Skip to content

13 Legal Risks That Stop a Ukrainian Defense Company

One unnoticed legal risk costs more than it looks — a blocked export, a frozen payment, a leaked technology, personal exposure for the director. Here are the 13 risk categories for defense and dual-use manufacturers, prioritized STOP · SCALE · SUPPORT: the five that stop a business first, the triggers behind each, and a risk-check for your company. Also the map a foreign investor runs in due diligence.

12 min read

Produced in partnership with Juscutum.

Petro Bilyk, Partner, AI & Technology practice.

On this page

One unnoticed legal risk costs more than it looks — a blocked export, a frozen payment, a leaked technology, or personal exposure for the director. In a defense business, legal security works not after an incident but before the contract, the technology transfer, the production run and the shipment. Below is a map of 13 risk categories, ordered by what can stop the business first.

The risk map at a glance
What it isA map of 13 legal-risk categories for defense and dual-use manufacturers
PrioritizationSTOP (5, critical) → SCALE (5, high) → SUPPORT (3, medium)
Three consequence zonesStoppage · Liability · Loss of control
When it appliesBefore the contract, the technology transfer, the production run and shipment
Who uses itFounders (internal audit) and investors (due diligence)
SourceJuscutum’s defense-tech legal risk map
The frame

Why legal risk stops a defense business

In an ordinary business, a legal mistake costs money. In a defense business, it stops the business itself. So legal security has to work as part of the production system — not as a reaction after an incident, but as a condition before the contract, the technology transfer, the production run and the shipment. The risk map splits the consequences into three zones.

01

Stoppage

An export, a payment, a permit or the production cycle is blocked.

02

Liability

Personal exposure for the director and the owners of critical functions.

03

Loss of control

A technology leak, disputes over IP or data, reputational damage.

Dual-use goods
Products with both civilian and military applications. They’re controlled under dedicated regimes (the EU’s Regulation 2021/821, the Wassenaar Arrangement, and for US-origin content the EAR), and a Ukrainian company’s international transfers run through the State Service of Export Control (SSECU). That’s why product identification comes before any contract.
Prioritization

Which risks to fix first: STOP → SCALE → SUPPORT

Not all risks are equal. You protect what can stop the business now first, and only then what slows scaling or dents reputation. The map splits the 13 categories into three tiers — and you start on the left.

STOP · critical
Export control
Sanctions compliance
Criminal-law risk
Restricted access
Cybersecurity

From Juscutum’s risk map · the STOP → SCALE → SUPPORT prioritization

Critical · STOP

The 5 risks that stop product, payment or team

These are the top five categories. Each has a specific trigger — the moment the risk fires and turns into a stoppage.

STOP: risk → trigger
1. Export controlUncontrolled transfer of goods, code, data or access
2. Sanctions complianceA counterparty or the chain routes the deal into a prohibited zone
3. Criminal-law riskAn official’s decision lacks a proper procedure and evidence
4. Restricted accessSpecs, architecture, vulnerabilities or usage data are disclosed
5. CybersecurityThe network, cloud, channels or accounts are compromised

Behind each trigger sits a concrete action before the deal. Export control requires product identification (military or dual-use), an SSECU permit and an end-use certificate; even transferring technical data or access to a foreign person (a deemed export) can fall under control. Sanctions compliancemeans screening beneficial owners (UBOs) and the whole chain of participants, not just the direct buyer. Criminal risk is removed not by seniority but by a documented procedure: a decision needs a basis and a record. Restricted access and cybersecurity close the same thing from two sides — who can see the specs and architecture, and who can reach the network, cloud and accounts.

The full list

All 13 categories, mapped

Here are all thirteen, by tier. Each category is a set of typical triggers; the key ones are listed.

