Security1 distinct publisher3 min readPublished
Operators of more than 180 Russian facilities, most of them inside Ukrainian strike range, have been told to fund counter-drone protection themselves, with temporary state administration as the penalty for those who do not.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The instruction arrives without a specification. Kommersant reports that most of the larger Russian data centres already run solid cybersecurity, so the outstanding work is physical [6], and the report says plainly that what those drone defences will consist of is unclear [7].
That asymmetry is the operative detail. The penalty is defined as operations placed under state administration [2], while the obligation itself carries no such definition. A control with no published standard is enforced at the discretion of whoever inspects it.
The legal route matters as much as the requirement. Data centres are not a formally designated critical infrastructure sector in Russia [4]. Operators were told the decree reaches them anyway, because so much other critical infrastructure runs on their cloud that an outage would hit both public and private sectors [5]. This is designation by dependency rather than by listing. The decree itself, signed last month, covers operators who fail to protect against Ukrainian hacks and drone strikes or who take too long to repair damage [3]. No signing date appears in the report; the bulletin's other items are dated September 2, 2026, which places the signature in August [3].
Scope: more than 180 data centres in Russia, more than 80% of them in the European part of the country, inside the range of Ukrainian strikes [11]. Eighty per cent of 180 is 144, and the "more than" on both figures pushes the real number higher [1]. The exposed population and the regulated population are close to the same set, which is why the instruction is easy to justify and hard to price. The facilities east of that line inherit the compliance cost without the threat.
The cost path has a named claim behind it. Risky Business, reading the Kommersant report, expects the counter-drone investment to be passed down to customers, raising IT costs across Russia and neighbouring countries [8]. Neither the per-site cost nor a compliance deadline appears in the reporting [2]. An operator budgeting now is pricing an undefined control against an undefined trigger.
The panic and the text point in different directions. Russian business owners initially read the decree as a legal framework for nationalising their assets [9]. Kremlin officials have since said the transfer of ownership and assets is temporary and will be used rarely, for the most egregious offenders [10]. The first is a reading; the second is an assurance from the party that would do the taking. The wording that triggers a takeover has not narrowed in either account [3].
For operators outside Russia, the transferable element is the mechanism itself. A state can attach physical-resilience duties to cloud providers through their customers' criticality, skip the sector list entirely, and back the duty with an operating takeover [4][5][2]. Anti-drone kit at a data centre perimeter is a wartime line item specific to Russia and Ukraine. Being regulated as critical infrastructure without being listed as critical infrastructure travels far more easily.
Ranked by verification strength, evidence, and original report placement.
The Russian government has instructed data center operators to deploy protections against drone strikes and other physical threats as part of a national effort to boost defenses at critical infrastructure organizations.
Companies that fail to follow the Kremlin's instructions risk having their operations put under the state's administration.
Russian President Vladimir Putin signed a presidential decree last month allowing the state to temporarily take over the operations of critical infrastructure operators who fail to protect against Ukrainian hacks and drone strikes, or take too long to repair damage.
Data centers are not formally considered a critical infrastructure sector in Russia.
Data center operators were told the decree also applies to them, primarily because other critical infrastructure relies so heavily on cloud services that any data center outage is likely to cause widespread impact across both the public and private sectors.
According to a Kommersant report, most of the larger Russian data centers already have solid cybersecurity defenses in place, which means most only have to deploy drone defenses.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
ONCD stakes Texas water security on six months of donated vendor red teaming4 distinct publishers
invest
Markets price Ukraine ceasefire by end of 2026 at 18 cents on the dollar amid Ratcliffe summit report1 distinct publisher
invest
Designation day: your cloud vendor now answers to three regulators, and you still answer for it1 distinct publisher
security
Dutch bill would let AIVD and MIVD tap a designated adversary for a year without pre-approval2 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One newsletter relaying one Russian paper
Follow the chain and it is two links long: Risky Business summarising a Kommersant story. There is no decree number, no ministry, no named official and no operator on the record. The figure most likely to be repeated — 180-plus facilities, over 80% in European Russia — arrives with no registry or survey behind it, and the arithmetic floor of 144 exposed sites is only as good as that unsourced count.
An order issued, not a fence built
What exists is an instruction with a threat attached. Nothing in this reporting shows a single perimeter hardened, a detection system installed or a facility inspected, and there is no date by which any of that must happen. The reach is real — the instruction is described as landing on operators across a sector of more than 180 sites — but reach of a directive is not deployment.
Restrained account, two quotable overreaches
Risky Business does not inflate this; it says plainly that nobody knows what 'drone defenses' means, which is the most honest line in the piece. The stretch sits in the parts built to travel: a spike in IT costs across Russia and its neighbours, offered as expectation with no number attached, and strike-range framing that turns an unsourced facility count into a threat map. The headline promise of protection is also doing work the story never cashes — no measure, no deadline, no inspection.
Two interested filters before the reader
The Kremlin's walk-back is the tell: takeovers will be temporary, rare, reserved for the worst offenders. That is precisely the message a government facing capital-flight panic wants carried, and it reaches us through unnamed officials in the Russian domestic press rather than any published clarification. Kommersant is reporting on a presidential decree from inside Russia, which shapes what can be said about it. The relaying newsletter also opens with a disclosed vendor sponsorship, unconnected to this item but worth naming.
Believable direction, unusable detail
The trajectory is specific and internally consistent enough to credit: Moscow folding uncategorised infrastructure into a takeover regime and shifting the bill for physical defence onto private operators. Everything that would let someone act on it — when compliance is due, what it costs, what hardware is even permitted, which facilities have been told — is missing, and there is no second publisher to supply it. Dating rests on a 2 September 2026 statement elsewhere in the same issue, which is inference rather than a stated signing date.