Is Ukraine safe for software
development outsourcing?
Information Security, Business Climate, and Reforms
Many companies that are looking for a software development outsourcing company
in Ukraine wonder if the destination is safe in terms of politics, economy, business
climate, and information security.
And it is only logical as choosing the wrong outsourcing provider may be periculous
to the overall business process.
We’ve completed the guide that covers all these aspects and will hopefully help you
make well-weighed conclusions.
Intro
Companies that consider software development offshoring and look for an
outsourcing vendor must be 100% sure all their information assets and the users’
confidential data are safe and sound. A lot of businesses choose to cooperate
with Ukrainian developers due to the large pool of qualified talent in the country.
However, they often have many questions concerning Ukraine’s safety as a
software development outsourcing destination.
That’s why we’ve decided to take a closer look at the Ukrainian security legislation
and talk with N-iX information security team to establish how safe Ukraine is for
software development offshoring.
Legislation of Ukraine is being
harmonized with the EU law
Ukraine is going through a wide spectrum of reforms right now, and the state is
working in many directions to effectuate EU membership. Despite the post-soviet
legacy, Ukraine has taken many steps to fight corruption and red tape. All these
efforts have resulted in the stabilization of the economy, the inflow of investments,
and improved legislation.
The state is hitting its target for 3.5% GDP growth in 2018 and experiences
a persistent decline in inflation. Ukraine’s IT exports grew by 20% year-on-year
in 2017 to reach a new record of USD 3.6 billion. Thus Ukraine has proven itself
as a reliable IT outsourcing destination.
Ukraine’s legislation on data protection and info
security focuses mostly on cybersecurity in the state
sector. Regarding data protection in the private sector,
In June 2010, Ukrainian Parliament passed the Law
“On Protection of Personal Data” which came into
effect in January 2011. In July 2013, Parliament
passed amendments to the Data Protection Law
and made it more up to date.
On 25 October 2017, Ukraine entered the EU–Ukraine
AssociationAgreementandpublishedaplanofmeasures
for its effective implementation. The plan pays special
attention to the harmonization of Ukrainian legislation
with the EU law. According to Paragraph 11 of this
plan, the Ukrainian Parliament Commissioner for
Human Rights was required to revise legislation
on the protection of personal data and bring it into
compliance with GDPR.
Additionally, Ukraine’s President Petro Poroshenko
has signed the bill on the key principles of ensuring
cyber security in Ukraine. The law takes into
consideration a number of proposals from NATO
and the EU experts.
How Ukrainian IT companies
ensure data protection
and information security
Ukrainian laws are still undergoing changes to be in full accord with the EU legislation.
As a result, established Ukrainian IT companies, their information security, and legal
teams take lead on complying with international regulations, following best security
practices, and meeting clients’ demands. For instance, here are some of the basic
security procedures N-iX uses:
Office security
First of all, we ensure the physical security of our
facilities, use CCTV cameras and advanced access key
card systems to prevent unauthorized visitors from
the office. N-iX infosec team carries out background
verification checks on all candidates for employment
and obliges employees to sign security commitments.
All employees of the organization receive appropriate
awareness education and regular updates in
organizational policies and procedures. The company
ensures the security of teleworking and protects
information that is accessed, processed or stored at
teleworking sites.
Data protection
Our team protects data from loss, destruction,
falsification, and unauthorized access according to
legislative, regulatory, contractual and business
requirements. N-iX ensures secure log-on procedures,
password management, cryptographic keys
management, network security, and information asset
management. The employees’ access rights
to information are removed when the cooperation
is over.
Protection of intellectual property
We ensure the protection of intellectual property
rights according to the legislative and contractual
agreements. Our information security teams revise
the security policies at planned intervals to guarantee
they are suitable, adequate and effective. Also, we
maintain appropriate contacts with relevant authorities,
ecurity forums, and interest groups to provide business
continuity in case of an emergency or a disaster.
It is also worth mentioning that Ukrainian programmers
are ranked first in the world in terms of security.
Countries with the best developers
regarding security
How to establish secure cooperation
with an IT vendor
When a client has formulated their accurate
requirements concerning info security and data
protection, the company should verify if an
outsourcing vendor follows the corresponding
procedures and policies to meet the specific demands.
First, ask if the IT company undertakes recurrent
internal audits of its compliance with the security
controls and policies. Furthermore, the compliance
must be verified by an accredited third party
(e.g., once a year).
Second, an IT outsourcing vendor must provide an
accurate information asset inventory and indicate
what devices and networks they will use to store,
access, and transfer the data. The company must also
specify what administrative and technical controls
they will apply to ensure the integrity, availability,
and confidentiality of the information assets.
