Summary

  • Infosecurity Ltd is best understood as a regulated Russian managed-security business with a small network-control surface, not as a network operator whose economics are driven by route scale. AS201144, the RIPE LIR record and its routed address blocks are evidence of operational footing, but the economic asset is the service stack: SOC, digital-risk protection, DLP operation, penetration testing, vulnerability management, compliance consulting and Softline channel reach.
  • The judgment is favourable but conditional. Infosecurity can defend margin when it turns one-off compliance and incident-anxiety spending into recurring managed-service contracts with high analyst utilisation and controlled vendor costs. The case weakens if entry prices become the realised price for complex customers, if Russian-vendor supply captures the gross margin, if government and regulated-sector work creates more liability than renewal revenue, or if the company cannot keep its public trust signals current.

The Customer Is Buying A Transfer Of Burden

A bank, industrial company or public-sector buyer does not buy an outsourced security operations centre because it wants another dashboard. It buys a transfer of burden. The customer wants someone else to collect events around the clock, maintain detection rules, classify incidents, contact the responsible people, preserve evidence for regulators and decide when a routine alert has become a board-level problem. The economic question is therefore not whether Infosecurity can describe a modern security service.

It is whether the company can price that transfer high enough to pay for the people, infrastructure, software licences and incident commitments required to make it credible.

That starting point matters because the public record contains two very different stories. One story is marketing language about 24/7 monitoring, hundreds of detection scenarios, Russian-certified technology, cyber-risk insurance and compliance with Russian security rules. The other is a set of financial and registry records that show a small legal entity carrying the RIPE network record, a larger service entity carrying much of the staff base, a parent group with strong distribution, and a competitive Russian SOC market where larger rivals can press price and talent costs at the same time. Infosecurity is not an obvious failure.

It is a margin test.

The core product is plausible. Infosecurity advertises SOC as a service with payment tied to actual events per second, connection from one month, event storage starting at three months, more than 100 supported event sources, more than 700 detection scenarios, more than 30 automatic response scenarios, a 50-plus expert SOC team, L1 to L3 handling, private-cloud processing on Infosecurity capacity, and cyber-risk insurance up to 10 million rubles for recovery-related costs within contractual limits. That is a serious claim for a mid-market and regulated-buyer proposition. It lets a customer avoid building an entire monitoring function alone.

But it also means Infosecurity carries the complexity that the customer is trying to avoid.

The first explicit judgment is this: Infosecurity's economics work only if the company is treated as a managed-service and compliance-packaging business, not as a reseller with a monitoring label attached. A reseller can survive on project margin and vendor rebates until purchasing cycles turn. A managed-security provider needs recurring revenue, repeatable onboarding, tight incident process, a labour model that does not consume every upsell, and enough proprietary workflow to keep the customer from comparing only licence prices. The public evidence shows that Infosecurity has the ingredients.

It does not prove that every ingredient belongs to the same legal entity or that each service line is equally profitable.

The Entity Boundary Is A Real Operating Issue

The directory entity points to Infosecurity Ltd as recorded by RIPE: ORG-IL513-RIPE, country Russia, registration number 1137746423330, LIR status, Moscow address and the AS201144 record. The company's own requisites page ties that registration number to ООО "ИС", full legal name Общество с ограниченной ответственностью "ИНФОСЕКЬЮРИТИ", with INN 7705540400 and main activity in computer consulting and related work. That is the right anchor for the directory entity and for this article.

The same official requisites page also lists ООО "Инфосекьюрити Сервис", with a separate registration number and tax identifier. Public corporate mirrors show that the service entity is much larger than the RIPE legal entity by staff and, in recent data, by income. RBC Companies puts the service entity's 2024 revenue at 920.237 million rubles and profit at 17.155 million rubles. Zachestny Biznes reports 2025 income of about 1.4 billion rubles, net profit of 59 million rubles and 279 employees for Infosecurity Service.

By contrast, Companium reports 2025 revenue of 601.4 million rubles and net profit of 72.1 million rubles for ООО "ИС", but only six average employees. RBC's 2024 mirror reported 617.973 million rubles of revenue, 67.390 million rubles of profit and 14 average employees for the same ООО "ИС".

