AntiMalware•October 7, 2026•🇷🇺Translated from Russian

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has introduced Self-Assessment, a specialized portal that consolidates information security self-evaluations across entire corporate holdings and groups of companies.

Many organizations face fragmented compliance tracking, where one subsidiary may fully meet requirements while another leaves audit remarks unresolved in email threads for years, and a third stores reports in isolated spreadsheets. The new Security Vision SA platform brings all self-assessment data into a single environment, enabling centralized control over remediation efforts.

The solution covers the full lifecycle of security self-assessment. This includes preparation of requirements, distribution of questionnaires, collection of responses with validation, calculation of results according to chosen methodologies, and ongoing monitoring of corrective actions. Parent companies receive both high-level overviews and granular visibility into individual subsidiaries and systems.

Requirements can be imported, grouped into templates, assigned to specific domains, and maintained with full version history. Assessments may be launched on a schedule or triggered for specific tasks, with questions routed to responsible specialists. Responses and supporting justifications undergo validation before results are computed, including support for an organization’s own internal methodology.

When compliance can be verified through metrics, the system supports automatic population of answers after criteria are configured. Unfulfilled requirements are automatically converted into action plans that include responsible parties, deadlines, and status tracking. Management can monitor which companies are actively addressing issues and identify areas where work has stalled.

The platform also provides reports and interactive dashboards with drill-down capabilities to specific organizations or systems. In addition, it maintains a registry of internal normative documents, tracks their versions, and notifies employees when they need to review updates.

By establishing a unified methodology, Security Vision aims to reduce manual data consolidation and help organizations allocate security resources according to actual priorities. The first demonstration of Security Vision SA will take place on October 27-28 at the SOC Forum.

Related articles

Habr•Policy & Regulation

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.

Habr•Policy & Regulation

Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money

The article from Solar details a hybrid methodology for quantifying cyber risks by converting technical threats into financial metrics such as probability and expected losses. It explains that cyber risks represent a specialized form of operational risk characterized by rapid propagation, scalability across IT infrastructure, and heavy dependence on third-party vendors and cloud providers. The process involves four stages: asset and threat identification, incident and vulnerability analysis, translation into monetary values using formulas like ALE, and ongoing monitoring with updates. Qualitative expert assessments are combined with quantitative techniques including Monte Carlo simulations and statistical modeling when data is available. The resulting metrics support investment prioritization through ROSI calculations, integration of cyber risks into enterprise risk management frameworks, and clear communication with directors and investors using business language. Regulatory pressure and the direct impact of incidents on revenue, costs, and business continuity make this approach increasingly essential.

AntiMalware•Policy & Regulation

Russian Interior Ministry Accuses Telegram of Ignoring Drug Trafficking Requests

The Russian Ministry of Internal Affairs has publicly stated that Telegram completely ignores requests from law enforcement agencies aimed at combating illegal drug trafficking. According to the ministry, the messenger has become one of the main platforms, alongside darknet markets, for involving teenagers in narcotics-related crimes. Acting head of the Main Directorate for Drug Trafficking Control Kirill Smurov highlighted that Telegram administration does not respond to official inquiries and refuses to share necessary information. In contrast, Yandex promptly removes prohibited content either independently or upon the first police request. Since 2022, approximately 153,000 crimes have been committed using Telegram, while Roskomnadzor has issued more than 150,000 content removal demands that received no response. Founder Pavel Durov, who is included in the Rosfinmonitoring list of terrorists and extremists, has not engaged with Russian authorities on these matters.

AntiMalware•Policy & Regulation

UK Regulator Ofcom Investigates Meta Over Instagram Instants Compliance With Online Safety Act

Britain's communications regulator Ofcom has opened an investigation into Meta to determine whether the company properly assessed risks before launching the Instagram Instants feature. The probe focuses on compliance with the Online Safety Act, specifically the potential for illegal content distribution and harms to minors. Instants, introduced in May 2026, allows users to exchange images that disappear after viewing. Under UK rules, platforms must update risk assessments before rolling out significant changes. Ofcom will first gather evidence and, if violations are found, issue a preliminary decision allowing Meta to respond. Penalties for non-compliance can reach 18 million pounds or 10 percent of global turnover, whichever is higher. Meta maintains it conducted risk analysis and implemented safeguards such as forwarding restrictions and teen account protections before launch.