SecuritylabAugust 12, 2026🇷🇺Translated from Russian

Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications

Mixing work and personal email may seem harmless when a large attachment needs to be sent quickly, but the practice creates lasting security and compliance problems. Corporate mailboxes are managed by the organization, which controls domains, applies filters, maintains backups, and can revoke access upon employee departure. Personal accounts, by contrast, remain fully under individual control even after termination, leaving contracts, client correspondence, and internal documents outside any company oversight.

152-FZ and the Labor Code impose obligations to protect personal data during processing, while 98-FZ governs trade secrets. When work files leave the corporate environment, additional uncontrolled copies appear in mobile caches, tablet downloads, and synchronized cloud storage. Recovering or auditing these copies becomes nearly impossible, complicating incident investigations and regulatory compliance.

Using a corporate address for online purchases, subscriptions, and password recovery also expands the attack surface. The work mailbox receives marketing lists, phishing attempts, and breach notifications, while personal services become dependent on an account the employer can disable at any time. After dismissal, employees lose access to tickets, receipts, and recovery codes tied to the corporate domain.

Security experts recommend clear separation of roles. All client communications, contracts, reports, and internal notifications should stay within the corporate system. Personal registrations, banking alerts, and private correspondence belong exclusively to the individual mailbox. Both accounts must use unique strong passwords and multi-factor authentication to prevent credential reuse from turning a minor leak into a major incident.

If mixing has already occurred, organizations advise locating work messages and attachments in personal accounts, disabling forwarding rules, returning files to approved repositories through official procedures, and notifying security teams when confidential data may be involved. Automatic forwarding between accounts is particularly dangerous because it creates an uncontrolled, persistent channel for sensitive information.

Related articles

HabrPolicy & Regulation

FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators

Russia's FSTEC Order No. 60, effective 1 September 2026, rewrites the list of entities subject to information system attestation under the updated Order No. 77. The changes reach far beyond state information systems to cover municipal information systems, industrial control systems at defense enterprises, protected premises for confidential talks, and any commercial personal data operators that voluntarily included attestation in their policies. New clauses introduce mandatory vulnerability analysis and penetration testing as explicit control methods, tighten reporting deadlines to five working days, and require FSTEC-licensed organizations with specific rights for testing. Parallel FSB Order No. 297 obliges every state institution, including schools and hospitals, to report incidents to NKTSKI within 24 hours via a personal cabinet established only after a formal interaction regulation is signed. Government Decree No. 1024 permits cloud services for state systems but keeps full compliance responsibility with the user organization. The combined rules take effect on 1 September 2026, with one provision delayed until March 2027.

HabrPolicy & Regulation

From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively

Anatoly Antipov, head of L1 analysts at a small in-house SOC, explains why traditional time-based metrics like MTTD and MTTR often lead to superficial incident handling and analyst burnout. Drawing on NIST SP 800-61 and the latest SANS SOC Survey, the article shows how speed-focused KPIs encourage analysts to game the system rather than improve security. The team replaced vague verdicts with a five-level matrix including TP.Ext, TP.Int, BP, FP, and FP.SOC to separate real incidents, benign activity, and internal detection debt. Weekly reports were restructured around three blocks covering overall volume, verdict distribution, and confirmed violations with actual effort metrics. Regular quality audits of closed alerts now check verdict accuracy, documentation completeness, and whether FP.SOC items trigger rule improvements. The approach helps small SOC teams focus on genuine risk reduction instead of dashboard optics.

Security NEXTPolicy & Regulation

NCA Annual Conference 2026 to Examine CSIRT Roles Amid AI and Supply Chain Shifts

The Japan CSIRT Council (NCA) will hold its NCA Annual Conference 2026 from December 2 to 4 in Tokyo, bringing together security practitioners from CSIRT teams and related fields. The event is open to both members and non-members and focuses on sharing knowledge across organizations and industries. Under the theme "Attacking, Defending, There Are People There," participants will discuss how generative AI evolution, economic security tensions, and increasingly complex supply chains are reshaping threats and the mission of CSIRT teams. The conference will take place on-site, with the first day hosted by Internet Initiative and the following two days at Akasaka Intercity Conference. Selected keynote sessions will be recorded and made available online afterward. Attendance is free but requires advance registration through the official event website.

AntiMalwarePolicy & Regulation

Personal Laptops, Corporate Secrets: 70% of Companies Err with BYOD Policies

Up to 90% of employees in Russian organizations use personal smartphones and laptops for work tasks, yet around 70% of companies implement Bring Your Own Device programs incorrectly. This creates serious risks of data leaks and other security incidents. Crosstech experts warn that businesses often fall into one of two extremes: either allowing unrestricted use of personal devices without any rules or turning employee devices into heavily monitored extensions of corporate security systems. Both approaches can backfire, with the first leading to lost or compromised devices and the second driving the creation of uncontrolled shadow IT through unofficial apps and cloud services. The recommended approach is to isolate corporate data using encrypted containers on mobile devices and dedicated remote desktops for home computers, without monitoring personal activities. Architect Egor Norkin emphasizes that companies should focus solely on how their data is handled rather than employee behavior outside work hours.