HabrSeptember 1, 2026🇷🇺Translated from Russian

FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators

Russian regulators have significantly widened the circle of organizations required to perform attestation of information systems starting 1 September 2026. The key document, FSTEC Order No. 60 of 27 February 2026, amends the earlier FSTEC Order No. 77 of 29 April 2021 and changes the very definition of entities covered by the attestation procedure.

The updated rules now explicitly apply to state and municipal information systems, including municipal personal data systems; industrial control systems at defense-industry organizations, including CNC machine tools; and protected premises used for confidential negotiations. The order also covers any information systems belonging to state bodies, state unitary enterprises or state institutions that are not formally classified as state systems, as well as critical information infrastructure objects, non-state personal data operators and industrial control systems at critically important or potentially hazardous facilities.

Two new articles introduce concrete control methods. Article 31¹ states that post-attestation monitoring must include vulnerability analysis and penetration testing. Article 16¹ makes penetration testing mandatory for state information systems and other systems of state bodies, unitary enterprises and institutions that have first or second protection class and are connected to the internet or interact with external systems, with the sole exception of encrypted VPN channels using certified cryptographic means.

Reporting deadlines have also changed. Article 32 now requires submission of control results to FSTEC at least once every three years and no later than five working days after completion of the control. Failure to meet the deadline can lead to suspension of the attestation certificate. Only organizations holding an FSTEC license that explicitly includes rights to conduct attestation tests and protection control against unauthorized access may perform the work.

A second document, FSB Order No. 297 of 6 August 2026, implements new incident-reporting obligations for every state institution under the amended Article 16 of Federal Law 149-FZ. Each school, hospital or other state-funded body must independently conclude an interaction regulation with NKTSKI, obtain a personal cabinet and transmit information about incidents within 24 hours. Three separate 24-hour clocks apply to incident reporting, confirmation of receipt and notification of preventive measures.

Finally, Government Decree No. 1024 allows the use of Russian-hosted cloud services for state systems provided the service meets or exceeds the required protection class, yet places full compliance responsibility on the heads of the user organizations. All three regulatory acts enter into force on 1 September 2026.

Related articles

HabrPolicy & Regulation

From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively

Anatoly Antipov, head of L1 analysts at a small in-house SOC, explains why traditional time-based metrics like MTTD and MTTR often lead to superficial incident handling and analyst burnout. Drawing on NIST SP 800-61 and the latest SANS SOC Survey, the article shows how speed-focused KPIs encourage analysts to game the system rather than improve security. The team replaced vague verdicts with a five-level matrix including TP.Ext, TP.Int, BP, FP, and FP.SOC to separate real incidents, benign activity, and internal detection debt. Weekly reports were restructured around three blocks covering overall volume, verdict distribution, and confirmed violations with actual effort metrics. Regular quality audits of closed alerts now check verdict accuracy, documentation completeness, and whether FP.SOC items trigger rule improvements. The approach helps small SOC teams focus on genuine risk reduction instead of dashboard optics.

Security NEXTPolicy & Regulation

NCA Annual Conference 2026 to Examine CSIRT Roles Amid AI and Supply Chain Shifts

The Japan CSIRT Council (NCA) will hold its NCA Annual Conference 2026 from December 2 to 4 in Tokyo, bringing together security practitioners from CSIRT teams and related fields. The event is open to both members and non-members and focuses on sharing knowledge across organizations and industries. Under the theme "Attacking, Defending, There Are People There," participants will discuss how generative AI evolution, economic security tensions, and increasingly complex supply chains are reshaping threats and the mission of CSIRT teams. The conference will take place on-site, with the first day hosted by Internet Initiative and the following two days at Akasaka Intercity Conference. Selected keynote sessions will be recorded and made available online afterward. Attendance is free but requires advance registration through the official event website.

AntiMalwarePolicy & Regulation

Personal Laptops, Corporate Secrets: 70% of Companies Err with BYOD Policies

Up to 90% of employees in Russian organizations use personal smartphones and laptops for work tasks, yet around 70% of companies implement Bring Your Own Device programs incorrectly. This creates serious risks of data leaks and other security incidents. Crosstech experts warn that businesses often fall into one of two extremes: either allowing unrestricted use of personal devices without any rules or turning employee devices into heavily monitored extensions of corporate security systems. Both approaches can backfire, with the first leading to lost or compromised devices and the second driving the creation of uncontrolled shadow IT through unofficial apps and cloud services. The recommended approach is to isolate corporate data using encrypted containers on mobile devices and dedicated remote desktops for home computers, without monitoring personal activities. Architect Egor Norkin emphasizes that companies should focus solely on how their data is handled rather than employee behavior outside work hours.

HabrPolicy & Regulation

Corporate Wi-Fi Passwords Stored in Plain Text on Every Connected Device

Many organizations continue to rely on a single shared password for corporate and guest Wi-Fi networks, creating long-term access risks after employees leave. On Windows systems, the netsh wlan show profile command reveals the password in clear text without requiring administrative rights. Linux distributions using NetworkManager store the PSK in readable files under /etc/NetworkManager/system-connections unless the keyring option is selected. macOS keeps passwords in the Keychain, which prompts for user confirmation before disclosure. The article explains why shared passwords cannot serve as effective access control and recommends WPA2/WPA3-Enterprise authentication or properly isolated guest networks instead. It also provides concrete commands for administrators to audit their own environments and highlights the consequences of infrequent password rotation.