FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators
Russian regulators have significantly widened the circle of organizations required to perform attestation of information systems starting 1 September 2026. The key document, FSTEC Order No. 60 of 27 February 2026, amends the earlier FSTEC Order No. 77 of 29 April 2021 and changes the very definition of entities covered by the attestation procedure.
The updated rules now explicitly apply to state and municipal information systems, including municipal personal data systems; industrial control systems at defense-industry organizations, including CNC machine tools; and protected premises used for confidential negotiations. The order also covers any information systems belonging to state bodies, state unitary enterprises or state institutions that are not formally classified as state systems, as well as critical information infrastructure objects, non-state personal data operators and industrial control systems at critically important or potentially hazardous facilities.
Two new articles introduce concrete control methods. Article 31¹ states that post-attestation monitoring must include vulnerability analysis and penetration testing. Article 16¹ makes penetration testing mandatory for state information systems and other systems of state bodies, unitary enterprises and institutions that have first or second protection class and are connected to the internet or interact with external systems, with the sole exception of encrypted VPN channels using certified cryptographic means.
Reporting deadlines have also changed. Article 32 now requires submission of control results to FSTEC at least once every three years and no later than five working days after completion of the control. Failure to meet the deadline can lead to suspension of the attestation certificate. Only organizations holding an FSTEC license that explicitly includes rights to conduct attestation tests and protection control against unauthorized access may perform the work.
A second document, FSB Order No. 297 of 6 August 2026, implements new incident-reporting obligations for every state institution under the amended Article 16 of Federal Law 149-FZ. Each school, hospital or other state-funded body must independently conclude an interaction regulation with NKTSKI, obtain a personal cabinet and transmit information about incidents within 24 hours. Three separate 24-hour clocks apply to incident reporting, confirmation of receipt and notification of preventive measures.
Finally, Government Decree No. 1024 allows the use of Russian-hosted cloud services for state systems provided the service meets or exceeds the required protection class, yet places full compliance responsibility on the heads of the user organizations. All three regulatory acts enter into force on 1 September 2026.
Related articles
How Russian Companies Can Legally Transfer Personal Data to Contractors Under 152-FZ
The article explains the legal distinction between data processors and independent operators when outsourcing tasks involving personal data. It details that the role of a contractor is determined by who sets the processing purpose, not by the service contract itself. For processors, a detailed data processing instruction under Article 6 of 152-FZ is required, while independent operators need a separate legal basis such as consent or contract performance. Special rules apply to employee data under Article 88 of the Labor Code, mandating written employee consent for transfers to third parties. The guidance also covers sub-processing risks, transparency obligations, and penalties under Article 13.11 of the Code of Administrative Offenses. Practical checklists help organizations classify contractors and prepare the correct documentation.
Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls
Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.
iMazing 3.6.3 Restores Sideloading of Removed iOS Apps via macOS After Apple Authentication Changes
Developers of iMazing have released version 3.6.3 that restores the ability for users to download and install applications previously removed from the App Store onto iPhone devices. The update currently functions only through macOS, with Windows support still pending further development. The changes address authentication and download errors that appeared in macOS 26 and earlier versions following modifications by Apple to its CommerceKit system. Apple began returning HTTP 403 Forbidden responses to tools including iMazing, ipa_downloader, and 3uTools by deactivating legacy tokens and revoking certificates used for app authentication. The restrictions have particularly affected Russian users who relied on these tools to reinstall banking and other applications removed due to sanctions. Support for macOS 27 Golden Gate and Windows remains unavailable and requires additional engineering work.
From MTTD and MTTR to Real Value: How to Organize SOC Metrics Effectively
Anatoly Antipov, head of L1 analysts at a small in-house SOC, explains why traditional time-based metrics like MTTD and MTTR often lead to superficial incident handling and analyst burnout. Drawing on NIST SP 800-61 and the latest SANS SOC Survey, the article shows how speed-focused KPIs encourage analysts to game the system rather than improve security. The team replaced vague verdicts with a five-level matrix including TP.Ext, TP.Int, BP, FP, and FP.SOC to separate real incidents, benign activity, and internal detection debt. Weekly reports were restructured around three blocks covering overall volume, verdict distribution, and confirmed violations with actual effort metrics. Regular quality audits of closed alerts now check verdict accuracy, documentation completeness, and whether FP.SOC items trigger rule improvements. The approach helps small SOC teams focus on genuine risk reduction instead of dashboard optics.