That discrepancy is not a minor footnote. It changes the interpretation of every operating claim. If a page claims hundreds of engineers, dozens of SOC experts and more than 700 projects, those claims are more consistent with a service group than with a six-person reporting entity. The analyst should not pretend the legal accounts, the website brand, the service entity and the network record are interchangeable.

The better reading is that the public-facing Infosecurity service operation is distributed across related entities inside Softline's Russian perimeter, while the directory entity carries the RIPE network record and its own financial statements.

There is also a same-name trap. A separate Russian company using the Infosecurity name publishes a different tax number, address and contact set. It is active in similar security language, but it is not the RIPE entity tied to ORG-IL513-RIPE. That kind of naming collision matters in cyber-security because buyer trust depends on knowing which legal counterparty, licence holder and incident responder is actually under contract. It also matters for this article: the relevant Infosecurity Ltd is the entity tied to OGRN 1137746423330 and the Softline-related service operation, not every company that can style itself as Infosecurity in Moscow.

The ownership boundary points toward Softline. Public records show ООО "ИС" owned overwhelmingly by Infosecurity Service and a Softline-related entity in one public mirror, while later public mirrors show Softline Security in the structure. The larger service entity is also reported as almost entirely owned by Softline Security in 2025 data. OSP reported in 2018 that Softline bought a controlling stake in Infosecurity, preserving the brand while expanding security services, including SOC and computer forensics.

CNews later described Softline-linked option and ownership structures around Infosecurity and noted that cryptography-license holders create foreign-investment approval constraints. The conclusion is not that Infosecurity is independent from Softline. It is that its sales reach and supplier leverage are strengthened by Softline, while its legal and regulatory architecture remains more complicated than a clean single-entity story.

The Network Footprint Supports Operations, Not A Network Thesis

Infosecurity has real number-resource evidence. RIPE identifies the organisation as an LIR. AS201144 is named ISS-AS and assigned to the Infosecurity organisation. The RIPE aut-num entity lists two upstream paths: AS199599 and AS209805. RIPEstat's current announced-prefix data showed the network announcing 149.255.132.0/22, four component /24s and 2a07:f540::/29 in the July 2026 observation window. BGP tools also described the network as active, RIPE-allocated, with five IPv4 originated prefixes, one IPv6 originated prefix, two upstreams and two peers.

IPinfo classified the ASN as a business network with 1,024 IPv4 addresses, two upstreams, zero downstreams and Moscow routers.

Those facts are useful because they show operational presence. A managed SOC that stores logs in a private cloud and exposes service portals needs controlled infrastructure, addressing, routing and abuse contacts. The ASN and prefixes help show that Infosecurity is not merely brokering everything through an unrelated hosting account. They also fit the company's claim that event processing for SOC as a service occurs on Infosecurity capacity.

But the same facts cap the network thesis. There is no public PeeringDB profile for AS201144 at the queried ASN. The upstream set is narrow. IPinfo shows no downstreams. BGP tools shows four /24s of IPv4 address space, not a broad access or hosting estate. The right reading is a small controlled network surface around service delivery. It is not evidence of a carrier business, a major hosting platform, or a large interconnection position. Routes, ASNs and prefixes are evidence, not entities, and here they point to operational support rather than the main economic engine.

That distinction matters for pricing. A network operator with many downstreams can spread backbone, peering and support costs across traffic and customers. Infosecurity cannot rely on that kind of network scale. Its margin must come from service attachment, analyst productivity, tooling reuse and the ability to package compliance risk. The network gives it credibility, but it does not solve the cost structure.

The Product Stack Is Built For Recurring Attach

Infosecurity's commercial proposition is broader than SOC. The home page and service pages cover SOC, DLP implementation and support, penetration testing, vulnerability management, cyber-resilience, employee training, audit and regulatory compliance. CYBERDEF adds a digital-risk and brand-protection SaaS offer. CYBERID adds executive digital-footprint protection. Cyber-checkup creates packaged diagnostic work. The catalogue matters because recurring SOC alone is hard to price high enough if every customer needs custom integration.

A stronger model sells the customer a security operating system: assess, implement, monitor, respond, train, review and improve.

