Habr•October 9, 2026•🇷🇺Translated from Russian

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A portion of Moneta clients recently lost connectivity to company servers due to filtering on the TSPU segment of the network. Initial checks of firewalls and bidirectional traces ruled out internal causes, while client sites and Pay URL payment notifications also became unreachable.

Eugene, a DevOps engineer at Moneta, documented the full diagnostic path using curl, traceroute, nping, and a custom Python script for post-handshake tracing. Basic tests showed timeouts on TLS Client Hello packets, with responses stopping after operator routers and BRAS equipment.

When payload-specific filtering was suspected, hexadecimal TCP data was extracted from Wireshark and replayed via nping and netcat to reproduce retransmissions. A dedicated script allowed TTL-controlled probes after completing the TCP handshake to isolate the exact hop where drops occurred.

Verification from multiple Russian nodes via globalping helped exclude routing faults. Once TSPU involvement was confirmed, a request was filed through the VTS personal account using organization credentials from Gosuslugi, specifying source and destination ranges, ports, protocol, and traffic justification.

After the request received “Partially Accepted” status without restoration, escalation to DCOA via support_asbi@dcoa.ru or support_asbi@noc.gov.ru was required. Obtaining the four-digit TSPU site identifier (e.g., 4XXX) proved difficult until direct contact with SSOP at supervising@noc.gov.ru succeeded.

The final diagnostic package sent to DCOA included DNS results, ICMP and TCP traces, curl output, and confirmation of ongoing traffic from the source IP. The article stresses that active traffic must be present during DCOA analysis and that the process applies only to legitimate information resources of legal entities.

Related articles

Securitylab•Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

AntiMalware•Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.

Habr•Policy & Regulation

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.

Habr•Policy & Regulation

Digitizing Cyber Risks: How to Communicate Cyber Threats to Boards in the Language of Money

The article from Solar details a hybrid methodology for quantifying cyber risks by converting technical threats into financial metrics such as probability and expected losses. It explains that cyber risks represent a specialized form of operational risk characterized by rapid propagation, scalability across IT infrastructure, and heavy dependence on third-party vendors and cloud providers. The process involves four stages: asset and threat identification, incident and vulnerability analysis, translation into monetary values using formulas like ALE, and ongoing monitoring with updates. Qualitative expert assessments are combined with quantitative techniques including Monte Carlo simulations and statistical modeling when data is available. The resulting metrics support investment prioritization through ROSI calculations, integration of cyber risks into enterprise risk management frameworks, and clear communication with directors and investors using business language. Regulatory pressure and the direct impact of incidents on revenue, costs, and business continuity make this approach increasingly essential.