From a cybersecurity perspective, we cannot guarantee that every system component or security control will always hold. So mission-critical systems should be designed to limit blast radius, detect compromise, and contain it when something fails.
“There is no single “secure architecture”.
There is an architecture resilient to a defined threat model.”
– Anastasiia Voitova, Head of Security Engineering at Cossack Labs, at Fwdays Tech Summit 2026.
In this talk, Anastasiia used a real cyber incident to show how transitive trust can turn one compromised component into access across multiple systems. Then she walked through how to design secure data exchange step by step: from VPN, IP allowlisting and mTLS to service-to-service authentication, scoped access, and object-level authorisation. The focus was practical – what to implement, what to verify, and which questions to ask when designing data exchange between critical systems.
Anastasiia explained how security architecture changes when you assume from the start that individual security controls will eventually fail.
This is the approach Cossack Labs uses to build security architectures for mission-critical systems that must remain operational in high-risk environments across the sectors where failure isn’t an option: defence, critical national infrastructure, finance, healthcare, and the public sector.