Habr•August 6, 2026•🇷🇺Translated from Russian

InfoWatch Details ARMA Wall NGFW Development for Industrial Systems Under Russian Import Substitution Rules

InfoWatch has released the second installment of its technical interview series covering the development of ARMA Wall, the company’s next-generation firewall designed specifically for industrial automation and critical infrastructure networks.

The discussion addresses the use of artificial intelligence, migration challenges from foreign vendors, reliance on Russian hardware, certification processes, and the rationale for choosing NGFW technology over data diodes in OT environments.

Engineers confirmed that all data processing occurs on-premise. No cloud services or third-party agents are used because customer security policies and certification requirements explicitly prohibit such approaches. Internal AI agents are also avoided; only limited research-oriented services assist with vulnerability discovery and configuration analysis, with final decisions always made by human engineers.

The product incorporates both proprietary detection models and a curated mix of external threat feeds. Signatures are continuously optimized for performance while legacy rules remain active, including those protecting against exploits targeting Siemens controllers discovered in the 2000s.

Migration from foreign NGFW solutions is supported through detailed pre-project surveys that capture existing security policies. Automatic migration tools are planned but not yet implemented; manual configuration by experienced engineers is currently preferred to preserve context-specific filtering rules.

Regarding import substitution, InfoWatch noted that border firewalls have largely moved to domestic platforms in line with regulator requirements. However, full replacement inside ICS remains gradual because the typical lifecycle of industrial control systems is approximately 15 years. The company is deepening integration with Russian SCADA and controller vendors to enable native NGFW deployment within these long-lived environments.

Certified builds maintain fixed checksums, yet the regulator permits rapid updates for critical vulnerabilities without invalidating the certificate. This capability proved essential as the threat landscape evolved dramatically between the 2021 certification of the earlier Industrial Firewall product and 2026.

Detection feeds are delivered both online and offline for air-gapped networks. Administrators can also import indicators of compromise directly from NKCKI regulator letters; the system parses these indicators and automatically incorporates them into IDPS rules.

All development is performed by an internal team. Every component undergoes static and dynamic analysis before security specialists approve release. The company is implementing secure software development lifecycle processes and is preparing for relevant certification. Even embedded modules from other Russian vendors are tested to ensure they cannot become single points of compromise.

Testing of Russian processors such as Baikal has been completed, although production deployments still rely on imported platforms. Hardware is supplied through Kraftway, a state corporation subsidiary, with an average lead time of 60 days.

The product originated from industrial security requirements identified between 2017 and 2019. Its first commercial release, Industrial Firewall, targeted scenarios where foreign solutions from Hirschmann, Moxa, and Cisco were tightly coupled to specific verticals. ARMA Wall aims to provide unified protection across petrochemical, energy, and mining sectors while emphasizing security of critical information infrastructure over maximum throughput.

Deep packet inspection covers both legacy and modern industrial protocols, enabling command-level filtering at boundaries between corporate and OT networks as well as inside SCADA and PLC segments. In 2022 the solution blocked an attempt to deactivate licenses on Siemens controllers at a major Russian industrial site, preventing a full production stoppage.

Compared with data diodes, ARMA Wall offers lower total cost of ownership while providing equivalent one-way traffic enforcement plus bidirectional command inspection when needed. Virtual contexts are planned but not yet available; current segmentation requires multiple appliances. A KVM virtual machine image exists, and support for domestic hypervisors is in progress.

Pricing is influenced by hardware costs and the degree of import substitution. Reference deployments include the certified installation at RKK Energia (Roscosmos). The product integrates with third-party sandboxes and antivirus solutions using open protocols rather than attempting to create a closed ecosystem.

Pilot programs typically last one month, with equipment provided for up to three months. The recommended process includes two weeks of passive traffic analysis, two weeks of testing on an isolated segment, and two weeks of scaled rollout across the infrastructure.

Related articles

AntiMalware•Policy & Regulation

Russia Plans Additional Security Checks for Gosuslugi Portal Access

Prime Minister Mikhail Mishustin has directed the Ministry of Digital Development to develop extra authentication measures for the Gosuslugi portal used by 120 million citizens. The new controls would apply both to initial logins and to account recovery procedures. Details on the exact checks and implementation timeline remain unspecified as the ministry must first propose a concrete mechanism. In parallel, officials are preparing a third package of anti-fraud measures that includes a unified consent platform inside Gosuslugi for managing personal data processing permissions. The platform would let users view which organizations access their data, revoke prior consents, and report violations. Russian police have separately warned that fraudsters are already exploiting the topic of account protection by sending messages that threaten blocking or data leaks and urge victims to call provided numbers.

Securitylab•Policy & Regulation

Entering Cybersecurity Without a Specialized Degree: Sector Rules and Practical Entry Points

The article examines whether a specialized higher education diploma is necessary to start a career in information security. It breaks down three main industry segments—state security structures, regulated government organizations, and private business—and explains the differing formal and practical requirements in each. In government-related roles, candidates must meet strict regulatory standards for education and approved programs. Private companies instead focus on demonstrable technical skills in networks, Windows Server, Linux, and security tools. The piece also covers typical junior engineer expectations, real-world career paths from unrelated backgrounds, and four key ways to prove competence without a diploma. It concludes with advice on building home labs, troubleshooting skills, and accessing open training resources like the CyberED course.

AntiMalware•Policy & Regulation

MTS, MegaFon and Beeline Must Temporarily Suspend Radio Equipment at FSO Request Under Extended Frequency Licenses

Russian telecom operators MTS, MegaFon and VimpelCom (Beeline) have received extensions for their radio frequency allocations until 31 December 2027, but the licenses now include a binding requirement to pause operations of radio-electronic equipment upon demand from the Federal Security Service (FSO). The State Commission for Radio Frequencies (GKRCH) added this condition during its 31 August meeting, directly linking compliance with FSO instructions to the continued use of spectrum originally allocated in 2006. The measure applies during security operations, high-priority state activities and special FSO events, potentially causing temporary loss of mobile connectivity for subscribers in affected areas. Although FSO powers to request such suspensions have existed since 2011, the new decision embeds the obligation explicitly into the frequency license terms. At the same time, the operators retain earlier commitments to expand network coverage to all settlements with at least 2,000 residents by 31 March 2027. The dual requirements illustrate how spectrum policy now balances nationwide connectivity goals with operational readiness for temporary shutdowns ordered by security authorities.

AntiMalware•Policy & Regulation

Russia Discusses Extra Fees for International Traffic Over 50 GB in 5G Networks

The Russian Ministry of Digital Development is again in talks with mobile operators about introducing charges for international data traffic exceeding 50 GB per month, but only within 5G networks. The measure would potentially apply to VPN services and other foreign resources, adding to users' mobile bills. No final decision has been reached and the exact fee amount remains unspecified. Sources indicate a possible launch in October, though timelines are subject to change. Technical challenges arise because current 5G deployments rely on LTE infrastructure, requiring new traffic separation, network handover tracking, and billing system adjustments. Average monthly mobile data usage stood at 24 GB in 2025, making the 50 GB international 5G threshold a narrow scenario. Headlines claiming VPNs will become paid services overstate the current discussions, which focus solely on international traffic classification.