The SOC page is the clearest recurring product. Pricing is tied to actual EPS and starts at 300,000 rubles. The service can be connected from one month, stores events from three months, includes private-cloud log storage and allows additional options to be activated or deactivated during the contract. That is a practical structure. EPS pricing lets the company charge more as telemetry volume rises. Optional modules help preserve entry-level affordability while keeping enterprise expansion possible. Quarterly payment options and one-month connection language lower initial customer friction.

The danger is that starting prices can anchor buyer expectations. A SOC price from 300,000 rubles per month equals 3.6 million rubles per year before options, expansion and implementation work. That may be attractive for a medium customer that cannot hire a full team. It is not enough by itself to support a large dedicated team, deep custom detections, regulatory reporting, incident response and insurance-backed risk transfer for a demanding enterprise.

The economic solution is segmentation: use the entry price for narrow EPS and service scope, then expand through event volume, extra sources, consulting, incident-retainer work, vulnerability management, DLP support and compliance deliverables.

Cyber-checkup shows the one-off side of the funnel. Public prices include around 150,000 rubles for personnel-focused phishing work, 350,000 rubles for compliance, 400,000 rubles for brand analysis, 500,000 rubles for perimeter work, 550,000 rubles for management-system assessment, 950,000 rubles for technical audit, and around 2.6 million rubles for the full package before discount. These prices are not padding; they show how a managed-security provider monetises customer anxiety before it becomes a subscription. A buyer unsure of its perimeter, personnel resilience or regulatory state can start with a diagnostic.

Infosecurity can then convert findings into implementation, monitoring and managed response.

CYBERDEF strengthens the recurring story. It is presented as a SaaS service with Russian code and team, a Russian software-register entry, a price from 120,000 rubles per month, monitoring across open and hidden digital spaces, more than 10,000 phishing resources blocked monthly, more than 450,000 digital threats identified monthly on average, 24/7 team operation and incident reaction within three minutes. The facts are company claims, not audited performance data. But as economics they are meaningful: digital-risk protection is more modular than a full SOC and can attach to fraud, brand, executive-protection and threat-intelligence budgets.

CYBERID, at a stated price from 100,000 rubles, is another margin experiment. It sells protection for executives and owners, with one-month or annual structures. The value proposition is not commodity firewall support. It is the idea that senior management creates a risk perimeter through personal data, public records, messaging exposure and impersonation. If Infosecurity can attach that to banking, retail, industrial and public-sector accounts already buying monitoring or brand protection, the incremental gross margin can be attractive. If it is sold as bespoke manual research, labour costs will rise quickly.

DLP services complete the managed-operating model. The DLP page says Infosecurity implements, supports, tunes and reviews DLP systems, including daily event handling, vendor interaction, documentation and SLA-based support. It cites customer scales from 500 to more than 25,000 users. DLP is labour-intensive, but it is also sticky. Once policies, exceptions, employee communications and legal documentation are embedded, switching providers is painful. That creates better retention than a one-time software resale.

Penetration testing and vulnerability management play a different role. They are not necessarily recurring in the same way as SOC, but they create high-skill credibility and feed the monitoring business. The pentest page covers external, internal, web, mobile, source-code and social-engineering tests, with reports and remediation plans. The vulnerability-management page emphasises process design, implementation, automation and outsourcing. In a strong account, those services explain why the SOC sees certain events, why the customer has certain controls, and which fixes reduce future alert volume.

That is how advisory work can protect monitoring margin rather than distract from it.

Pricing Must Outrun Labour

The labour challenge is visible in several ways. The SOC page claims 50-plus experts in the SOC team. Cyber-checkup claims more than 300 certified engineers across the team. Vulnerability management claims more than 250 engineers. Public corporate mirrors, however, show the six-person or 14-person reporting base at ООО "ИС" and the much larger staff base at Infosecurity Service. That split is logical inside a group structure, but it means the economic burden is carried somewhere in the related-entity system even if a single financial statement does not show it cleanly.

Security labour is not a cheap support desk. RuSecJobs archives show Infosecurity historical recruiting for cloud SIEM work involving high event loads, Hadoop ecosystem experience, normalization, correlation rules, SQL, Linux and documentation. The same public archive includes Moscow SOC analyst roles at other employers with pay references around 120,000 to 180,000 rubles net for experienced operational roles, while an Infosecurity trainee analyst posting referenced part-time student work at a much lower starting level.

