AntiMalware•August 5, 2026•🇷🇺Translated from Russian

Yandex Cloud Partners with Sogaz and Ingosstrakh to Automate Cyber Risk Assessment for Business Insurance

Yandex Cloud has partnered with major Russian insurers Sogaz and Ingosstrakh to launch new cyber insurance programs for businesses. Under the arrangement, the insurers provide financial protection while Yandex Cloud evaluates the client’s cloud infrastructure to determine appropriate policy conditions.

The assessment is performed using the Yandex Security Deck service. This tool automatically scans cloud resources, applications, and stored data for open internal information, excessive user access rights, data leak risks, and potential infrastructure compromise vectors. Findings are aggregated into a single interface and ranked by priority.

Clients receive the full report and may forward it directly to the insurer, which uses the data to calculate policy terms. When serious vulnerabilities are detected, Yandex Cloud offers specific remediation steps. The automated approach is intended to replace traditional paper questionnaires that often contain incomplete or outdated information.

According to Sogaz, the total volume of requested cyber-risk coverage more than doubled year-over-year during the first half of 2026, exceeding 12 billion rubles. The new model combines infrastructure diagnostics, technical protection measures, and financial compensation in the event of an incident.

Insurers gain a more accurate, real-time view of client risks, while businesses receive an opportunity to address cloud misconfigurations before they are exploited by attackers.

Related articles

Habr•Policy & Regulation

Fonts, CDNs, and Hosting: The Cross-Border Data Transfers No One Notices

A Russian developer building a contract-processing service discovered that his website was silently sending visitor data to foreign companies despite keeping all contract data on Russian servers. The site used Vercel for hosting, Google Fonts across 33 pages, and Cloudflare's cdnjs for PDF and Word libraries, exposing IP addresses, browsers, and browsing history. Under Russia's 152-FZ, such transfers require a separate notification to Roskomnadzor, and the United States and EU are not on the list of countries with adequate protection. The developer migrated fonts and libraries to his own Russian server, moved hosting domestically, and updated his privacy policy after a single console command revealed the external domains. The case highlights how common web practices like loading Google Fonts or using CDNs can trigger strict data localization and notification rules, with fines reaching millions of rubles for violations.

Habr•Policy & Regulation

How to Complete the Roskomnadzor Personal Data Notification Form in 2026: Field-by-Field Analysis

The article provides a detailed walkthrough of the current Roskomnadzor notification form for operators processing personal data under Russian law. It explains that the form is an extract from existing internal documents rather than a questionnaire, requiring operators to reference their data processing policy, inventory results, appointment orders, and protection level acts. Key prerequisites include confirming that notification is mandatory after the 2022 amendments removed most exemptions, preparing five core documents, and understanding that the form pulls data directly from those records. The guide covers every section, from operator identification and processing regions to data categories, protection measures, geography, and post-submission obligations. It also addresses common mistakes, the option to save drafts, auto-population features, and liability for non-compliance or inaccurate information. The piece concludes with a checklist mapping each form field to its source document.

Habr•Policy & Regulation

OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches

Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.

Habr•Policy & Regulation

RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent

RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.