Why Defending a Company Costs Millions While Attacks Can Succeed for Just Hundreds of Dollars
In the 26th episode of Belyaev Podcast, two experienced CISOs examined a question every security leader eventually faces: how to explain to business stakeholders exactly what they are paying for when investing in information security.
Vyacheslav Kasimov, CISO of Tochka Bank, and Boris Evdokimov, Director of Information Security at the ASNA pharmacy network, highlighted a fundamental imbalance. Attackers can often launch campaigns using relatively inexpensive cloud computing, automation tools, and anonymization services, while organizations must spend millions on layered defenses, continuous monitoring, and incident response capabilities.
The discussion emphasized that security value cannot be measured by the number of security products purchased or the lack of public breach announcements. Instead, it should be evaluated through the lens of critical business processes, potential impact, probability of realization, and the organization’s ability to continue operations after an incident.
Kasimov noted that the absence of known leaks can be misleading. Undetected compromises, unconnected signals, or data already sold on closed channels may exist without the company’s awareness. Evdokimov added that organizations need systematic monitoring of public and underground sources to detect early signs of exposure.
Both experts stressed that mature security programs require clear answers to several practical questions: which assets are most critical, who has access to them, what indicators of compromise can be detected, and how the company will respond in the first hours after confirmation of an incident.
The conversation also addressed the common perception of security as a business obstacle. When security teams only block initiatives without offering safe implementation paths, they risk being bypassed. The recommended approach is to present risk scenarios, compensating controls, their costs, and the remaining residual risk so business leaders can make informed decisions.
Regarding emerging technologies, the speakers discussed the responsible integration of artificial intelligence into security operations. Automation can accelerate initial triage and response, yet models must be tested, access rights limited, actions logged, and irreversible decisions kept under human control. Any AI system granted infrastructure access becomes part of the attack surface and requires ongoing validation.
In closing, the participants agreed that the most damaging consequence of a security incident is often the long-term loss of customer trust, which can result not only from the breach itself but also from inadequate communication or lack of a clear recovery plan.
Related articles
Beeline Offers One Month Free Access to Six Services for Prepaid Customers
Beeline has launched a promotional campaign allowing home users on prepaid plans to try up to six digital services for free over 30 days. The offer, tied to the operator's second annual Cellular Independence Day, runs from October 2 to October 9 and includes services such as Virtual Assistant PRO, unlimited mobile data, internet sharing without speed reduction, custom network name display, 250 GB of cloud storage, and access to over 650,000 e-books and audiobooks. Each selected service activates its own free period starting from the moment of connection and deactivates automatically afterward. Customers already paying for four or more of the listed services will receive 300 bonus rubles for communication instead. The unlimited data option is unavailable in the Chukotka Autonomous Okrug and Norilsk. Activation is handled exclusively through the Beeline mobile app, and users with existing paid subscriptions to any service cannot activate the free trial version of the same service.
Enterprise-Grade Web Protection on a Budget: How Cloud WAF Lowers Barriers for SMBs
A new overview from Reg.cloud explains how cloud-based Web Application Firewalls reduce the cost and complexity of protecting websites, APIs, and web applications for small and medium-sized Russian businesses. According to Positive Technologies data cited in the article, 75% of successful web application attacks in 2025 disrupted organizational operations, while 82% of SMBs faced cyber incidents in the past year. The piece details the differences between traditional on-premises WAF deployments and cloud offerings, emphasizing ready-made protection profiles for CMS platforms, SaaS services, and digital agencies. It outlines a three-stage operational model covering preparation, DNS-based traffic redirection, and ongoing policy tuning that can be handled by existing DevOps or development teams without dedicated security staff. The service currently offers a free tier supporting up to three applications at 50 requests per second, along with seven preconfigured security profiles and dual audit/blocking modes. The article concludes by stressing that WAF remains only one layer and must be combined with patching, access controls, and separate DDoS or anti-bot solutions.
Yandex B2B Tech Integrates Hybrid Full-Text and Vector Search in Single YDB Query
Yandex B2B Tech has added hybrid search to its YDB database, allowing full-text and vector approaches to run together inside one SQL query. The update helps small and medium businesses as well as large corporations locate exact document identifiers while also matching semantic meaning in descriptions, even when wording differs. Full-text search handles precise elements such as policy numbers, codes, and names, whereas vector search identifies conceptual similarity. Results from both methods are merged and ranked within the same transaction, keeping all data inside a single database instance. This removes the need to maintain a separate search engine and vector store or to reconcile information between them. The technology is aimed at chatbots, recommendation systems, and AI assistants that process technical content where both exact codes and human-readable problem descriptions matter equally. Hybrid search is now available in the on-premises YDB 26.3 release and in the cloud-based Managed Service for YDB.
Google Developing Voice-Activated Emergency SOS Feature for Android Devices
Google is working on a voice-activated Emergency SOS function for Android that would allow users to summon help without touching their smartphone. The feature, discovered in the Personal Safety app code by Android Authority, appears to trigger after the user says the word 'Help' three times in sequence. Once activated, the system would automatically determine location, begin emergency video recording, and place a call to emergency services. The current method requires pressing the power button five times, which can be impractical in certain situations. Additional code strings suggest optional voice confirmation with phrases such as 'Say yes to continue' and 'Say cancel to dismiss Emergency SOS'. The function is not yet available to users and may eventually reach non-Pixel devices running the Personal Safety app, though supported languages and models remain undisclosed.