Habr•August 17, 2026ā€¢šŸ‡·šŸ‡ŗTranslated from Russian

Ozon Data Security Team Details Audit Framework to Eliminate Paper-Only Compliance

Ozon’s Data Security team has published a detailed account of its internal audit methodology designed to move beyond formal compliance reports and deliver measurable improvements in data protection.

Alena, who leads the group of 11 analysts, explains that the company handles large volumes of personal data and private data distributed across numerous microservices. These include customer names, addresses, payment details, order contents, and internal business information that must be protected under Federal Law 152-FZ and company requirements. Primary fines for violations range from 150–300 thousand rubles, with repeat offenses reaching 300–500 thousand rubles and potential penalties up to 3 percent of annual turnover or 500 million rubles for data leaks.

How the datasec audit is conducted

The process begins with system familiarization: analysts map microservices, APIs, data flows, and access points, often creating visual diagrams that can take weeks to complete for complex CRM systems. They then review role-based access models to detect excessive permissions. In one audit, broad rights to modify product tags were narrowed because incorrect tagging could lead to storage and display errors causing significant financial damage.

Next, the team examines both employee and service account access. One review covered more than 84,000 user-role combinations, resulting in recommendations to revoke unnecessary privileges that could be exploited if an account were compromised. Logging is another focus area; teams are required to enable human-readable audit logs that support incident investigation, real-time alerts, and playbooks for detecting mass data exports or suspicious UI activity.

Protected access and storage are verified through mandatory use of HTTPS and database encryption so that even direct database access does not expose readable information. Analysts also assess additional architecture elements depending on the specific system under review.

Prioritization model and guiding principles

To decide which systems to audit first, the team applies a scoring framework that evaluates four core parameters: Data (volume and sensitivity), Importance (business criticality), Number (employee count interacting with the system), and Money (potential financial loss from downtime or leakage). Optional factors include incident history, user type, and regulatory obligations such as critical information infrastructure requirements.

The group stresses that audits must produce real changes rather than remain on paper. A notable success involved removing recipient names, phone numbers, and addresses from Ozon delivery boxes. Although the practice was legally permissible, the team argued it created an unnecessary risk of bulk data collection; after implementation, delivery operations continued without disruption.

Key recommendations include setting clear priorities, examining security implications at the business-requirements stage, being willing to redesign long-standing processes, maintaining open dialogue with development and business teams, and assembling analysts who are personally invested in practical outcomes. The ultimate measure of success, according to Alena, is when the first recommendation from an audit report becomes an implemented change in production.

Related articles

Habr•Policy & Regulation

Bill Gates Calls for Stronger External Oversight and Regulation of AI

Bill Gates stated in an NBC News interview that self-regulation by AI developers is no longer sufficient and urged Congress to pass binding laws on artificial intelligence. He warned that AI tools in the hands of malicious actors could trigger catastrophic events capable of causing up to a billion deaths, emphasizing the unprecedented power of combining bad intentions with modern AI systems. Gates advocated for mandatory rules, audits, and monitoring, particularly in critical sectors such as medicine, finance, and government infrastructure, while acknowledging that some added bureaucracy would be necessary. Leaders from Anthropic and OpenAI have similarly suggested slowing AI development, with former Anthropic employee Jacob Coxon publicly accusing companies of playing roulette with lives by pursuing self-improving superintelligence. House Speaker Mike Johnson prefers to wait for industry proposals, whereas Mark Zuckerberg opposes coordinated oversight and believes individual labs should decide on pace. Several U.S. states including California, Maryland, and New York have already begun launching their own AI regulatory initiatives and expert panels.

Securitylab•Policy & Regulation

Implementing DevSecOps in Unprepared Teams: A Practical Three-Month Roadmap

Many development teams face resistance when security tools are introduced without proper process changes, leading to bypassed checks and unresolved findings. The article outlines a structured approach for small teams of five to eight developers without a dedicated security specialist, focusing on one service as a pilot. It emphasizes assigning clear roles including a Security Champion, selecting initial checks such as secret scanning with Gitleaks and dependency analysis, and converting scanner reports into actionable tasks with owners and deadlines. The plan covers the first eight weeks of setup, including baseline handling for legacy issues, automated blocking rules, and incident rehearsal exercises. Metrics recommended include time to first triage, age of open critical defects, and false positive rates, aligned with DORA indicators for release performance. The guidance draws on OWASP SAMM practices and stresses that security requirements must be integrated into daily workflows rather than added as extra gates.

Habr•Policy & Regulation

Why Technically Strong CISOs Lose to Weaker Peers: The Hidden Role of Internal Politics

A new analysis from independent expert Andrey Biryukov explains why technically proficient CISOs frequently fail to secure budgets and executive support while less technical peers succeed. The core issue lies not in technical knowledge but in the ability to translate security risks into business language that resonates with CFOs, CEOs, and boards. Biryukov details how influence, rather than formal authority, determines whether security initiatives gain traction or stall in endless approvals. He emphasizes building coalitions in advance, crafting compelling narratives, and preparing concrete business cases that quantify revenue impact and regulatory exposure. The article also highlights common pitfalls such as relying on fear-based arguments or ignoring stakeholder KPIs. Ultimately, the piece argues that selling security internally is essential for any CISO who wants both resources and long-term survival in the role.

AntiMalware•Policy & Regulation

Bybit Restricts Transfers to Sanctioned Entities Including Lazarus Group and CryptoPro

Cryptocurrency exchange Bybit has notified users that transfers to or from entities on its Restricted Counterparties list are prohibited, regardless of amount or whether conducted directly or through intermediaries. The list includes the North Korean state-sponsored Lazarus group and Russian cryptographic software developer CryptoPro due to their presence on sanctions lists from the United States, European Union, and United Kingdom. Bybit will automatically reject outgoing transfers to listed counterparties and may freeze incoming funds from them or related addresses, with potential account suspension or closure for users involved. The exchange emphasizes that blockchain transparency allows tracing of funds without user confessions and reserves the right to block transactions even with counterparties not yet explicitly listed. These measures are embedded in Bybit's terms of service to ensure compliance with international sanctions regimes.