AntiMalwareSeptember 2, 2026🇷🇺Translated from Russian

Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls

Large Russian data centers may fall under the scope of presidential decree No. 604, which permits temporary state management of critical infrastructure facilities with insufficient protection. By default, Rosimushchestvo would assume the role of administrator.

The measure can be applied when an owner fails to fulfill security requirements, poses a threat to stable operations, inadequately protects the facility from drone attacks, or restores operations too slowly after an incident. The decree covers communications, energy, transport, industry, utilities, and other critical sectors.

Industry participants believe that major commercial and departmental data centers serving government bodies, banks, and federal operators clearly qualify. While Tier III and higher facilities usually maintain solid cyber defenses, the primary new expenses will involve physical security measures.

Operators must now protect generators, cooling systems, communication nodes, and other external engineering equipment against aerial threats. The challenge is especially acute in European Russia, where 80–90 percent of commercial data center capacity is concentrated in Moscow and St. Petersburg.

Protection against drones was not previously part of standard data center design. Some companies are already modernizing infrastructure. RTK-DC stated it continuously reviews security measures, while RUVDS confirmed work on safeguarding external equipment.

The market anticipates detailed sector-specific requirements tied to facility category and criticality. Experts highlight the need for redundant communication channels, DDoS protection, vulnerability management, and accelerated recovery processes. Additional protection will require significant capital expenditures that may ultimately be passed on to clients, particularly in government, financial, and telecommunications segments.

First Deputy Prime Minister Denis Manturov assured that no mass campaign or nationalization is planned; decisions will be made on a case-by-case basis at the highest level.

Related articles

安全客Policy & Regulation

China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents

A bus electronic display router in Wuhu, Anhui, was compromised in April 2026 because the device retained factory-default credentials and exposed multiple management ports. The Ministry of Public Security highlighted the case in its Hu Wang 2026 report, stressing that failing to change default passwords and leaving ports open constitutes a violation of the Cybersecurity Law regardless of whether serious harm occurred. The RCtea botnet actively targeted similar routers and cameras across China, infecting 9,827 devices in just six days in January 2026 through Telnet brute-force attacks. Experts from the Chinese Academy of Social Sciences clarified that penalties do not require actual damage and that operators must implement technical measures, retain logs for at least six months, and maintain internal security procedures. Additional cases in Qinghai and Nanchong demonstrated repeated enforcement actions against entities that ignored weak-password remediation orders. The report calls on operators, regulators, and manufacturers to enforce password changes at installation, close unnecessary ports, and apply network segmentation to prevent low-hanging IoT devices from becoming botnet recruits.

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.