Russian Data Centers Above 500 kW May Receive Protection from Forced Relocation Under Gilotina 2.0 Roadmap
Land plots containing large data centers may receive special protection against compulsory seizure for state and municipal needs. The proposal has been included in the draft roadmap Gilotina 2.0 for the data center sector.
The ban is planned to come into force on 15 December 2027. Facilities with capacity of 500 kW and above that are entered in the Russian registry of data centers would fall under the protection, according to information obtained by Vedomosti.
The amendments are intended to prevent the demolition of an operating facility for the sake of comprehensive territory development. A data center cannot simply be disassembled in the evening and moved to a neighboring plot.
The Association of Data Center Industry Participants considers the 500 kW threshold unjustified, pointing out that no standardized method yet exists to separate IT load from total electrical capacity. The association also criticizes the linkage to the registry, noting that participation remains voluntary and therefore protection may not cover all facilities.
The Coordination Council of Data Centers supports the threshold, arguing that guarantees should primarily cover large and difficult-to-replace sites. Should land release still prove necessary, the initiator of new construction would be required to provide an equivalent plot or finance its creation.
Compensation would extend beyond walls and server racks. Reimbursement is proposed to include construction of a new data center, relocation of equipment and IT load, reservation of power capacities, laying of communication lines and power grids, as well as losses arising from early termination of client contracts.
The initiative has received support from RTK-COD, MTS, and Megafon, although the operators also oppose mandatory registry linkage. The issue is especially acute in Moscow, where local data centers operate at approximately 95 percent capacity and free power resources are nearly exhausted, forcing new sites to be built in the regions.
Related articles
R-Vision SIEM Debuts at Standoff 17 Cyber Battle and Processes 8.8 Million Correlation Events
R-Vision presented its SIEM solution for the first time at the Standoff 17 cyber exercise, where the akPots team used it to monitor a telecom operator infrastructure and investigate incidents. The product was deployed in two weeks, with 80 percent of required event sources already supported out of the box. During four days of continuous attacks the system triggered 46 correlation rules, generated more than 8.8 million correlation events and 40 thousand alerts, while analysts created 13 custom widgets and executed over 9,000 search queries. Resource consumption remained low, with the collector averaging 0.7 CPU and 1.9 GB RAM even under peak load. Participants rated the solution 4 or 5 out of 5 and highlighted raw-text search, the RQL query language and event grouping as the most useful features. The exercise also identified areas for interface and alert-description improvements.
From Security Champion to Engineering Security Culture: MTS Web Services Transforms DevSecOps Approach
MTS Web Services has shifted from a single Security Champion per team model to a broader engineering security culture that distributes responsibility across multiple specialists. The previous approach created overload for appointed champions, offered insufficient training, and failed to motivate appointed participants to grow their skills. The new strategy emphasizes voluntary participation, professional development through dedicated tracks, and integration of security practices into daily workflows and onboarding. Key changes include forming a DevSecOps guild, running regular workshops and Q&A sessions, embedding vulnerability scan results into team metrics, and adding competency maps with role-specific learning paths. The company now recognizes security heroes and high-performing teams while linking basic security training completion to performance indicators. Results show organic growth in engagement, with event numbers rising from a handful in 2023 to 18 in 2025 and product teams independently adopting secure development practices.
Security Vision SIEM Adds Monitoring for Missing Logs, Correlation Quality, and SOC SLA Compliance
Security Vision has released a major update to its SIEM platform that extends monitoring beyond external threats to the health of the data collection pipeline itself. The new release introduces continuous checks for source stability, allowing administrators to define acceptable event flow deviations and receive alerts when logs suddenly stop arriving. A dedicated dashboard now evaluates correlation rule performance through testing on simulated events and supports import/export in Sigma format for easier detection sharing across platforms. The StatAnalyser service applies statistical models to flag atypical behavior with special markers, while the incident card gains automated retrospective process-chain reconstruction that links parent processes, user sessions, and host movements. Additional oversight features track analyst SLA adherence and let managers drill from team-wide statistics into individual performance metrics. Overall, the platform aims to close the loop from data ingestion through detection, investigation, and response within a single managed workflow.
ManticoreSearch Publishes Detailed Checklist for Enabling Authentication in Production
ManticoreSearch has released an extensive checklist for safely enabling authentication in production deployments. The guide covers standalone nodes, distributed tables with remote agents, and replication clusters, stressing the need for thorough inventory of clients and nodes before changes. It details procedures for creating users with minimal privileges, testing in staging environments, and performing controlled rollouts during maintenance windows. Special attention is given to handling Bearer tokens, protecting auth.json files, and ensuring consistent authentication data across cluster nodes. The document also explains differences between RT-mode and plain-mode configurations and provides commands for initializing the first administrator and reloading authentication settings.