Business protection
Cybersecurity and risk management
Resources on infrastructure protection, vulnerability management, FSTEC requirements, email security and cyber risk reduction.
This hub combines practical guidance on protecting enterprise infrastructure, managing vulnerabilities and meeting data protection requirements.
News coverage includes the potential business impact and concrete next steps for technology and management teams.
Topic materials
Cybersecurity

SMS OTP delivery: TTL, retries and fraud controls
How to design one-time-code delivery over SMS: expiry, attempt limits, idempotency, resend rules, delivery reports and fallback channels.

Botsman EE 3.4 adds IPv6 and Kubernetes operations updates
Botsman EE 3.4 adds IPv6, external-authentication testing, Longhorn 1.8.2 and security fixes. We outline a practical enterprise pilot.

Selectel releases the SelectOS 2.0 server operating system
SelectOS 2.0 uses Debian 13 and Linux 6.12.86, signed repositories and a separate security-update channel. We outline a practical adoption plan.

Seligdar strengthens industrial security with Positive Technologies products
Seligdar has deployed MaxPatrol VM and PT Sandbox for vulnerability management and corporate email protection. We examine the practical implications.

Microsoft introduces Project Perception for agentic cyber defence
Microsoft has announced Project Perception, where AI agents continuously discover, assess and remediate cyber risks under human supervision.

Cloud.ru open-sources a data filter for AI models
Cloud.ru has published Guardrails Filter, a service that masks personal data, passwords and API keys before a request reaches an AI model.

Kaspersky NGFW 1.2 adds virtual contexts and resilient routing
Kaspersky has released a major NGFW 1.2 update. We examine virtual contexts, routing, resilience and the checks required in an enterprise pilot.

Selectel reports a fourfold increase in peak DDoS volume
Selectel reports growth in DDoS count, duration and power. We examine the methodology and practical resilience measures for digital services.

Zero Trust architecture: resource access without trusting the network
A practical Zero Trust guide covering resource inventory, identities, access policy, device posture, telemetry and a staged migration plan.

China issues seven standards for AI agent interoperability
China has issued seven national standards for AI agents. We examine architecture, identity, discovery, tool calling and the implications for B2B integrations.

Kaspersky updates its corporate email security platform
Kaspersky has updated email protection with AI-written message analysis, password-protected document scanning and employee risk profiles.

Kaspersky launches vulnerability management platform in Russia
Kaspersky VM centralises vulnerability discovery and prioritisation. We examine its confirmed functions, limits and the process required around it.

Cyberattacks on Russian industry increased by 31%
Kaspersky reported a 31% rise in security incidents affecting Russian industry. We examine the operational risks and practical defensive controls.

Enterprise RAG search: architecture, access control and answer quality
How to design RAG search over corporate data with document preparation, ACLs, indexing, citations, quality evaluation, audit logs and safe operation.

Enterprise video analytics: designing storage, networks and access
How to design enterprise video analytics across cameras, edge processing, network capacity, archives, access control, resilience and monitoring.

New FSTEC requirements for government information systems took effect in 2026
FSTEC Order No. 117 updated security requirements for Russian government information systems. Here is what system owners and contractors should review.

Shared responsibility in IaaS: provider and customer controls
How provider and customer responsibilities divide across infrastructure, operating systems, access, data, backups, monitoring, incidents and contracts.

Secure AI agent architecture: tools, permissions and action control
How to deploy AI agents safely by separating decisions from execution, narrowing tools, protecting retrieval and memory, and adding approval and audit.

IaaS or your own data center: what to choose
A full comparison of renting cloud infrastructure versus building your own data center: costs, launch speed, scaling, security and FSTEC requirements.

Disaster recovery planning: how to build and test a workable plan
How to create an executable disaster recovery plan with business impact analysis, dependencies, RPO/RTO, roles, runbooks and regular exercises.

FSTEC and data protection: what business needs to know
What an FSTEC licence confirms, how it relates to personal-data protection and what to verify with an infrastructure contractor.

Backup and fault tolerance of infrastructure
How to protect a business from downtime and data loss with backups, fault tolerance, RPO, RTO, SLA and recovery testing.