Third, there must be a contract clause that states
what happens to the data when the agreement
is terminated. A vendor should give a written
confirmation that the data has been deleted
or transferred back to its owner.
To ensure data protection and compliance with GDPR,
the vendor can provide pseudonymization of the data.
Pseudonymization is a de-identification procedure
by which personal data is replaced by one or more
artificial identifiers, or pseudonyms, and thus the IT
vendor has no access to actual users’ personal data.
Also, the customer can require the IT vendor to work
remotely with its data without porting it to servers in
Ukraine.
Another important evidence that the IT outsourcing
company follows all the security policies and
procedures is obtaining the corresponding certificates
and compliance with the international laws and
regulations. For instance, if a company is granted
with ISO 27001 it means it implements a wide
range of administrative and physical controls to
ensure confidentiality, integrity, and availability
of information assets. Another standard, PCI DSS
is required to process credit card data. Whereas,
compliance with HIPAA law is required when working
with medical data.
Also, it is crucial for an IT outsourcing vendor to have
legal representatives in the EU or US offices.
Political situation
Companies that are looking for an IT outsourcing vendor in Ukraine may have
concerns regarding its safety as there is an ongoing conflict in the eastern part
of Ukraine. However, let’s take a closer look at the situation.
First. The conflict is taking place in the remote, secluded area in the east of
Ukraine, and it has no impact whatsoever on other regions.
Ukraine is the continent’s second largest country at 603,628 square kilometres,
and the distance between some cities is substantial. For instance, major IT hubs in
Ukraine, Kyiv and Lviv, are closer to Prague, Krakow or Berlin than to the conflict
zones.
Distance between main software development
outsourcing hubsand ‘conflict zones’
Second. To settle the conflict and keep it under
control, Ukraine is cooperating with the US and
Canadian army, US Congress, UN, etc.
For instance, Canada has been a strong supporter
of Ukraine in its fight against the oppressor. It also
provides direct support to the Ukrainian government
and army in a number of different ways.
The House of Representatives of the US Congress
supported the allocation of $ 250 million to help
Ukraine enforce security in 2019.
Third. There are other examples of countries with
conflict zones that have sustainable economy and
favourable business climate.
Ukraine’s challenges are similar to those countries such
as Morocco (Western Sahara issue), Pakistan (Kashmir),
Israel, and other countries face. And they remain alluring
despite conflict or political instability.
Reforms and innovations
As part of its anti-corruption endeavour the country
has implemented:
the ‘Prozorro‘ e-procurement system throughout all
levels of government and state owned enterprises
public access to state property registers,
implementing E-Data, and placing the Treasury
system online
e-declarations for all public servants, including
the judiciary
automatic VAT refunds system
New anti-corruption institutions. These include
the newly established:
National Anti-Corruption Bureau (NABU)
National Agency to Prevent Corruption (NAPC)
Special Anti-Corruption Prosecutor (SAP)
To make the anti-corruption measures more effective, the
governmentleveragestechinnovations,suchasblockchain.
For instance, the Ministry of Finance of Ukraine
implemented Distributed Labs’ eAuction, a blockchain
platform for transparent auction management.
EU visa-free travel for Ukraine
An important step in making Ukraine closer to EU was approving visa-free travel
for Ukrainians. The EU’s approval came in 2017 and followed the reforms in areas
such as migration, public order and security, external relations and fundamental
rights. That facilitated business traveling for Ukrainians and eliminated another
barrier between Ukrainian and European business worlds
Enhanced infrastructure
and new routes
Ukraine is perfect for doing business as it is easily accessible to key global business
hubs. There are 19 passenger airports, and every year airway companies open new
flights from Ukraine. It takes just 3 hours to get to London from Kyiv by air, and —
2 hours from Kyiv to Berlin.
Business climate
Sustainable growth is the best indicator
of favourable business climate
Despite the conflict and post-soviet legacy, Ukraine
is showing signs of stabilization and prosperity, and it is
hitting its target for 3.5% GDP growth in 2018. Inflation
is going down and is estimated to normalize under 6%
by 2019.
A large share of the profit growth can be tributed to the
development of the IT industry. It is one of the most
rapidly developing sectors in Ukraine. According to PwC,
the IT sector in Ukraine has grown by 15-20% over the
last 2 years (from $2.5 billion to $3 billion). According to
Bloomberg Innovation Index, the country is rated 46th
for its adoption of innovations.