🔴 Critical — STOP

  • Regulatory & export-control. Product classification, international transfer of software and hardware, re-export without a permit, an unverified end-user.
  • Sanctions & compliance. Contact with sanctioned persons, circumvention through intermediaries, blocked payments (AML), loss of international partnerships.
  • Criminal-law. Unlawful transfer of dual-use items, corruption in certification, disclosure of restricted information, personal liability of the director or CTO.
  • Restricted-information regime. Disclosure of technical specs, unprotected communication channels, no information classification, sensitive PR material.
  • Cybersecurity & data protection. Unauthorized network access, attacks on cloud infrastructure, analytics leaks, no incident-response plan.

🟠 High — SCALE

  • Intellectual property. Unassigned rights to code and algorithms, disputes with contractors, open-source without a licence audit, a partner copying the technology.
  • International-scaling contracts. Unclear liability split, no end-use / no re-export, excessive performance guarantees, disputes over data ownership.
  • Defense procurement & the state. Price and margin disputes, spec-compliance claims, post-contract audit risk, dependence on a single customer.
  • People & management. Loss of critical engineers, missing NDAs and IP assignment, leaks via departed staff, founder disputes over product rights.
  • Supply chain. Dependence on a narrow set of suppliers, components from sanctioned jurisdictions, shortages of critical parts, counterfeit risk.

🟡 Medium — SUPPORT

  • Finance, tax, banking. Blocked payments (AML/sanctions), wrong customs classification, transfer-pricing risk, FX limits and international settlement.
  • Technical regulation, certification, quality. No conformity assessment, non-compliance with jurisdiction standards, missing test protocols.
  • Reputational & political. Accusations of entanglement in conflicts, information attacks, discredit through a technical incident, misuse by the end-user.
Self-check

Run the risk-check on your company

A practical way to check yourself in two minutes. For each of the 13 categories, mark whether you hold both a procedure and documentary proof. Empty critical (STOP) categories are what stops the business first.

Interactive risk check
How many of the 13 categories do you cover?
0/13
covered
Critical · STOP
High · SCALE
Medium · SUPPORT
Mark the categories where you already hold both a procedure and documentary proof.

Critical gaps stop a business. Let's close them before a buyer, an investor or an audit finds them.

Close the risks
Readiness

5 readiness questions before you scale

Legal security is the ability to move fast without losing control. A company is ready to scale if it can answer five questions with confidence.

  1. 1What exactly do we produce and transfer?
  2. 2To whom, where and for what end-use?
  3. 3Who has access and who approved the decision?
  4. 4What contractual boundaries apply after transfer?
  5. 5What documents prove proper control?

Start with an internal audit: run the 13 categories and mark which ones you already have a procedure and a document for, and which you don’t. That is your priority map: close the open STOP categories first, then SCALE, then SUPPORT.

Then comes what every careful counterparty checks. The same perimeter that protects you from a stoppage is the one an investor runs in due diligence and a buyer runs before a contract. A company with the 13 categories closed clears both without surprises — and that is what opens access to both capital and foreign contracts.

Legal risk in defense rarely arrives on its own — it arrives at the moment of the contract, the payment or the transfer, when it’s too late to stop. The companies that win close the perimeter in advance, in STOP → SCALE → SUPPORT order. That is the layer Wiseboard Defense builds for Ukrainian defense-tech companies: from product identification to a clean structure the buyer and the investor will later see.

FAQ

Frequent questions

Sources & disclaimer

Produced in partnership with Juscutum. Petro Bilyk, Partner, AI & Technology practice. This article is informational and not legal advice. Regimes and lists (sanctions, critical goods, Defence City criteria) change — verify against the primary sources from SSECU, the Ministry of Defence and the NSDC, and get individual advice before acting.

Published: 23 July 2026

Share
TagsLegal riskComplianceExport controlSanctionsDue diligenceDefence CityDual-use
Next step

Close the legal perimeter before the deal and the round

Wiseboard builds everything the buyer and the investor check: export-readiness and permits, sanctions and corporate compliance, clean IP on the company, information protection and a data room — in STOP → SCALE → SUPPORT order.

Wiseboard × Juscutum — ecosystem partners: legal support, export-readiness and capital

Your privacy

We use cookies to measure how the site is used so we can improve it. Analytics and marketing stay off until you allow them. Cookie policy