Against the backdrop of growing business investment in digital transformation, which may exceed RUB 6.1 trillion in 2025, institutional efforts to build a comprehensive cybersecurity system are intensifying. In recent months, several key initiatives have been launched, from a centralized anti-fraud platform to long-awaited penetration testing methodologies. Together, these steps point to a new, more mature stage in the regulation of the digital environment.
A Unified Front Against Cyber Fraud
One of the most significant operational decisions was the clarification of timelines for creating a centralized platform to combat cyber fraud. According to the digital development authority, a system for interaction between regulators, banks, and telecom operators is expected to be launched on a unified technology platform by March 1, 2026. This step implements recently adopted legislation and is aimed at automatically exchanging signals about suspicious events, identifying phishing websites, and quickly restricting access to fraudulent resources.
Technology Transition Strategy: Grants in Exchange for Scalability
In parallel with anti-fraud measures, support for the domestic IT industry is being adjusted, with priority given to projects that can deliver the strongest economic impact. As part of the third wave of selection for major IT projects, RUB 8.3 billion has been allocated in grants. Priority is now given to solutions with the highest potential for scaling, the presence of artificial intelligence modules, and the ability to be used in mission-critical information infrastructure.
The new rules require grant recipients to confirm the return of funds through taxes and contributions equal to 100% of the grant amount. This approach is intended to ensure not only the development of new solutions, but also the creation of products that are truly in demand by the market and ultimately strengthen local technological independence.
The Technical Regulator Sets Security Standards
A major event for the professional community was the approval of the “Methodology for Testing Information Security Systems Using Penetration Testing Methods.” The long-awaited document is mandatory for penetration testing of high-class protected information systems with internet access.
This measure is intended to systematize and unify the process of assessing the security of critical assets. However, market data shows that identifying vulnerabilities is only half the task. Statistics indicate that companies fix only 56% of discovered issues on time, while in sectors such as healthcare and education this figure drops below 30%.
Time for Proactive Action
The set of initiatives clearly signals that the era of uncontrolled digital transformation is coming to an end. Businesses, especially those working with mission-critical infrastructure or actively participating in the digital economy, need to stay ahead of regulatory requirements.
Only a proactive and systematic approach to cybersecurity will allow companies not only to comply with tightening requirements, but also to reliably protect their growing digital assets in the face of hybrid threats.
A Unified Front Against Cyber Fraud
One of the most significant operational decisions was the clarification of timelines for creating a centralized platform to combat cyber fraud. According to the digital development authority, a system for interaction between regulators, banks, and telecom operators is expected to be launched on a unified technology platform by March 1, 2026. This step implements recently adopted legislation and is aimed at automatically exchanging signals about suspicious events, identifying phishing websites, and quickly restricting access to fraudulent resources.
Technology Transition Strategy: Grants in Exchange for Scalability
In parallel with anti-fraud measures, support for the domestic IT industry is being adjusted, with priority given to projects that can deliver the strongest economic impact. As part of the third wave of selection for major IT projects, RUB 8.3 billion has been allocated in grants. Priority is now given to solutions with the highest potential for scaling, the presence of artificial intelligence modules, and the ability to be used in mission-critical information infrastructure.
The new rules require grant recipients to confirm the return of funds through taxes and contributions equal to 100% of the grant amount. This approach is intended to ensure not only the development of new solutions, but also the creation of products that are truly in demand by the market and ultimately strengthen local technological independence.
The Technical Regulator Sets Security Standards
A major event for the professional community was the approval of the “Methodology for Testing Information Security Systems Using Penetration Testing Methods.” The long-awaited document is mandatory for penetration testing of high-class protected information systems with internet access.
This measure is intended to systematize and unify the process of assessing the security of critical assets. However, market data shows that identifying vulnerabilities is only half the task. Statistics indicate that companies fix only 56% of discovered issues on time, while in sectors such as healthcare and education this figure drops below 30%.
Time for Proactive Action
The set of initiatives clearly signals that the era of uncontrolled digital transformation is coming to an end. Businesses, especially those working with mission-critical infrastructure or actively participating in the digital economy, need to stay ahead of regulatory requirements.
Only a proactive and systematic approach to cybersecurity will allow companies not only to comply with tightening requirements, but also to reliably protect their growing digital assets in the face of hybrid threats.