Moreover, Ukraine has gone up 23 positions up over the
last 3 years in the World Bank’s Ease of Doing Business
2017. The country also ranks among the world leaders in
terms of outsourcing, according to the Global Services
Location Index by A.T. Kearney, and is rated 24th.
Moreover, 13 Ukrainian outsourcing companies made it
into the 2017 Global Outsourcing 100.
Ukraine is an alluring place
for investment
Since 2014 the state has focused greatly on improving
the business climate in Ukraine, and it has taken many
measures in that direction. The Government has approved
its Strategic Action Plan 2020, which entails:
On-going deregulation ( the government canceled more
than 450 outdated regulations)
Improving corporate governance of state agencies
and privatization
Supporting innovation
Improving the Ease of Doing Business
As a result of the combined effort, Ukraine has become
an investment hot spot.
Total market capitalization stands at $6.5bn. There are
also some big companies on the market, which is of vital
importance for big investors. For instance, 40+ companies
are valued at $50m or beyond. The market is fairly liquid,
too. The average daily trade volume stands at $265m.
2017 year in hightlights
Ukraine is home to 100+ RD offices of market-leading
companiesacrossawiderangeofindustries,fromtelecoms,
gaming, healthcare, fintech, to retail, and e-commerce.
Such global leaders as Boeing, Aricent, Huawei, Siemens,
Oracle, Magento, Apple, Microsoft, Deutsche Bank, Skype,
eBay, IBM have RD offices in Ukraine.
The USA has the largest share of RD partnerships
in Ukraine. It equals about 45% of companies. Kyiv is the
key location for setting up RD offices. Other cities that
are a perfect fit for setting up an RD office include Lviv,
Dnipro (Dnipropetrovsk), Odesa, Kharkiv, and Vinnytsia.
In 2018, a few companies, including PwC, opened up new
offices in Ukraine.
Ukraine houses a wide range of top-notch product
companies including Grammarly, Readdle, Jooble,
Depositphotos, TemplateMonster, GitLab, and
the startup community is growing by 500 new
entrepreneurs each month. Also, Ukraine is home
to High Castle, a blockchain-based investment
marketplace and startup accelerator.
As we can see, despite some instability, Ukraine is showing strong signs of economic
and political stabilization. Since 2014 the state has implemented a variety of
reforms and improvements in different directions, from legislature to tourism.
As a result, it has proven an alluring and reliable destination for investment, RD,
software development outsourcing.
Afterword

Is Ukraine safe for software development outsourcing?

  • 1.
    Is Ukraine safefor software development outsourcing? Information Security, Business Climate, and Reforms
  • 2.
    Many companies thatare looking for a software development outsourcing company in Ukraine wonder if the destination is safe in terms of politics, economy, business climate, and information security. And it is only logical as choosing the wrong outsourcing provider may be periculous to the overall business process. We’ve completed the guide that covers all these aspects and will hopefully help you make well-weighed conclusions. Intro
  • 3.
    Companies that considersoftware development offshoring and look for an outsourcing vendor must be 100% sure all their information assets and the users’ confidential data are safe and sound. A lot of businesses choose to cooperate with Ukrainian developers due to the large pool of qualified talent in the country. However, they often have many questions concerning Ukraine’s safety as a software development outsourcing destination. That’s why we’ve decided to take a closer look at the Ukrainian security legislation and talk with N-iX information security team to establish how safe Ukraine is for software development offshoring.
  • 4.
    Legislation of Ukraineis being harmonized with the EU law Ukraine is going through a wide spectrum of reforms right now, and the state is working in many directions to effectuate EU membership. Despite the post-soviet legacy, Ukraine has taken many steps to fight corruption and red tape. All these efforts have resulted in the stabilization of the economy, the inflow of investments, and improved legislation. The state is hitting its target for 3.5% GDP growth in 2018 and experiences a persistent decline in inflation. Ukraine’s IT exports grew by 20% year-on-year in 2017 to reach a new record of USD 3.6 billion. Thus Ukraine has proven itself as a reliable IT outsourcing destination.
  • 5.
    Ukraine’s legislation ondata protection and info security focuses mostly on cybersecurity in the state sector. Regarding data protection in the private sector, In June 2010, Ukrainian Parliament passed the Law “On Protection of Personal Data” which came into effect in January 2011. In July 2013, Parliament passed amendments to the Data Protection Law and made it more up to date. On 25 October 2017, Ukraine entered the EU–Ukraine AssociationAgreementandpublishedaplanofmeasures for its effective implementation. The plan pays special attention to the harmonization of Ukrainian legislation with the EU law. According to Paragraph 11 of this plan, the Ukrainian Parliament Commissioner for Human Rights was required to revise legislation on the protection of personal data and bring it into compliance with GDPR. Additionally, Ukraine’s President Petro Poroshenko has signed the bill on the key principles of ensuring cyber security in Ukraine. The law takes into consideration a number of proposals from NATO and the EU experts.
