT infrastructure to meet current needs and scale resources without significant costs.. Now, transferring data and parts of the infrastructure to an external provider creates additional risks for information security. To minimize them, the National Bank of Ukraine has also established rules for preventing bad services by banks, financial companies and payment institutions. From now on, contracts with bad providers may be consistent with the NBU’s requirements, and the very fact of such a financial arrangement must be reported to the regulator. Chief Executive of Cityhost. ua Maxim Rivtin asked what the NBU respects, what provisions are bound to be transferred to the agreement and what needs to be covered before choosing the head of the worst services.

NBU Resolution No. 99 dated September 25, 2025.

Resolution of the NBU Board No. 25. 08. 2025 No. 99, which approved the Regulations on the procedure for stagnating the technology of dark calculations, became the regulator’s reaction to the growing role of external IT suppliers in the financial sector and the strengthening of cyber threats. The document was published on the 2nd spring of 2025, and the decency of the 1st leaf fall in 2025. A six-month transition period has been introduced for financial regulations, during which time it is necessary to bring existing agreements up to date with the new rules.. Therefore, again with peace, the regulations became obligatory for the market on May 1, 2026.

Before the new rules appeared, the financial sector was subject to NBU decree 08. 03. 2022 No. 42. The Vaughn allowed banks to save and process personal data of clients and bank secretaries, as well as carry out processing on data issued in the countries of the European Union, Great Britain, the USA or. This norm was established during the war period and for two years after its implementation, it continues to operate today.

“The problem lay in the fact that the previous rules mainly indicated that data could be saved, but did not establish clear requirements before choosing a provider, replacing the contract and the necessary certificates. Resolution No. 99 transferred the time limit to the systemic regulation model and closed these gaps,” explains the founder of Cityhost. ua Maxim Rivtin.

All services are regulated by the NBU Resolution No. 99 dated September 25, 2025.

New benefits are extended to banks, providers of financial services, operators and participants of payment systems, as well as technological operators of payment services. The situation supports the main models of cloud services - IaaS, PaaS, SaaS and SECaaS. In this case, the regulator does not impose a restriction of the same type: the use of private, collective, public or hybrid infrastructure is allowed.

In fact, it could waste all the external wasteful resources that a financial company uses in its work:.

Requirements: virtual and physical servers, data storage systems, back-end infrastructure.

Platforms: dark database systems, software development middleware, Kubernetes and other container middleware.

Security software: CRM systems with client data, scoring services, electronic document management and other SaaS solutions.

The decree accords great respect to Lanczug’s ghastly servants. For example, a financial institution can enter into an agreement with a SaaS provider, which, in its turn, places information in the infrastructure of another provider. If this partner does not comply with the powers of the regulator, the additional risk is to blame. The provider itself is obliged to notify the client in advance about changes in partners or subcontractors, as such changes may affect the contractual obligations.

The main benefits of providers who provide terrible services.

The regulation does not install direct regulatory authorities until the worst providers, since the NBU evaluates the financial system and agrees with the supplier that the system of risk management. At the same time, it was practically impossible for these services to be implemented without the unwavering readiness of the provider himself.. Therefore, at the hour of your choice, consider the following criteria:.

Certificates of compliance with international information security standards, which the provider is required to issue or publish at least once per week. The decree does not specify specific standards, but in practice the broadest ones are ISO/IEC 27001, 27017 and 27018.

Geography of data processing and storage. It is not allowed to reclaim data centers taken from the aggressor power, in temporarily occupied territories, or from entities subject to sanctions in Ukraine.

Prosperous Lanzug partners. The provider is responsible for documenting the partners received before the conclusion of the contract and promptly notifying the client about their replacement.

Continuity of work. The owner is responsible for documenting and reviewing emergency update plans, backups, and in case of a technical failure.

Obov’yazkovi vmogi before the contract with a bad provider.

Section IV of the Regulations contains 18 obligatory provisions that may be included in the contract. When you look at them from a practical point of view, stench smells in five main directions:.

What you expect to know for specific processes: the agreement may cover the transfer of services and distribution of responsibility for encryption keys, data logs, access control and incident response.

Vitality and possibility of exit: the provider may regularly announce the appointment of contracting parties, and the establishment is responsible for the ability to make changes or to comply with the agreement in the transfer cases.

Confidentiality and certification: information cannot be transferred to third parties without authorization, and provider certificates may be confirmed strictly.

Data and geographical boundaries: the protection of the guilty jurisdiction will be clearly indicated, and after the application of the application, the installation may require further access to information without the possibility of further.

Provider partners: the client needs to be promptly informed about the change of subcontractors, control their access to information with shared access and transfer the possibility of pre-line termination to the contract. If the service is provided by a non-resident, the right of each country to negotiate before the contract is additionally indicated.

Checking the counterparty - how to choose a provider of bad services.

After the implementation of NBU Decree No. 99, the choice of a risky provider for a financial installation can no longer be limited to equalization of performance and technical characteristics. Now there is a comprehensive review of legal, technical and security risks. To reduce potential threats, organizations should follow the following algorithm:.

Change the legal entity. Read the EDRPOU code, the power structure and final beneficial owners using additional open registries and services on the YouControl or Opendatabot platform.

Browse from sanctions lists. Verification must be carried out not only by the third-party provider, but also by the company and partners it receives before providing services.

Install the actual expansion of the equipment. It is necessary to know the specific region and platform where data for each service is collected and saved, including backup copies.

Request current certificates. It is important to verify not only the fact of its obviousness, but also the fact that the services and processes themselves fall within the scope of certification.

Turn over the exit mechanism. Please clarify in advance which lines the client is retrieving his data back from and how the provider confirms the remaining data..

“Previously, many financial companies, when choosing a terrible infrastructure in front of them, adjusted the price and available resources, and food security went to a different plan. Resolution No. 99 did not bring fundamentally new benefits to safety. “Vona gladly put security on par with the excellence of service,” says the CEO of Cityhost. ua Maxim Rivtin. — Now financial clients will immediately request a package of supporting documents: certificates, information about partners, the procedure for reporting an incident and the procedure for deleting data. Since the provider cannot quickly submit these documents, it is simply not possible to reach the agreed upon availability of these services on the right - explains Rivtin Maxim"

Resolution of the National Bank of Ukraine No. 99 dated September 25, 2025 did not stop financial institutions from vikating dark technologies. Її meta - make it possible to control and transfer.

From now on, checking the provider, bringing contracts up to date with new rules and preparing a package of supporting documents and important mental work with the financial sector. For companies that are not located in the financial sector, these benefits are absolutely not obligatory. Prote stinks can serve as a useful guide when choosing any kind of terrible service - from affordable virtual hosting to complex corporate infrastructure. Maxim Rivtin, CEO of Cityhost. ua: We analyze the benefits of the National Bank to financial regulations, read on the HiTech website. Expert.




Add a comment
:D :lol: :-) ;-) 8) :-| :-* :oops: :sad: :cry: :o :-? :-x :eek: :zzz :P :roll: :sigh:
 Enter the correct answer