AntiMalwareAugust 25, 2026🇷🇺Translated from Russian

Bitrix24 Releases Fully On-Premise BI Constructor for Regulated Enterprises

Bitrix24 has launched a new delivery model for its BI Constructor that enables full on-premise deployment without any external dependencies.

The platform for visual analytics can now be installed entirely within a customer's infrastructure. No external servers, cloud APIs, or internet connections are required, keeping all corporate data behind closed doors.

Previously, large enterprises faced difficulties because the BI Constructor was available either in the cloud or as a boxed version that still needed access to external infrastructure for updates and auxiliary services. For companies in regulated industries, such outbound channels often conflicted with internal security policies and regulatory requirements.

In the new variant, all data processing and storage occur exclusively on the customer's servers. Organizations independently manage access rights, backup procedures, updates, and integration with internal security tools.

The solution is fully compatible with the boxed version of Bitrix24 running on PostgreSQL and does not connect to external CDNs or cloud APIs.

1C-Bitrix expects the closed delivery model to appeal to large businesses and organizations that must process restricted-access data inside the corporate perimeter. The product has already been implemented and tested in pilot environments, with broader customer pilots scheduled in the coming months.

Related articles

HabrPolicy & Regulation

Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations

A year after stricter Russian personal data protection fines took effect, many entrepreneurs continue to commit violations that could trigger multimillion-ruble penalties from Roskomnadzor. The article details ten common breaches, including the prohibited use of Google Forms for data collection, missing cookie banners, absent or invalid consent forms under forms, and failure to obtain separate consents for publishing reviews. Additional violations cover missing privacy policies, outdated notifications to Roskomnadzor, improper transfer of employee data to third parties without written consent, lack of data processing agreements, and absence of records for paper-based data storage locations. Each violation is explained with direct references to the Law on Personal Data, the Code of Administrative Offenses, and specific government orders, along with exact fine ranges for citizens, individual entrepreneurs, and legal entities. Practical remediation steps are provided, such as replacing foreign services with Yandex Forms, drafting compliant consent texts per Article 9, and submitting updated notifications under Order No. 180. The guidance emphasizes conducting a full site audit and implementing all required documents to avoid penalties throughout 2026.

HabrPolicy & Regulation

Rethinking SSO: Centralized User Data Provision and Authorization Processing in Corporate Systems

The article examines Single Sign-On systems not merely as authentication gateways but as architectural hubs for delivering user attributes and executing additional authorization logic. It highlights how SSO can aggregate data from sources like Active Directory, HR systems, and IDM platforms, then deliver it via OIDC claims to downstream applications. The discussion covers the shift from fragmented integrations across dozens of apps to a single trusted enforcement point using standards such as aggregated and distributed claims. It also explores the authorization pipeline where SSO acts as a Policy Enforcement Point querying external Policy Decision Points via the AuthZEN Authorization API 1.0. Practical examples include electronic business cards, role assignment, access routing, and mandatory MFA checks before token issuance. The piece stresses maintaining data ownership with source systems while establishing SSO as the single point of trust for applications.

HabrPolicy & Regulation

Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025

Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.

AntiMalwarePolicy & Regulation

Russia Authorizes Temporary State Takeover of Unprotected Critical Infrastructure

President Vladimir Putin has signed a decree that empowers the Russian government to appoint temporary managers for critical infrastructure facilities whose owners have failed to ensure adequate security. The measure directly targets operators of objects classified as critical infrastructure who have not met protection requirements. Under the new rules, the state can intervene by installing an interim administrator to oversee operations until security standards are satisfied. This approach aims to prevent potential disruptions or threats arising from insufficiently defended assets. The decree provides a legal mechanism for rapid governmental response without permanent nationalization of the facilities. It reflects ongoing efforts to strengthen oversight of sectors deemed essential to national security and stability.