FROM FORTRESS TO ECOSYSTEM: A NEW PARADIGM OF UNIVERSITY CYBERSECURITY (THE POINT OF VIEW OF ODESSA POLYTECHNIC)
DOI:
https://doi.org/10.31673/2409-7292.2026.036112Abstract
The article substantiates the need to transition from the classical perimeter model of information security
("fortress") to the concept of a university cybersecurity ecosystem. The university is considered as an open socio-technical
ecosystem, the evolutionary goal of which is a spiral cycle of knowledge generation and transfer. Real cyber threats that
purposefully destroy the phases of this cycle are systematized. A four-level architecture of the cybersecurity ecosystem is
proposed: organizational-normative (with a clear demarcation of responsibility), process-oriented (dynamic security
profiles based on Context-Aware Zero Trust), technical-analytical (complex of intelligent monitoring with AI-driven
SIEM) and anthropogenic-educational (formation of "distributed immunity"). It is proved that the central subject of
ecosystem formation and audit should be the specialized department of cybersecurity. The conceptual model is described
through resource justification on the example of the infrastructure of Odessa Polytechnic, which showed its high practical
feasibility and economic feasibility. A system of quantitative indicators and a pilot operation plan for empirical verification
of the architecture have been developed. It is substantiated that further implementation of this model has the potential to
transform cyber security from an item of expenditure and formal compliance to a driver of scientific leadership, export of
analytics and equal international integration.
Keywords: cybersecurity ecosystem, spiral knowledge cycle, cyber resilience, intelligent monitoring, dynamic
security profiles, system of quantitative indicators, Odesa Polytechnic.
References
1. Tansley A. G. The use and abuse of vegetational concepts and terms. Ecology.1935. Vol. 16, No. 3. P. 284-307.
2. Ostrom E. A general framework for analyzing sustainability of social-ecological systems. Science. 2009. Vol.
325, No. 5939. P. 419-422.
3. Etzkowitz H., Leydesdorff L. The dynamics of innovation: from National Systems and "Mode 2" to a Triple
Helix of university-industry-government relations. Research Policy. 2000. Vol. 29, No. 2. P. 109-123.
4. Nonaka I., Takeuchi H. The Knowledge-Creating Company: How Japanese Companies Create the Dynamics of
Innovation. New York: Oxford University Press, 1995. 284 p.
5. McElroy M. W. The New Knowledge Management: Complexity, Learning, and Sustainable Innovation.
Butterworth-Heinemann, 2003. 320 p.
6. Linkov I., Eisenbies J. R., Disch C., et al. Cyber-resilience: a framework for managing cyber risks. Journal of
Cyber Security and Information Systems. 2018. Vol. 1, No. 1. Pp. 1-12.
7. Bodeau D. K., Graubart R., & Rosoff A. Cyber Resilience for Systems and Organizations. MITRE Corporation,
2017.
8. Alberts C. J., McQuaid D. Cybersecurity Engineering: Managing Risk and Resilience. SEI, 2010.
9. Rajkumar R., Lee I., Sha L., Stankovic J. Cyber-physical systems: the next computing revolution. Proceedings
of the 47th Design Automation Conference. 2010. Pp. 731-739.
10. Linkov I., Bates M. E., Trump B. D., et al. Cyber-resilience and digital immunity in complex systems.
Environment Systems and Decisions. 2020. Vol. 40. Pp. 1-10.
11. Про внесення змін до деяких законів України щодо захисту інформації та кіберзахисту державних
інформаційних ресурсів, об'єктів критичної інформаційної інфраструктури : Закон України від 27.03.2025
№ 4336-IX. Відомості Верховної Ради України. 2025. № 35, ст. 134.
12. Деякі питання захисту інформаційних, електронних комунікаційних, інформаційно-комунікаційних,
технологічних систем : Постанова Кабінету Міністрів України від 18.06.2025 № 712. Офіційний вісник України.
2025. № 57, ст. 3921.
13. Про затвердження Порядку проведення інструктажів та систематичних тренінгів щодо кібергігієни :
Постанова Кабінету Міністрів України від 08.10.2025 № 1281. Офіційний вісник України. 2025. № 87, ст. 6055.
14. Про утворення Міжвідомчої робочої групи з питань залучення міжнародної допомоги для забезпечення
кібербезпеки та кіберстійкості держави : Постанова Кабінету Міністрів України від 08.03.2024 № 276. Офіційний
вісник України. 2024. № 28, ст. 1803.
15. NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE). Cognitive Warfare: The Battle for the
Brain. NATO CCDCOE Publications, 2021.
16. National Institute of Standards and Technology (NIST). Security and Privacy Controls for Information Systems
and Organizations (NIST SP 800-53 Rev. 5). Gaithersburg, MD: NIST, 2020.
17. Перелік подій аудиту, що підлягають реєстрації (Додаток А до Політики AU, на основі НД ТЗІ 3.6-006-
24 та NIST SP 800-53r5). Внутрішній регламент організації. 2024.