The domestic information security industry is undergoing a structural transformation. After several years of rapid growth driven by the transition to local technologies, the market has slowed down, regulatory requirements have become stricter, and the first major fines under the new data leak rules have already been issued. In these conditions, only companies that can scale, comply with the rules, and compete for scarce talent are able to remain strong.
Market: From Rapid Growth to Consolidation
According to Kontur.Focus and Kontur.Egida analysts, in 2025 the number of information security companies in the domestic market grew by only 3%, reaching 12.1 thousand. This is exactly half the growth rate of the previous year, when the figure stood at 6%. At the same time, the number of liquidated legal entities and individual entrepreneurs increased by 15.9%. Experts attribute this to market saturation and higher customer requirements.
“The space for a quick entry of new players has closed,” comments Daniil Borislavsky from Kontur.Egida. “Competition has shifted from simply entering the market to being able to stay in it. Smaller companies struggle with rising operating costs and the need to meet strict industry standards set by technical, security, and financial regulators.” The market is moving toward consolidation: major players are either acquiring entire teams or taking over smaller competitors.
Regulators Are Raising the Bar
Against this background, regulators continue to tighten the rules of the game. The technical regulator has published new recommendations for protecting the network perimeter, including stricter requirements for device administration, network segmentation, DDoS protection, and mandatory backup of configurations. The document was developed based on the analysis of real attacks involving remote exploitation of vulnerabilities.
At the same time, enforcement practice under the updated legislation is gaining momentum. A Moscow commercial court issued one of the first fines under the new rules, ordering the online school Ukids to pay RUB 400,000 after a data leak affecting 500,000 clients. The leaked data included full names, phone numbers, and email addresses. The incident occurred due to the compromise of an account in the Bitrix24 CRM system, presumably because two-factor authentication was not enabled. Although the applicable article provides for a fine starting from RUB 10 million, the court reduced it to RUB 400,000 because the company is classified as a microenterprise. Nevertheless, this is the first precedent under the tightened rules and a clear signal for the entire market.
Talent Is Becoming the Main Resource
The paradox of the current situation is that while the growth in the number of companies is slowing down, demand for information security specialists is not declining, and requirements for them are increasing. In 2025, almost 9,000 people enrolled in publicly funded places in the Information Security field, making it one of the top 10 IT specializations.
However, as a survey of CISOs and information security vendors conducted by SecPost showed, universities are not keeping pace with the market. The list of leading educational institutions included ITMO, MIPT, MEPhI, Bauman Moscow State Technical University, HSE, as well as regional universities such as Voronezh State University, Ural Federal University, and Tomsk State University. Still, graduates often lack practical skills. AppSec engineers need stronger experience in code vulnerability analysis, while SOC specialists need better knowledge of data query languages, Linux, Python, and, most importantly, proactive threat hunting.
“Universities do not have sufficient budgets for modern laboratory environments, and there is a severe shortage of instructors with practical industry experience,” Gazprombank notes. “Bureaucracy and outdated teaching methods are the main areas for improvement.” Positive Technologies suggests defining the profile of an in-demand entry-level specialist at the industry level and scaling best practices across universities.
The domestic cybersecurity market is entering a new reality: the number of companies is stabilizing, the strongest players are surviving, regulatory pressure is increasing through fines and new requirements, and the key shortage is no longer security tools themselves, but qualified specialists capable of operating them and resisting real threats.
Market: From Rapid Growth to Consolidation
According to Kontur.Focus and Kontur.Egida analysts, in 2025 the number of information security companies in the domestic market grew by only 3%, reaching 12.1 thousand. This is exactly half the growth rate of the previous year, when the figure stood at 6%. At the same time, the number of liquidated legal entities and individual entrepreneurs increased by 15.9%. Experts attribute this to market saturation and higher customer requirements.
“The space for a quick entry of new players has closed,” comments Daniil Borislavsky from Kontur.Egida. “Competition has shifted from simply entering the market to being able to stay in it. Smaller companies struggle with rising operating costs and the need to meet strict industry standards set by technical, security, and financial regulators.” The market is moving toward consolidation: major players are either acquiring entire teams or taking over smaller competitors.
Regulators Are Raising the Bar
Against this background, regulators continue to tighten the rules of the game. The technical regulator has published new recommendations for protecting the network perimeter, including stricter requirements for device administration, network segmentation, DDoS protection, and mandatory backup of configurations. The document was developed based on the analysis of real attacks involving remote exploitation of vulnerabilities.
At the same time, enforcement practice under the updated legislation is gaining momentum. A Moscow commercial court issued one of the first fines under the new rules, ordering the online school Ukids to pay RUB 400,000 after a data leak affecting 500,000 clients. The leaked data included full names, phone numbers, and email addresses. The incident occurred due to the compromise of an account in the Bitrix24 CRM system, presumably because two-factor authentication was not enabled. Although the applicable article provides for a fine starting from RUB 10 million, the court reduced it to RUB 400,000 because the company is classified as a microenterprise. Nevertheless, this is the first precedent under the tightened rules and a clear signal for the entire market.
Talent Is Becoming the Main Resource
The paradox of the current situation is that while the growth in the number of companies is slowing down, demand for information security specialists is not declining, and requirements for them are increasing. In 2025, almost 9,000 people enrolled in publicly funded places in the Information Security field, making it one of the top 10 IT specializations.
However, as a survey of CISOs and information security vendors conducted by SecPost showed, universities are not keeping pace with the market. The list of leading educational institutions included ITMO, MIPT, MEPhI, Bauman Moscow State Technical University, HSE, as well as regional universities such as Voronezh State University, Ural Federal University, and Tomsk State University. Still, graduates often lack practical skills. AppSec engineers need stronger experience in code vulnerability analysis, while SOC specialists need better knowledge of data query languages, Linux, Python, and, most importantly, proactive threat hunting.
“Universities do not have sufficient budgets for modern laboratory environments, and there is a severe shortage of instructors with practical industry experience,” Gazprombank notes. “Bureaucracy and outdated teaching methods are the main areas for improvement.” Positive Technologies suggests defining the profile of an in-demand entry-level specialist at the industry level and scaling best practices across universities.
The domestic cybersecurity market is entering a new reality: the number of companies is stabilizing, the strongest players are surviving, regulatory pressure is increasing through fines and new requirements, and the key shortage is no longer security tools themselves, but qualified specialists capable of operating them and resisting real threats.