  • 6.
    How Ukrainian ITcompanies ensure data protection and information security Ukrainian laws are still undergoing changes to be in full accord with the EU legislation. As a result, established Ukrainian IT companies, their information security, and legal teams take lead on complying with international regulations, following best security practices, and meeting clients’ demands. For instance, here are some of the basic security procedures N-iX uses:
  • 7.
    Office security First ofall, we ensure the physical security of our facilities, use CCTV cameras and advanced access key card systems to prevent unauthorized visitors from the office. N-iX infosec team carries out background verification checks on all candidates for employment and obliges employees to sign security commitments.
  • 8.
    All employees ofthe organization receive appropriate awareness education and regular updates in organizational policies and procedures. The company ensures the security of teleworking and protects information that is accessed, processed or stored at teleworking sites. Data protection Our team protects data from loss, destruction, falsification, and unauthorized access according to legislative, regulatory, contractual and business requirements. N-iX ensures secure log-on procedures, password management, cryptographic keys management, network security, and information asset management. The employees’ access rights to information are removed when the cooperation is over.
  • 9.
    Protection of intellectualproperty We ensure the protection of intellectual property rights according to the legislative and contractual agreements. Our information security teams revise the security policies at planned intervals to guarantee they are suitable, adequate and effective. Also, we maintain appropriate contacts with relevant authorities, ecurity forums, and interest groups to provide business continuity in case of an emergency or a disaster. It is also worth mentioning that Ukrainian programmers are ranked first in the world in terms of security. Countries with the best developers regarding security
  • 10.
    How to establishsecure cooperation with an IT vendor When a client has formulated their accurate requirements concerning info security and data protection, the company should verify if an outsourcing vendor follows the corresponding procedures and policies to meet the specific demands. First, ask if the IT company undertakes recurrent internal audits of its compliance with the security controls and policies. Furthermore, the compliance must be verified by an accredited third party (e.g., once a year). Second, an IT outsourcing vendor must provide an accurate information asset inventory and indicate what devices and networks they will use to store, access, and transfer the data. The company must also specify what administrative and technical controls they will apply to ensure the integrity, availability, and confidentiality of the information assets. Third, there must be a contract clause that states what happens to the data when the agreement is terminated. A vendor should give a written confirmation that the data has been deleted or transferred back to its owner.
  • 11.
    To ensure dataprotection and compliance with GDPR, the vendor can provide pseudonymization of the data. Pseudonymization is a de-identification procedure by which personal data is replaced by one or more artificial identifiers, or pseudonyms, and thus the IT vendor has no access to actual users’ personal data. Also, the customer can require the IT vendor to work remotely with its data without porting it to servers in Ukraine. Another important evidence that the IT outsourcing company follows all the security policies and procedures is obtaining the corresponding certificates and compliance with the international laws and regulations. For instance, if a company is granted with ISO 27001 it means it implements a wide range of administrative and physical controls to ensure confidentiality, integrity, and availability of information assets. Another standard, PCI DSS is required to process credit card data. Whereas, compliance with HIPAA law is required when working with medical data. Also, it is crucial for an IT outsourcing vendor to have legal representatives in the EU or US offices.
  • 12.
    Political situation Companies thatare looking for an IT outsourcing vendor in Ukraine may have concerns regarding its safety as there is an ongoing conflict in the eastern part of Ukraine. However, let’s take a closer look at the situation. First. The conflict is taking place in the remote, secluded area in the east of Ukraine, and it has no impact whatsoever on other regions. Ukraine is the continent’s second largest country at 603,628 square kilometres, and the distance between some cities is substantial. For instance, major IT hubs in Ukraine, Kyiv and Lviv, are closer to Prague, Krakow or Berlin than to the conflict zones.
  • 13.
    Distance between mainsoftware development outsourcing hubsand ‘conflict zones’
  • 14.
    Second. To settlethe conflict and keep it under control, Ukraine is cooperating with the US and Canadian army, US Congress, UN, etc. For instance, Canada has been a strong supporter of Ukraine in its fight against the oppressor. It also provides direct support to the Ukrainian government and army in a number of different ways. The House of Representatives of the US Congress supported the allocation of $ 250 million to help Ukraine enforce security in 2019. Third. There are other examples of countries with conflict zones that have sustainable economy and favourable business climate. Ukraine’s challenges are similar to those countries such as Morocco (Western Sahara issue), Pakistan (Kashmir), Israel, and other countries face. And they remain alluring despite conflict or political instability.
