Habr•October 11, 2026•🇷🇺Translated from Russian

Building the Foundation of Digital Trust: Why Identity Security Remains Undervalued

Identity Security is one of the most underestimated foundations of cybersecurity. Behind the routine request to “give a person access” lies a company’s decision to trust an individual with its information and to allow work with specific documents and systems. This requires understanding what the person must do, which data they need, and when their permissions should end.

Significant investments in protection tools can still leave a dismissed employee with access to confidential documents while a new hire waits for access to a critical system. The topic clearly shows how deeply IT and information security functions intersect. The same directory services, sign-on mechanisms, and access management tools both enable applications and protect company information.

Price of Errors in Access Management

The 2026 Identity Conf presented research by Indid and the Identity Club. The survey covered 200 organizations with at least 100 employees that already use at least one Identity Security solution. 43.5% of respondents reported errors in manual rights assignment that temporarily gave outsiders access to confidential data. 33.5% noted access remaining for dismissed employees. These figures reflect the participants’ own organizations and cannot be extrapolated to the entire Russian market, yet they illustrate where problems arise: personnel changes do not always reach information-system settings.

The reverse side of the problem is equally costly. Before IdM implementation, account creation at Lamoda Tech could take three days. Warehouse staff need access on the morning of their first working day. Such delays affect core business processes and helped justify investment in Identity Security.

Designing Protection Together with Business Processes

In August 2026 NIST introduced the Human-Centered Cybersecurity concept. The authors recommend considering people’s needs, capabilities, and limitations when developing policies, processes, and technologies. For Identity Security this approach should cover the entire path from the decision on permissions to task execution. A manager asked to review an employee’s rights may see only obscure technical role names; the request format must therefore provide clear business explanations.

Economics of the Project Across the Full Lifecycle

Project evaluation must distinguish waiting time from labor costs. Three days until access is granted does not equal three days of continuous administrator work. The freed time of an employee does not automatically become an economic benefit; the actual change in their work must be measured. Separate evaluation of operational improvement and risk reduction is advised. Measurable indicators include task completion time and labor costs, while expected losses are assessed through scenarios and documented assumptions.

What to consider in the project:

  • Data to verify: implementation and maintenance costs, labor for surveys, integrations, support, rights reviews, and audit evidence preparation.
  • Load on business processes: access waiting time, task execution, login and recovery success rates, approval errors, support tickets, and manual exceptions.
  • Residual business risk: unacceptable action scenarios, potential damage, and actual ability to detect and terminate dangerous access.

From Human Trust to System Permissions

Determining who needs access begins with relationships between people. Employment or contractor agreements define the work, conditions, and responsibilities. These legally formalized relations must serve as the basis for granting information and system access. Architectural frameworks such as TOGAF help describe business functions, yet the model must accurately reflect each employee’s and external contractor’s real working tasks. Contract, position, and instructions alone do not explain which data require access; commercial secrets, medical confidentiality, attorney-client privilege, and personal data rules must be mapped to concrete actions and resources.

Keeping Permissions Aligned with Company Changes

After initial configuration, business tasks change, contracts end, and new applications appear. Identity Security is therefore a set of processes forming a managed lifecycle with feedback at three levels: rapid restriction of dangerous access, periodic review of actual permissions, and revision of system-wide rules. These processes align with NIST SP 800-53 Rev. 5 controls AC-2, AC-6(7), AU-6, and IR-4, as well as NIST SP 800-137 for continuous monitoring. Russian FSTEC Order No. 117 (points 48 and 49) and GOST R 59547-2021 provide additional reference points for commercial organizations.

Linking Business Permissions to Application Rights

Centralized access management requires that decisions on permissions are correctly executed in every application. Failed integration attempts have shown that attributes and detailed rights configured only inside an application cannot be managed through API. Pre-project surveys must therefore trace the path from agreed business actions to their execution in each specific application. IGA combines organizational governance with system administration, while IdM links HR data to accounts, assigns and revokes rights, and reconciles results against approved permissions. RBAC and ABAC models, described in GOST R 59383-2021, translate business roles into technical permissions. Integrations must be maintained as the landscape evolves; implementation in a mid-sized company typically takes 10–12 months according to Solar estimates.

Assembling a Trust Environment from Domestic Solutions

The Russian market already offers mature domestic products covering IdM, Credential Management, Access Management (including SSO and PAM), and governance functions. The FICAM reference model from GSA illustrates how identity management, electronic credentials, and access control integrate with overall governance and information resources. Organizations can adapt this model to their own infrastructure and regulatory requirements.

Related articles

AntiMalware•Policy & Regulation

VK Files Lawsuit in EU Court Seeking to Overturn Sanctions Imposed in July

Russian internet company VK has submitted a formal challenge to the European Union's sanctions regime by filing a case with the Court of Justice of the European Union. The company argues that the restrictions placed on VK and its subsidiary Communication Platform LLC are both unjustified and unlawful. The lawsuit, registered under case number T-664/26 on 7 October, directly contests the July sanctions that targeted the developer of the MAX messenger. Earlier restrictions had already led to the removal of multiple VK ecosystem applications from Apple App Store and Google Play, forcing users toward alternative distribution channels such as RuStore, Huawei AppGallery, Samsung Galaxy Store and Xiaomi GetApps. While installed Android applications continue to function and receive updates, iOS users face disrupted push notifications after the apps were delisted. The legal action itself does not automatically restore app availability in the affected stores.

Securitylab•Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

Habr•Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.

AntiMalware•Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.