AntiMalwareAugust 24, 2026🇷🇺Translated from Russian

Russian State Operators Must Report Cyber Incidents to FSB Within 24 Hours From September 2026

Russian state information system operators will no longer be able to delay reporting cyber incidents to the FSB. From 1 September 2026, they must transmit details of any detected incident to the National Coordination Center for Computer Incidents (NKTsKI) no later than 24 hours after discovery.

The obligation is established by FSB Order 297. It covers operators of GIS, information systems belonging to state bodies, state unitary enterprises and state institutions. The document specifically highlights incidents that result in unauthorized transfer of information, commonly understood as data leaks.

Interaction with GosSOPKA will take place exclusively through NKTsKI after organizations connect to its technical infrastructure. Upon receiving a notification, the center will assign a unique identifier that serves as official confirmation the information has been properly submitted.

FSB Order 297 was developed to implement Law 568-FZ, adopted in December 2025. The measure converts prompt notification of the FSB from recommended practice into a mandatory, formalized procedure.

Related articles

AntiMalwarePolicy & Regulation

Microsoft Removes Reinstallation Requirement for Enabling Smart App Control in Windows 11

Microsoft has eliminated the primary restriction on Smart App Control, allowing home users to activate or reactivate the Windows 11 security feature without performing a clean installation of the operating system. Previously, toggling the setting effectively required users to reinstall the entire system. Smart App Control leverages Microsoft's cloud-based reputation system and analyzes digital signatures to block suspicious, potentially dangerous, or unsigned files before execution. The toggle is now accessible through Windows Security under App & browser control. The update is being rolled out gradually via Windows 11 updates, though users who have disabled optional diagnostic data may still need a reset or reinstallation. The feature can interfere with developers and enterprise users working with rare or unsigned tools, as there is no option to whitelist individual blocked applications.

HabrPolicy & Regulation

Trusting Russian Root Certificates and Monitoring Domestic CT Logs

The article examines risks associated with installing Russian root certificates issued by the Ministry of Digital Development. It explains how these certificates, when trusted, enable potential MitM attacks through TSPU infrastructure by allowing on-the-fly issuance of fraudulent certificates for foreign domains. Yandex Browser stands out by enforcing Certificate Transparency checks for domestic certificates, unlike other browsers that disable CT validation in the presence of added roots. Three primary domestic CT logs are maintained by Yandex, VK, and the Ministry, with log lists updated annually. A Python script is provided to query these logs directly and verify SCT inclusion for any certificate. The piece also notes limitations of existing web monitors such as ct.tlscc.ru when dealing with newer log endpoints.

HabrPolicy & Regulation

Why Legitimate Russian Websites Fail to Load With or Without VPN: TSPU RKN Blocking and MinTsifry Certificates Explained

Russian internet users are experiencing widespread access issues to legitimate domestic websites both when using VPNs and when connecting directly. The problems stem from TSPU devices installed by all ISPs under Roskomnadzor requirements and the transition to national MinTsifry certificates that foreign browsers do not trust. Three distinct error scenarios are documented: ERR_CONNECTION_TIMED_OUT when accessing Russian-IP sites over VPN, ERR_CERT_AUTHORITY_INVALID on major bank sites without VPN, and partial page loading failures caused by TSPU fingerprinting. Solutions for ordinary users include split-tunneling VPN clients, installing MinTsifry root certificates, or switching to Yandex Browser and Chromium-Gost. Website owners are advised to disable TLS 1.3, enable HTTP/2 support, and consider changing server IP addresses if SSH connections are also blocked. The article explicitly excludes any discussion of circumvention methods for prohibited content and focuses only on legal Russian resources as of August 2026.

HabrPolicy & Regulation

Smart Homes on Pause: Why Digital Systems in New Buildings Fail After Three Years

Modern residential complexes increasingly rely on digital infrastructure, yet many smart home systems stop functioning properly within three years of commissioning. The root causes lie in decisions made during the design phase rather than after handover. Marketing-driven features often lack any sustainable operational model, leading to disappearing services once the warranty period ends. A fragmented vendor landscape, missing documentation, and absent ownership further accelerate degradation. Cybersecurity risks grow when updates and monitoring are neglected, turning buildings into easy targets. The article outlines how to build resilient systems that remain functional for 10–20 years by focusing on total cost of ownership, open standards, and clear responsibility frameworks.