HabrSeptember 18, 2026🇷🇺Translated from Russian

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank has described how it migrated regulated on-premises workloads into Yandex Cloud while maintaining its existing Zero Trust posture alongside a new Cloud Trust model of shared responsibility.

The bank began with a classic perimeter-based architecture that enforced strict network segmentation and default-deny policies. When teams requested access to external cloud resources, traditional controls proved insufficient because Yandex Cloud exposes public APIs protected primarily by RBAC, policies, and ACLs rather than network firewalls.

Network Access

Engineers established a dedicated interconnect consisting of dark fiber between the bank and the cloud provider, encrypted with GOST algorithms. All management, integration, and data-plane traffic traverses this link. On-premises network objects were replicated in the cloud: each system maps to a cloud, each environment to a folder, and each folder contains isolated networks protected by Security Groups. IP address pools are announced across the interconnect so cloud subnets appear as additional data-center segments within the bank’s existing IP-address management system.

User Access

Authentication remains anchored in on-premises Active Directory and KeyCloak instances that are federated with Yandex Cloud IAM. Authorization is delegated to cloud-native service roles that map directly to Active Directory groups, preserving least-privilege principles while allowing teams to continue using familiar approval workflows.

Configuration Control

Every cloud project must produce architecture documentation that is reviewed before resources are provisioned through an internal platform integrated with the cloud API. The bank maintains an allow-list of approved managed services and enforces configuration standards through custom Cloud Security Posture Management checks written in code. Where internal expertise is limited, the team supplements its scanner with Yandex Security Deck modules.

SOC and Logging

Because the bank cannot collect every log type directly, it uses the provider’s YCDR service for detection and response while retaining full control over on-premises logs. This hybrid monitoring approach covers both control-plane and data-plane events generated inside Yandex Cloud.

The resulting environment currently runs 1,500 virtual machines, 100 managed services, and supports 1,000 identities. Alfa-Bank concludes that security in hybrid infrastructure requires deliberate decisions about where to retain control and where to accept Cloud Trust delegation, rather than attempting to enforce either model exclusively.

Related articles

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.

HabrPolicy & Regulation

Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law

A detailed analysis examines the legal consequences of uploading contracts containing personal data into foreign AI services such as ChatGPT under Russian Federal Law 152-FZ. The article clarifies that even standard supply agreements include names, positions, passport details, INN numbers, phones and emails that qualify as personal data. It breaks down applicable administrative penalties from Article 13.11 of the Code of Administrative Offenses, including 150-300 thousand rubles for processing without a proper legal basis and separate fines for failing to notify Roskomnadzor. Cross-border transfer rules under Article 12 require a dedicated notification to the regulator before sending data to services hosted in the United States or European Union. The piece also reviews recent court practice, including a Moscow district court ruling that treated uploading commercial information to DeepSeek as disclosure of trade secrets. No criminal liability under Article 272.1 of the Criminal Code applies to ordinary business use, yet the absence of a data processing agreement with OpenAI or similar providers creates ongoing compliance exposure.

AntiMalwarePolicy & Regulation

Ideco NGFW Novum Earns Highest Customer Rating in Quadrant Technologies Import Substitution Study

Ideco NGFW Novum achieved the top customer score of 6.9 out of 10 in the Matrix of Import Substitution 2026: NGFW research conducted by Quadrant Technologies, surpassing the market average of 6.3 and outperforming seven competing Russian solutions. The study evaluated vendors based on specialized revenue alongside 18 criteria covering product quality and functionality, with ratings provided directly by specialists who deploy and operate the firewalls in production environments. Ideco excelled in 11 parameters above seven points, including administration convenience at 7.9, technical support and partner network at 7.6, Zero Trust segmentation at 7.3, and both integration capabilities and core NGFW functionality at 7.2. Despite strong product scores, Ideco remains in the Development quadrant rather than Leadership due to lower profile revenue volume, positioning the company as a prime candidate for advancement with increased sales and large-scale deployments. Complementary testing by Infosystems Jet laboratory showed Ideco NGFW Novum passing 189 of 242 checks under Methodology 3.0 and becoming the sole participant to complete an eight-hour stress test. The broader Russian NGFW market is shifting away from emergency import substitution toward demands for real-world stability, updates, documentation, support, and usability, with product cost cited as a rejection factor by 37.5 percent of respondents.