The precise pay for current Infosecurity staff is not public, but the direction is clear: credible SOC work requires a blended team, not only junior monitors.

Softline's own 2025 results release adds the parent-level pressure point. The group cited wage growth as one reason operating expenses rose, while also noting customer budget pressure under inflation. That combination is exactly what squeezes managed services. Customers outsource because they do not want to pay for a full team. Providers still have to pay the team. The spread survives only when the provider's staff and tools support many customers with enough standardisation.

The public prices imply three tiers of margin. The first is low-touch recurring: CYBERDEF from 120,000 rubles a month, CYBERID from 100,000 rubles, SOC entry from 300,000 rubles. These are attractive if modules are standardised and a shared team can serve many customers. The second is project work: cyber-checkups, audits, pentests and implementation. These can carry high nominal ticket sizes but depend on utilisation and scope control. The third is complex regulated service: bank SOC, DLP operation, KII compliance and incident response. These can produce sticky accounts but also create the highest liability and labour load.

Infosecurity's 2025 public financial mirror for ООО "ИС" shows 601.4 million rubles of revenue and 72.1 million rubles of net profit. That is a respectable net margin in public accounting terms. RBC's 2024 numbers show 617.973 million rubles of revenue, 67.390 million rubles of profit, 267.305 million rubles of cost of sales and 350.668 million rubles of gross profit. Those figures look healthy. The caution is that the accounts are entity-specific and not enough to isolate recurring managed-security gross margin.

If revenue includes resale, project work, support, subsidies, implementation or intercompany transactions, the SOC economics cannot be read directly from the headline profit.

Infosecurity Service shows a different profile. RBC reports 920.237 million rubles of 2024 revenue and 17.155 million rubles of profit, with 553.990 million rubles of cost of sales and 366.247 million rubles of gross profit. Zachestny Biznes reports 1.4 billion rubles of 2025 income, 59 million rubles of net profit and 279 employees. That looks like the staff-bearing service company: larger revenue, lower net margin, larger wage and delivery base. If that is right, the service entity carries more of the labour reality while ООО "ИС" carries some product, network, license or project economics.

A buyer would not care about the internal split until there is a dispute. An investor or counterparty should.

Suppliers Can Capture The Economics

Infosecurity's proposition is explicitly multivendor and domestic. The SOC page names Security Vision IRP and KUMA SIEM as certified Russian solutions in the SOC core. The store and catalogue language points to Kaspersky, Code Security, Positive Technologies and Dr.Web products. The home page says the company uses Russian software included in the domestic software register. This is commercially necessary in Russia's post-2022 procurement environment. Regulated buyers need domestic products, certified controls and local support.

Supplier dependence is not automatically bad. A managed provider can create margin by knowing which product fits a given customer, configuring it properly, absorbing the vendor learning curve and operating the service after deployment. In a market where customers are replacing or reducing dependence on Western products, that integration work has value. The MS Bank Rus case is useful: the customer had IBM QRadar and considered buying Russian products or building a hybrid SOC before choosing Infosecurity's service. That is exactly the kind of decision where an integrator can turn vendor transition into recurring service revenue.

The risk is that the supplier captures the durable economics. If the customer views the outcome as KUMA, Security Vision, Kaspersky, Dr.Web or Positive Technologies plus a replaceable operator, Infosecurity becomes a channel and staffing layer. If the vendor controls roadmap, certification, licence price and renewal mechanics, Infosecurity can win the deal and still give away margin. The better outcome is for Infosecurity to own the detection content, onboarding pattern, incident process, customer evidence pack and account relationship.

The public SOC page tries to claim that ground through its own scenarios, response playbooks, private-cloud storage, personal account and reporting language.

Softline gives Infosecurity leverage on this issue. Softline's audited 2025 results show very large group turnover, significant gross profit and a strategic emphasis on own solutions. The 2025 results release shows services and cloud solutions as a major gross-profit contributor and describes strong margins on own solutions. Group scale can help negotiate vendor terms, reach customers and finance development. It can also impose parent priorities. If Softline pushes volume, Infosecurity may win more accounts at thinner margin.

