Skip to content
RUEN

Nikolay Lobanov

Information security and critical information infrastructure protection

Nikolay Lobanov

Independent expert in information security and critical information infrastructure (CII) protection.

My focus is the regulatory gap: the backbone infrastructure of the financial sector, meaning clouds, DNS and hosting, remains outside the regulatory perimeter for significant CII objects. I file comments on draft acts by FSTEC, the Ministry of Digital Development, the FSB, the Ministry of Transport, the Ministry of Finance and the Bank of Russia, and engage with the State Duma Committee on Information Policy and the Federation Council. Master's student at RANEPA, programme in Public Administration and National Security.

Areas of work

CII regulation

Comments and proposals on draft acts published for public consultation: from the anti-fraud package and its secondary regulation to CII security metrics, requirements for artificial intelligence in state systems and the status of fintech infrastructure, meaning digital assets and crypto exchanges, outside the perimeter of Federal Law 187-FZ.

Parliamentary track

Engagement with the State Duma Committee on Information Policy, the Federation Council, ROCIT and banking associations.

Municipality 2.0

Head of the IT track of a municipal governance digitalisation project: built and launched a team performance bot for the district.

Research

Master's thesis at RANEPA: protecting the national payment system infrastructure from cyberattacks.

Results

March 2026 to September 2026. Every item is backed by a document or a consultation page.

September 2026
6 of 7 accepted

Six proposals included in the revised text of a draft government decree

On the draft amendments to Government Decree No. 861 of 24.10.2011 (ID 01/01/08-26/00170295, the unified identification system and the state services portal) the developer included six proposals out of seven: handling of downtime of the unified system with that period excluded from deadlines, a hard deadline for erasure or anonymisation of received data, publication of the connection manual with deferred application of format changes, limits on third-party access, minimum privileges for the operator in the role model, and a six-month transition period for accession agreements.

Developer letter of 04.09.2026 with the revised text and the summary of proposals. The act is not yet adopted, this concerns the draft text.

July 2026
Partly accepted

Proposals on 210-FZ secondary regulation accepted by the Digital Ministry

On the draft rules for telecom operator reimbursement (ID 00169315) the ministry accepted suspension of deadlines while the state information system for countering offences committed with the use of information and communication technologies is unavailable, the forwarding deadline, and an increase of the reconciliation interval from 4 to 6 hours. On the phone number criteria (ID 00169312) the status is "partly accepted": the number clearing mechanism on the state services portal was confirmed.

Developer comments on the consultation pages, recorded 30.07.2026.

March, June 2026
Reviewed by the committee

Proposals on the anti-fraud package taken up by the State Duma Committee on Information Policy

Expert proposals on draft law No. 1110676-8 were reviewed by the committee, with two official responses signed by chairman S. Boyarsky. The law was signed as Federal Law No. 210-FZ of 26.06.2026.

Committee responses No. 3.27-24/118 of 27.03.2026 and of 24.06.2026.

May 2026
2 of 4 accepted

Proposals on CII security metrics, FSTEC of Russia

On a draft government decree (01/01/04-26/00167663) two proposals were marked accepted: independent verification of assessments through a 10 percent FSTEC sample, and inclusion of financial organisations via Decree No. 92.

FSTEC official summary of proposals.

May, June 2026
Submitted

Policy briefs to the Digital Economy Development Council at the Federation Council

Briefs to the section on technological sovereignty and information security: the infosec workforce gap, and classifying digital currency infrastructure as CII.

A. Sheikin section, 19.05.2026 and 01.06.2026.

Spring, summer 2026
No result

Filings where proposals were not accepted

Amendments to the drafts on DNS (167678), cloud infrastructure for state systems (167984) and Order No. 677 (168142). The official summary on 168142 of 25.06.2026 accepted none of the participants proposals, and no summary has been published on 167678. On the cryptographic protection requirements for state systems (169883) the summary of 01.09.2026 rejected all three proposals. A formal inquiry to the Information Security Department of the Bank of Russia on the gap between NKTsKI and FinCERT notifications received a signed response noting the proposals.

Consultation summaries, Bank of Russia response, ref. OE-220338.

March 2026
Conference paper

XIII Snesarev Readings, RANEPA

"Fintech infrastructure outside the CII perimeter": the regulatory gap thesis presented to the academic community.

XIII Snesarev Readings programme.

Primary sources: the draft law No. 1110676-8 record on sozd.duma.gov.ru and the public consultation summaries on regulation.gov.ru. The full list of 28 filings is on the Russian version of this page.

Expertise

Nine years in IT infrastructure, including inside the CII perimeter of the financial sector: regulatory proposals built on engineering experience, not theory.

