Solar launched a web protection service with a financial guarantee
The provision of compensation in case of successful cyber attacks was concerned not only by insurers, but also by companies from the sphere of information security. One of the largest participants in the Solar market offered protection against web attacks with financial guarantees. Experts note that not many customers can afford such services.
One of the largest companies in the information security market (IB) « Solar » launched a service protection service (WAF) with financial guarantees for online stores, they told Kommersant in the company. Payment of compensation is possible in cases of failure in the work of the WAF software and hardware, failure to fulfill the functionality and non-compliance with the parameters declared in the technical task, as well as failures of the service due to DDOS attacks on the contractor infrastructure. The size of the material guarantee is determined by the formula, taking into account the downtime, as well as the potential undertaken profit. The company assess the probability of such events no higher than 0.5%.
According to Solar, in some cases, compensation payments can reach up to several million rubles.
According to “Inform Promotions”, online stores are among the most attacking companies, as they store huge volumes of personal data and financial information. “The total number of DDOS attacks on Russian organizations for 2024 has almost doubled, reaching 508 thousand,” is estimated in “Inform Protection”. At the same time, according to the director of the technical department of the RTM Group, Fedor Muzalevsky, about 5 thousand online stores use protection against web.
Insurance companies are already engaged in cyber insurance, but it does not cause great interest in the real sector. Most Russian companies (51%) are not insured by the risks associated with information leaks, it follows from the Infowatch study. According to experts, from the total number of legal entities registered in the Russian Federation, they do not have 99% of companies from leakage of data. The volume of the cyber insurance market in 2024 amounted to about 3 billion rubles, and in 2025 it may exceed 3.5 billion rubles. (see “Kommersant” dated February 6).
The service offered by Solarm, “can afford no more than dozen stores, they should be attributed primarily to marketplaces,” Mr. Muzalevsky notes. According to him, only the defense of the corps is « from several thousand to several tens of thousands of rubles per day. » Wildberries & Russ said that they use the integrated Secure-By-Design approach to protect web services, including their own solutions. In Akit, Yandex and Ozone, they did not respond to Kommersant’s request.
The IB market participants surveyed by Kommersant do not plan to launch such products with financial guarantees. According to Sergei Babkin, the director of the “Information Security” direction, the key difficulties in launching such a product lie in the creation of the correct risk calculation model, which “should include many variables, from what the customer is and how interesting it is to potential attackers, to evaluating its infrastructure, the state of information protection systems, as well as the volume of services for which the finalness Contractor and an agreement on the level of services. «
Such statements about financial guarantees are rarely used in the market, “since they are marketing in nature,” said Alexander Bleznosevov, head of the IBC of the Telecom Exchange. To pay compensation, it is necessary to “determine and prove for what reasons the inaccessibility of the online store occurred, where the simple service arose, whether the service provider, which provided the web application using WAF, is to blame,” he lists. At the same time, the problems can be in the infrastructure, in the communication channel, etc. Therefore, the probability of an occasion in which compensation will be paid, “seems extremely low,” summarized Mr. Blemosyvy.