If Softline pushes own-solution margin, Infosecurity may be expected to favour group economics over customer-neutral product choice.

Customers Pay For Compliance As Much As Detection

The strongest customer segment is not the most technically glamorous one. It is the customer with a regulatory problem. The SOC page targets critical information infrastructure, personal-data processors, distributed infrastructure, finance, large business and medium business. It cites FSTEC, FSB, FinCERT, GosSOPKA/NKTsKI, KII law, personal-data law, Russian banking standards and Central Bank requirements. The audit and compliance pages reinforce the point. Infosecurity is selling evidence that a buyer can show to supervisors, auditors and internal risk committees.

That is economically powerful because compliance budgets are less discretionary than experimental security budgets. A customer can defer a better dashboard. It cannot easily ignore sector regulation, KII classification, personal-data protection, financial-sector controls or a board directive after a visible breach. Infosecurity's licences and certifications are therefore not decorative. They are part of the product. FSTEC and FSB licence numbers allow the company to perform categories of regulated work.

The company does not simply promise technical improvement; it promises that improvement in a language Russian regulated buyers can procure.

The Norvik Bank and MS Bank Rus cases show why this works. In the Norvik case, SOC-as-a-Service was framed around avoiding capital expenditure and high-qualified personnel while gaining monitoring and prevention capability. In the MS Bank Rus case, the bank weighed buying a Russian replacement, building a hybrid SOC or using a service, then chose the service. This is the classic managed-service sales motion: "Do not build a full stack alone; buy the outcome." For a bank, the outcome includes regulator-facing comfort, incident evidence and operational continuity, not only alert detection.

Public procurement data adds another side of concentration. Companium reports 95 public-procurement contracts for ООО "ИС" totalling 155.5 million rubles, with named top customers including public and state-linked organisations. Public-sector work can validate regulatory capability and provide steady demand. It can also create slow payment cycles, paperwork, bid price pressure and legal exposure. The Minpromtorg dispute reported by ABN, where the court refused an 87.12 million ruble claim over a monitoring-and-response platform subsidy, is not a proven operating failure; the report says the claim was refused.

But the existence of the dispute still shows the kind of public-money and performance-measure conflict that can arise when security platforms are tied to state support.

The same applies to court evidence. A Garant-recorded lease-payment dispute involving ООО "Инфосекьюрити" is not strategically significant by itself. It matters only as a reminder that the legal entity has ordinary corporate frictions in addition to high-trust security claims. None of the public evidence suggests insolvency or a sanctions block; Companium's screening states no sanction-list inclusion for ООО "ИС" in its public view. The operational lesson is narrower: regulated work creates credibility and complexity at the same time.

Trust Signals Are Mixed

Infosecurity has several positive trust signals. It lists FSTEC and FSB licences. It claims direct coordination with FinCERT and GosSOPKA/NKTsKI. It advertises a licensed CERT posture and says the service team has recognised qualifications. Its public pages show bank cases, regulatory service lines and Softline group backing. Its financial mirrors show an active company with meaningful revenue and profit. The route registry shows a maintained RIPE entity and current prefixes.

The mixed signal is FIRST. The FIRST team directory currently lists Infosecurity Incident Response Team, IN4-CERT, as suspended. That does not erase domestic regulatory credentials. It does weaken any claim that international incident-response association membership is a live, unqualified trust asset. Carnegie Mellon's public guidance on CERT mark authorisation also reminds readers that CERT naming is a licensed mark process, not a generic badge.

Infosecurity may have valid historical or contractual rights around its CERT name, but a current buyer should distinguish domestic incident-response capability from current international association status.

The other mixed signal is visibility. The company has a small ASN, limited public interconnection, no public PeeringDB profile and a same-name company outside the scope of the RIPE entity. None of these facts breaks the business case. Each adds diligence burden. A customer transferring incident responsibility should know the exact contracting entity, support entity, data-hosting location, subprocessors, licence holder, insurance limit, service desk process and escalation path. If Infosecurity can answer those questions clearly, the visibility gap becomes manageable.

If it cannot, the buyer will push price down or choose a larger SOC provider with simpler public posture.

