HabrJuly 29, 2026🇷🇺Translated from Russian

Building Information Security Culture: How Welcome Training Turned Rules into Engaging Dialogue

A large software company has shared how it replaced dry policy documents with an interactive Welcome Training program to build genuine information security culture among its staff.

The organization already deploys advanced controls such as access restrictions, security policies, an SIEM system, and antivirus solutions. However, these tools proved ineffective when employees lacked basic understanding of why rules exist and what consequences follow from violations.

What did not work

Signing a policy document during onboarding proved insufficient, as staff rarely retained the content. Posting rules on the corporate portal also failed to drive compliance, since no verification mechanism existed.

The target audience consists of developers, analysts, testers, product managers, and designers. While these professionals often master complex product security technologies, many still store passwords in Google Sheets, showing that technical skill does not automatically translate into security culture.

Welcome Training structure

The company therefore introduced 45-minute in-person sessions limited to groups of 7–10 people. The format encourages questions and discussion. The curriculum includes:

  • Current threat landscape with examples of major Russian incidents
  • Step-by-step attack mechanics to illustrate individual impact
  • Assets under protection, including code, data channels, and personal information
  • Consequences of sharing credentials or personal data
  • Password requirements and use of corporate password managers
  • Proper use of corporate email
  • Storing sensitive data on encrypted volumes with VeraCrypt
  • Secure credential transfer using the pbin service
  • File checking via VirusTotal and antivirus tools
  • Recognition and response to social engineering
  • Signs of workstation compromise and reporting procedures
  • Overview of deployed corporate protections such as Kaspersky Endpoint Security, Kaspersky Secure Mail Gateway, and SIEM

Results include higher engagement, better retention, increased awareness of personal responsibility, and a measurable drop in human-factor incidents.

Related articles

AntiMalwarePolicy & Regulation

Russian Ministry Clarifies No Plans to Disable Apple iPhones Despite New Device Registry

The Russian Ministry of Digital Development has officially stated that no government body or telecom operator has the authority to remotely disable iPhones or other devices from specific manufacturers. The clarification was issued in response to an inquiry from deputy Vladimir Plyakin regarding rumors of potential restrictions if Apple fails to comply with Russian legislation. Current laws do not permit turning user devices into non-functional bricks through any centralized mechanism. However, amendments to the law On Communications will introduce a national registry of user equipment identifiers starting March 1, 2027. The ministry is still developing the regulatory framework for this database, including what data will be collected and which agencies will have access. Officials emphasized that the existence of the registry does not imply any capability for mass device deactivation at this stage.

AntiMalwarePolicy & Regulation

Russia's Top Investigator Proposes AI, VPN and Other Technologies as Aggravating Circumstances in Criminal Code

Alexander Bastrykin, head of Russia's Investigative Committee, has put forward a bill that would treat the use of artificial intelligence, VPN services and other information technologies as an aggravating factor when sentencing offenders. The proposal aims to address the growing role of digital tools in crimes ranging from fraud and data trafficking to terrorism, murder and sexual offences. Current Russian law lacks a universal provision allowing courts to factor in the deployment of such technologies during punishment decisions. Bastrykin argued that embedding specific technologies into dozens of Criminal Code articles would be inefficient because the IT landscape evolves too rapidly for static legal language. Instead, the committee advocates a systemic approach that recognises technology as a distinct aggravating circumstance when it serves as the primary instrument of the crime or significantly amplifies the harm caused. The measure would not criminalise the mere possession or activation of a VPN, smartphone or AI model; it would apply only when these tools materially enable or scale criminal activity. The bill has already been prepared by the Investigative Committee and was outlined in an interview with Interfax.

HabrPolicy & Regulation

Bank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants

The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.

AntiMalwarePolicy & Regulation

Aladdin Obtains New FSB Certificate for CryptoFlash Encrypted USB Drive Valid Until 2029

Aladdin has received a new FSB Russia certificate for its Aladdin CryptoFlash hardware-encrypted USB drive. The certificate number СФ/124-5574 confirms compliance with cryptographic protection requirements for classes KS1 and KS2 and remains valid until 16 July 2029. The device now supports additional Russian Linux distributions including RED OS 7.3 and 8, Alt 8 SP Workstation, Alt Workstation 10, and the OS of the Moscow Electronic School. Read and write speeds have been increased to 11 MB/s while the graphical interface received improvements. The product uses the Magma encryption algorithm in hardware and operates as a clientless solution that requires no additional drivers or software. The previous certificate remains active until December 2028, allowing both versions of the device to be used in parallel for storing and transferring official and confidential information marked DSP.