National Settlement Depository

3.5 years in engineering roles at systemically important financial market infrastructure, with ownership of technical decisions: technical policy for server infrastructure import substitution.

Ministry of Health federal contract

Contributor to the "Digital Twin of Healthcare Processes" federal project: infrastructure in air-gapped environments.

RANEPA

Master's programme in Public Administration and National Security, thesis on protecting the national payment system infrastructure.

Publications and talks

CII security: clouds, DNS and hosting outside the perimeter of 187-FZ
Article, BISA, Business Information Security Association, 3 September 2026, in Russian
Reimbursement through the state system: analysing the March legislative changes ahead
Article, PLUSworld, PLUS journal, 3 September 2026, in Russian
A standard for AI software: what a bank should ask its vendor now
Article, BIS Journal, 28 August 2026, in Russian
Banks core infrastructure outside the CII perimeter: what the amendment practice showed
Journal article, BIS Journal, 28 July 2026, print issue No. 3/2026, in Russian
Third-party infrastructure as a blind spot of CII regulation
Op-ed column, D-Russia.ru, 16 July 2026, in Russian
Expert catalogue, Information Security section
Expert profile, TAdviser.ru, 17 July 2026, in Russian

Next appearance

1 October 2026, CNews conference "Import substitution in practice 2026": listed among the speakers.

Telegram channel "Na stadii obsuzhdeniya": breakdowns of draft CII and information security regulations while they can still be changed, and what was accepted. Mirrored on MAX: "Na stadii obsuzhdeniya", in Russian.

Profiles

How I can help

Alongside my public work on draft regulations, I take on a limited number of engagements from companies. The format is advisory: analysis, briefs, training. I do not perform work requiring FSTEC licences, such as attestation or technical protection of information.

Breaking down 210-FZ requirements for a bank or telecom operator

On 1 March 2027 the anti-fraud package and its secondary regulation take effect: integration with the state information system for countering offences committed with the use of information and communication technologies, reimbursement of stolen funds, and data exchange with telecom operators. I will give your team a clear picture: which processes to build, the deadlines and risks, and what to watch in the final wording of the decrees. I filed proposals on these drafts and the Digital Ministry accepted some of them, so I know the documents first-hand.

Methodological support for CII object categorisation

187-FZ and Government Decree No. 127: I help you work out which of your systems fall under categorisation, how to prepare the object inventory and justify the categories. I act as a second pair of eyes for your categorisation commission: methodological support, review of contested points, checking documents before submission.

Requirements for artificial intelligence in protected systems

FSTEC is preparing amendments on artificial intelligence to the requirements under Order No. 117, and a draft national standard on secure development of AI software is under discussion in parallel. I will explain what applies to your systems and what to ask a model vendor now: the requirements, the timeline, and the questions for the contract and the architecture. I filed comments on both documents and wrote analyses of them for industry media.

A seminar on CII and infosec regulation for your team

A live walkthrough of current requirements for IT and infosec specialists, lawyers and compliance: what is already in force, what takes effect within the year, what is still under discussion and where a position can still be filed. Based on my own filing practice and correspondence with regulators. One and a half to two hours, online or in person in Moscow.

If this sounds like your situation, write to my e-mail with a short description. The initial conversation is free and carries no obligation, and we discuss the fee once the scope is clear.

For editors and organisers

I comment on CII regulation, the secondary regulation under 210-FZ, FSTEC requirements, artificial intelligence in protected systems and the protection of financial sector infrastructure. Requests are best sent by e-mail, I reply the same or the next working day.

How to introduce me

Nikolay Lobanov, independent expert in information security and critical information infrastructure protection, master's student at RANEPA

Short bio

Independent expert in information security and critical information infrastructure protection. Files comments on draft acts by FSTEC, the Digital Ministry, the FSB and the Bank of Russia, with some proposals marked accepted by the developers.

Full bio

Independent expert in information security and critical information infrastructure protection. Nine years in IT infrastructure, including systemically important financial market infrastructure. Since 2026 takes part in public consultations on draft regulations, with proposals on the anti-fraud package and CII security metrics marked accepted. Author of articles in BIS Journal, D-Russia.ru, PLUSworld and CISOCLUB. Master's student at RANEPA, programme in Public Administration and National Security.

Photographs

Press kit: full size photographs, bios and comment topics on a separate page, in Russian.

Contact

Press comment on CII regulation, participation in public consultations on draft acts, review of regulatory documents, business enquiries from companies.

E-mail: nlobanov-25 [at] ranepa.ru
Press, regulators, event organisers and business enquiries

Telegram: @na_stadii
Draft regulation breakdowns, in Russian

MAX: max.ru/channel_na_stadii
Mirror of the Telegram channel