The unofficial labour and jobs signals cut both ways. Historical job posts around Infosecurity cloud SIEM work suggest real technical substance: high event loads, Hadoop-type systems, correlation rules and normalization are not superficial marketing terms. They also show why margins can be hard. SOC capability is built by specialists who can leave, demand higher pay, or become bottlenecks when projects stack up. Automation reduces routine work only after expensive rule creation, integration and tuning.

Competitors Are Numerous And Larger In Parts Of The Stack

Infosecurity is not selling into an empty market. Anti-Malware's SOC and penetration-testing reviews place it among a wide group of Russian SOC, MDR, security integrator and pentest providers, including companies with larger public security brands, larger analyst benches or more proprietary technology. Interfax reported a Russian SOC-monitoring services market estimate of roughly 24-25 billion rubles in early 2025 with about 30% annual growth. A growing market attracts capacity. Capacity eventually presses pricing.

The alternatives for a customer are straightforward. A large bank or industrial company can build its own SOC, buy domestic SIEM and IRP platforms, create a hybrid team, contract with a larger managed provider, or split work between a product vendor and a consultancy. The MS Bank Rus case itself says the customer compared Russian-product purchase, hybrid SOC and SOC-as-a-Service. That is the real competitive frame: Infosecurity must beat in-house capex, vendor-led implementation and larger outsourced SOCs at once.

Its advantage is breadth and channel. Infosecurity can move from cyber-checkup to implementation to SOC to DLP support to vulnerability management to executive protection. Softline can bring procurement reach and vendor relationships. Domestic licences help regulated buyers. The service pages give price anchors, which many enterprise security providers avoid. That transparency can help medium customers approach the company before they are ready for a large bespoke procurement.

Its disadvantage is the need to defend premium value without looking generic. If every competitor says 24/7, certified products, threat intelligence, response, regulatory compliance and expert team, the buyer will ask for price. Infosecurity has to show why its onboarding, detection content, reporting, insurance limit, customer communication and Softline-backed delivery reduce total cost. The public pages make the claim. The hard test is renewal behaviour, which is not public.

Unit Economics: The Spread Is There, But It Is Narrow

The rough unit-economics logic is simple. At 300,000 rubles per month, a base SOC customer produces 3.6 million rubles of annual recurring revenue before options and implementation. Ten such customers produce 36 million rubles. One hundred produce 360 million rubles. That arithmetic looks attractive only if the service is standardised, event volumes are priced correctly and the same team can manage many customers without manual escalation swallowing the gross margin.

The one-off products can fill the gap. A technical cyber-checkup at around 950,000 rubles or a full checkup at around 2.6 million rubles can create useful project revenue. Penetration tests, Sber-methodology audits, DLP configuration and vulnerability management can add billable days. But project revenue is not the same as recurring value. It resets after delivery and depends on staff availability. Infosecurity should want every project to create a follow-on subscription, not just a satisfied one-time buyer.

The public financials support a cautious positive view. ООО "ИС" made profits in 2024 and 2025 according to public mirrors. Infosecurity Service appears to have scaled revenue and employees. Softline's group economics provide distribution and financing context. This is not a shell with a website. Yet the profitability evidence is not granular enough to prove the core SOC product alone has strong margin. The broader group may make money from licences, implementation, support, state projects, branded platforms, service resale, intercompany arrangements and staff leasing.

The article's judgment must therefore stay disciplined: the business can be attractive, but the SOC label by itself does not prove a high-quality recurring revenue base.

The best evidence in favour of margin is the product ladder. Start with cyber-checkup or audit. Attach DLP support or vulnerability management. Move the customer onto SOC with EPS pricing. Add CYBERDEF for brand and phishing exposure. Add CYBERID for executives. Use Softline to sell domestic product licences and infrastructure. Use regulatory deadlines to shorten sales cycles. Use incident reports to keep renewals. That ladder can create account-level economics that a simple "SOC from 300,000 rubles" price does not reveal.