  • 15.
    Reforms and innovations Aspart of its anti-corruption endeavour the country has implemented: the ‘Prozorro‘ e-procurement system throughout all levels of government and state owned enterprises public access to state property registers, implementing E-Data, and placing the Treasury system online e-declarations for all public servants, including the judiciary automatic VAT refunds system New anti-corruption institutions. These include the newly established: National Anti-Corruption Bureau (NABU) National Agency to Prevent Corruption (NAPC) Special Anti-Corruption Prosecutor (SAP) To make the anti-corruption measures more effective, the governmentleveragestechinnovations,suchasblockchain. For instance, the Ministry of Finance of Ukraine implemented Distributed Labs’ eAuction, a blockchain platform for transparent auction management.
  • 16.
    EU visa-free travelfor Ukraine An important step in making Ukraine closer to EU was approving visa-free travel for Ukrainians. The EU’s approval came in 2017 and followed the reforms in areas such as migration, public order and security, external relations and fundamental rights. That facilitated business traveling for Ukrainians and eliminated another barrier between Ukrainian and European business worlds Enhanced infrastructure and new routes Ukraine is perfect for doing business as it is easily accessible to key global business hubs. There are 19 passenger airports, and every year airway companies open new flights from Ukraine. It takes just 3 hours to get to London from Kyiv by air, and — 2 hours from Kyiv to Berlin.
  • 17.
    Business climate Sustainable growthis the best indicator of favourable business climate Despite the conflict and post-soviet legacy, Ukraine is showing signs of stabilization and prosperity, and it is hitting its target for 3.5% GDP growth in 2018. Inflation is going down and is estimated to normalize under 6% by 2019. A large share of the profit growth can be tributed to the development of the IT industry. It is one of the most rapidly developing sectors in Ukraine. According to PwC, the IT sector in Ukraine has grown by 15-20% over the last 2 years (from $2.5 billion to $3 billion). According to Bloomberg Innovation Index, the country is rated 46th for its adoption of innovations. Moreover, Ukraine has gone up 23 positions up over the last 3 years in the World Bank’s Ease of Doing Business 2017. The country also ranks among the world leaders in terms of outsourcing, according to the Global Services Location Index by A.T. Kearney, and is rated 24th. Moreover, 13 Ukrainian outsourcing companies made it into the 2017 Global Outsourcing 100.
  • 18.
    Ukraine is analluring place for investment Since 2014 the state has focused greatly on improving the business climate in Ukraine, and it has taken many measures in that direction. The Government has approved its Strategic Action Plan 2020, which entails: On-going deregulation ( the government canceled more than 450 outdated regulations) Improving corporate governance of state agencies and privatization Supporting innovation Improving the Ease of Doing Business As a result of the combined effort, Ukraine has become an investment hot spot. Total market capitalization stands at $6.5bn. There are also some big companies on the market, which is of vital importance for big investors. For instance, 40+ companies are valued at $50m or beyond. The market is fairly liquid, too. The average daily trade volume stands at $265m.
  • 19.
    2017 year inhightlights
  • 20.
    Ukraine is hometo 100+ RD offices of market-leading companiesacrossawiderangeofindustries,fromtelecoms, gaming, healthcare, fintech, to retail, and e-commerce. Such global leaders as Boeing, Aricent, Huawei, Siemens, Oracle, Magento, Apple, Microsoft, Deutsche Bank, Skype, eBay, IBM have RD offices in Ukraine. The USA has the largest share of RD partnerships in Ukraine. It equals about 45% of companies. Kyiv is the key location for setting up RD offices. Other cities that are a perfect fit for setting up an RD office include Lviv, Dnipro (Dnipropetrovsk), Odesa, Kharkiv, and Vinnytsia. In 2018, a few companies, including PwC, opened up new offices in Ukraine. Ukraine houses a wide range of top-notch product companies including Grammarly, Readdle, Jooble, Depositphotos, TemplateMonster, GitLab, and the startup community is growing by 500 new entrepreneurs each month. Also, Ukraine is home to High Castle, a blockchain-based investment marketplace and startup accelerator.
  • 21.
    As we cansee, despite some instability, Ukraine is showing strong signs of economic and political stabilization. Since 2014 the state has implemented a variety of reforms and improvements in different directions, from legislature to tourism. As a result, it has proven an alluring and reliable destination for investment, RD, software development outsourcing. Afterword