Security3 publishers3 min readPublished Updated
Russia extends its infrastructure takeover decree to data centres it never designated critical
Operators of more than 180 Russian facilities, most of them inside Ukrainian strike range, have been told to fund counter-drone protection themselves, with temporary state administration as the penalty for those who do not.
The Watch · Security desk

What happened
- Russian data centre operators have been instructed to deploy protections against drone strikes and other physical threats, as part of a wider push on critical infrastructure defences.
- Kommersant reports most large Russian data centres already have solid cybersecurity in place, so for most of them the outstanding requirement is counter-drone protection.
- Russia has more than 180 data centres, with more than 80% of them in the European part of the country and within range of Ukrainian strikes.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- cost The counter-drone spend lands on operators first and, per the Kommersant read, on customers next, so Russian and neighbouring IT buyers absorb the price of a military threat they cannot influence.
- constraint With no published standard for adequate drone defence, an operator cannot demonstrate compliance in advance, which leaves the takeover trigger to the judgement of whoever inspects.
- contradiction Business owners read the decree as groundwork for nationalisation while Kremlin officials call takeovers temporary and rare, and which reading holds decides whether operators overspend now or wait.
- precedent Attaching physical-resilience duties by dependency rather than by sector designation means any provider whose customers are listed can be pulled in without a legal listing change.
The instruction arrives without a specification. Kommersant reports that most of the larger Russian data centres already run solid cybersecurity, so the outstanding work is physical [6], and the report says plainly that what those drone defences will consist of is unclear [7].
That asymmetry is the operative detail. The penalty is defined as operations placed under state administration [2], while the obligation itself carries no such definition. A control with no published standard is enforced at the discretion of whoever inspects it.
The legal route matters as much as the requirement. Data centres are not a formally designated critical infrastructure sector in Russia [4]. Operators were told the decree reaches them anyway, because so much other critical infrastructure runs on their cloud that an outage would hit both public and private sectors [5]. This is designation by dependency rather than by listing. The decree itself, signed last month, covers operators who fail to protect against Ukrainian hacks and drone strikes or who take too long to repair damage [3]. No signing date appears in the report; the bulletin's other items are dated September 2, 2026, which places the signature in August [3].
Scope: more than 180 data centres in Russia, more than 80% of them in the European part of the country, inside the range of Ukrainian strikes [11]. Eighty per cent of 180 is 144, and the "more than" on both figures pushes the real number higher [1]. The exposed population and the regulated population are close to the same set, which is why the instruction is easy to justify and hard to price. The facilities east of that line inherit the compliance cost without the threat.
The cost path has a named claim behind it. Risky Business, reading the Kommersant report, expects the counter-drone investment to be passed down to customers, raising IT costs across Russia and neighbouring countries [8]. Neither the per-site cost nor a compliance deadline appears in the reporting [2]. An operator budgeting now is pricing an undefined control against an undefined trigger.
The panic and the text point in different directions. Russian business owners initially read the decree as a legal framework for nationalising their assets [9]. Kremlin officials have since said the transfer of ownership and assets is temporary and will be used rarely, for the most egregious offenders [10]. The first is a reading; the second is an assurance from the party that would do the taking. The wording that triggers a takeover has not narrowed in either account [3].
For operators outside Russia, the transferable element is the mechanism itself. A state can attach physical-resilience duties to cloud providers through their customers' criticality, skip the sector list entirely, and back the duty with an operating takeover [4][5][2]. Anti-drone kit at a data centre perimeter is a wartime line item specific to Russia and Ukraine. Being regulated as critical infrastructure without being listed as critical infrastructure travels far more easily.
What to watch
- Whether Russian regulators publish an actual counter-drone specification or inspection regime for data centres, which would turn discretion into a checklist.
- The first named operator placed under temporary state administration, and what specifically triggered it.
- Whether data centres are formally added to Russia's critical infrastructure sector list, converting a verbal instruction into statute.