The best evidence against margin is the same ladder. Every rung requires people. Consultants assess. Engineers integrate. Analysts monitor. Service managers report. Pentesters test. DLP specialists tune. Incident responders investigate. Lawyers or compliance specialists document. If each customer requires bespoke work and the provider cannot automate or standardise enough, revenue growth can become labour growth. The 279-employee service-entity signal is therefore double-edged: it shows capacity, but it also shows the cost base needed to support the promise.

Geopolitics Helps Demand And Raises Friction

Russia's security market has been reshaped by import substitution, domestic certification and reduced comfort with Western security products. Infosecurity's pages lean into that environment. They refer to Russian products, domestic software-register entries, FSTEC and FSB licences, KII, personal data, Central Bank standards and Russian-certified SOC core technology. For buyers that cannot use, renew or justify Western tooling, a local provider with Softline reach is useful.

But geopolitics is not pure tailwind. Domestic products can narrow supplier choice. International trust markers may be harder to maintain. FIRST suspension for Russian teams, including Infosecurity's IN4-CERT listing, is a visible example. Encryption-related ownership structures can create approval issues, as reported around Softline-linked companies. Public-sector subsidies can create future performance and clawback disputes. Customers in globally exposed industries may need assurance that a domestic SOC can still handle cross-border incident evidence, cloud relationships and multinational audit expectations.

The practical conclusion is that Infosecurity is strongest where local compliance and local response matter more than international neutrality. Russian banks, industrial groups, domestic cloud and regulated public-sector buyers are natural customers. Multinational customers with sanctions, cross-border data and global incident-response requirements may be more cautious. The company's own customer evidence leans toward domestic regulated buyers, which fits the thesis.

What Would Reverse The Judgment

The positive judgment would weaken first if the pricing evidence proved to be more ceiling than floor. If most SOC contracts sit near the 300,000-ruble monthly entry price while requiring high-EPS coverage, complex integrations, regulatory reporting and frequent human escalation, the service would be underpriced. Entry pricing is useful only if volume, modules and standardisation move accounts up the curve.

The second reversal would be supplier economics. If Security Vision, KUMA, Kaspersky, Dr.Web, Positive Technologies or other domestic providers capture the contract renewal, licence uplift and roadmap value while Infosecurity remains the implementation and support layer, gross margin will compress. The company needs its own detection logic, response process, customer data model and account trust to keep the spread.

The third reversal would be legal or trust deterioration. Loss or restriction of FSTEC or FSB licences would hit regulated work directly. An adverse final subsidy-performance outcome would raise public-sector risk. Persistent FIRST suspension would not destroy domestic business, but it would reduce the value of international incident-response signalling. Confusion with separate same-name companies could also become costly if buyers cannot identify the contracting and data-processing entity clearly.

The fourth reversal would be customer concentration. Public bank cases and procurement data are useful, but they do not prove diversification. If a small number of public or financial customers account for a large share of recurring revenue, renewals and procurement cycles become more important than product quality. Infosecurity needs repeatable sales across finance, retail, industry, telecom, technology and public bodies, not only flagship cases.

The fifth reversal would be labour inflation. Softline has already acknowledged wage pressure at the group level. A managed-security provider can beat that pressure through automation, junior-to-senior leverage, reusable playbooks, strong tooling and clear scope. It cannot beat it through marketing. If experienced analysts, pentesters and engineers become more expensive faster than service prices rise, net margin will follow the staff market down.

The upside reversal is also clear. If Infosecurity can show consolidated recurring revenue, low churn, high module attachment, improved FIRST or equivalent trust status, durable FSTEC/FSB standing, high renewal rates, and a measurable spread between analyst cost and managed-service revenue per customer, the company would look stronger than the public evidence alone suggests. The public financials already show profitability. The missing proof is recurrence quality.

Final Judgment

Infosecurity is a defensible Russian managed-security business inside a larger Softline orbit, with enough licences, service breadth, network evidence and customer cases to be taken seriously. Its strongest economic proposition is not selling tools or operating a small ASN. It is persuading regulated customers that outsourcing monitoring, incident triage, digital-risk work and compliance evidence is cheaper and safer than building the same function in-house.

That proposition can create good margin, but only under discipline. The company must keep base SOC prices from becoming all-in prices, turn audits and checkups into subscriptions, make CYBERDEF and DLP support attach to existing accounts, preserve vendor leverage, use Softline distribution without surrendering margin, and make the legal entity boundary clear to customers. In other words, Infosecurity wins when it sells risk transfer as a repeatable operating service. It loses when each customer becomes a bespoke labour project dressed as a subscription.

The article's judgment is therefore explicit: Infosecurity can make managed security margin exceed labour and liability, but the advantage is conditional and operational, not structural. The public evidence supports a viable service platform with profitable reporting entities and real regulated-market demand. It does not support a complacent view that cyber-security demand alone guarantees value creation. In this business, revenue is easy to describe. Margin is earned every night an analyst does not have to solve the same problem from scratch.

Sources

  1. https://in4security.com/
  2. https://in4security.com/rekvizity
  3. https://in4security.com/licenzii
  4. https://in4security.com/soc
  5. https://in4security.com/soc/tpost/mcetx5s2p1-istoriya-uspeha-podklyuchenie-banka-k-ob
  6. https://in4security.com/soc/tpost/n0kxnc7jv1-ms-bank-rus-vnedril-servis-isoc-kompanii?amp=true
  7. https://in4security.com/cyber-checkup
  8. https://in4security.com/cyberdef
  9. https://in4security.com/cyberid
  10. https://in4security.com/cyber-resilience
  11. https://in4security.com/audit-kb
  12. https://in4security.com/dlp
  13. https://in4security.com/pentest
  14. https://in4security.com/vulnerability-management
  15. https://in4security.com/mssp
  16. https://rest.db.ripe.net/ripe/organisation/ORG-IL513-RIPE.json
  17. https://rest.db.ripe.net/ripe/aut-num/AS201144.json
  18. https://stat.ripe.net/data/announced-prefixes/data.json?resource=AS201144
  19. https://bgp.tools/as/201144
  20. https://ipinfo.io/AS201144
  21. https://www.peeringdb.com/api/net?asn=201144
  22. https://companies.rbc.ru/id/1137746423330-ooo-infosekyuriti/
  23. https://companium.ru/id/1137746423330-is
  24. https://companies.rbc.ru/id/1107746123165-ooo-infosekyuriti-servis/
  25. https://zachestnyibiznes.ru/company/ul/1107746123165_7702725949_OOO-INFOSEKYYuRITI-SERVIS
  26. https://www.osp.ru/cw/2018/03/13054038
  27. https://www.cnews.ru/news/top/2025-02-18_softline_zaplatit_271_million
  28. https://abn.agency/2025/12/24/sud-otkazal-minpromtorgu-vo-vzyskanii-subsidii-s-struktury-softline-na-87-mln-rublej/
  29. https://base.garant.ru/65748502/
  30. https://declaration.rostrud.gov.ru/declaration/index?DeclarationSearch%5Binn%5D=&DeclarationSearch%5Bregion_id%5D=10&page=775&per-page=50
  31. https://www.first.org/members/teams/
  32. https://sei.cmu.edu/license-sei-materials/authorization-to-use-the-cert-mark-for-us-entities/
  33. https://www.anti-malware.ru/analytics/Market_Analysis/Security-Operations-Center-2022
  34. https://www.anti-malware.ru/analytics/Market_Analysis/Penetration-Testing
  35. https://www.interfax.ru/business/1012128
  36. https://softline.ru/about/news/pao-softlayn-podtverzhdaet-rost-vsekh-klyuchevykh-finansovykh-pokazateley-gruppy-za-2025-god-po-itog
  37. https://softline.ru/about/news/pao-softlayn-obyavlyaet-o-roste-po-vsem-klyuchevym-pokazatelyam-po-itogam-2025-goda
  38. https://t.me/s/RuSecJobs?before=1975&q=%23soc
  39. https://www.cnews.ru/book/Softline_-_%D0%A6%D0%B8%D1%84%D1%80%D0%BE%D0%B2%D1%8B%D0%B5_%D0%A0%D0%B5%D1%88%D0%B5%D0%BD%D0%B8%D1%8F_-_Infosecurity_-_%D0%98%D0%BD%D1%84%D0%BE%D1%81%D0%B5%D0%BA%D1%8C%D1%8E%D1%80%D0%B8%D1%82%D0%B8
  40. https://infosecurity.ru/contacts