
A new line of services for monitoring and responding to cyber attacks offers protection with a financial liability of up to 30 million rubles.
AI-generated summary
Solar Group conducted a study among 100 organizations, identifying the shortage of information security specialists as the main problem of medium-sized businesses. 60% of companies in this segment do not use SIEM systems.
MOSCOW, October 5 – RIA Novosti. The Cyber Attack Center of the Solar group of companies (Solar JSOC) has launched a new line of monitoring and response services – JSOC ONE for medium-sized businesses, which will complement the existing individual service JSOC Expert for large companies, the company’s press service reports.
JSOC ONE will provide protection for small regional organizations, branches and contractors of large companies that previously did not consider the services of a classic information security center due to a lack of specialists and budget. The starting price for connection is from 3 million rubles per year. At the same time, for new tariffs, Solar is the first in Russia to introduce a financial guarantee: if the information security center misses an incident and the client suffers damage, the company will reimburse it up to 30 million rubles.
Against the backdrop of the growth and complexity of attacks, including those using AI capabilities, Solar JSOC - according to research by ICS Consulting, the first and largest commercial center for countering cyber attacks in the Russian Federation - in 2025 received 2.3 times more requests for monitoring and response services than a year earlier. And by the end of 2026, growth is expected to be 3.3 times the level of 2024. Demand from medium-sized businesses grew fastest in 2025 – 293%. For large companies this figure was 208%.
To study the reasons for these changes, Solar conducted a study at the beginning of the year that covered about 100 organizations from different sectors of the economy with staff ranging from 200 to more than 50 thousand employees. According to the data obtained, 60% of companies in the medium-sized business segment call the lack of information security specialists the main problem of cybersecurity, 80% because of this conduct monitoring only during working hours on weekdays. Among companies operating in this mode, 60% do not use a SIEM system. Three quarters (75%) of such enterprises are ready to transfer incident response to an external information security center. The average damage from encryption identified by study participants exceeds 7.5 million rubles, which significantly exceeds the costs of an information security center in the JSOC ONE format.
In large holdings and corporations the situation is different: they usually have their own monitoring centers, but they do not control the entire infrastructure - in 42% of cases, branches and subsidiaries are isolated from the main information security center. Companies in this segment (100%) are ready to outsource some of the response functions to an external provider. In this case, an external information security center can monitor a branch, subsidiary, contractor, or a separate infrastructure segment as long as it is not connected to the organization’s information security center.
In response to changing demand, Solar has developed new service packages within the Solar JSOC. The team studied the Russian and foreign markets and determined which tariffs and functions customers choose most often. The goal of JSOC ONE is to simplify the selection, connection and scaling of a service. Another goal is to change the perception of the information security center as an expensive and complex service for a select few.
At the same time, Solar is changing its approach to the responsibility of the service provider. The company is the first in Russia to stipulate the financial responsibility of the information security center for a missed incident directly in the contract. If an incident in the JSOC ONE monitoring zone was missed and the client suffered documented real damage, Solar will compensate it up to 30 million rubles. In this case, the company pays compensation directly - without the participation of the insurance company.
At the same time, the new line does not cancel the individual JSOC Expert format. In the Solar JSOC portfolio, it remains a solution for companies with complex and critical infrastructure that require custom configuration, atypical data sources and work with SIEM - Solar SIEM or supported third-party systems.
The JSOC ONE line includes two tariffs - JSOC ONE Start (from 3 million rubles per year) and Smart (from 4.4 million rubles per year). Connection takes from 1 day, and the client does not need to independently build an information security center and incur capital costs. In both tariffs, monitoring and response work around the clock. The response time to a critical incident does not exceed 30 minutes.
JSOC ONE Start is designed for companies that primarily need to protect critical endpoints (employee computers and servers). Its base is Solar EDR technologies for protecting endpoints, Solar Domain Name System DNS Radar for monitoring Internet access and blocking dangerous connections, and Solar Lighthouse for accounting for protected assets. Solar DNS Radar blocks an attempt to navigate to a suspicious resource, and Solar EDR allows you to deeply investigate the host from which the request originated. JSOC ONE Start operates in the cloud; Solar JSOC specialists monitor events on workstations and servers around the clock, respond to threats, block access to dangerous domains, and keep track of assets.
JSOC ONE Smart includes Start capabilities and adds Solar SIEM functionality, so you can collect events from different systems and monitor the entire infrastructure. The offer is also intended for companies that are building their own information security center, want to close a separate segment of the infrastructure, or receive additional expert opinion.
“Today, for the first time, protection from the flagship cyber defense center is becoming available to organizations that two years ago did not even formulate such a request. This revolutionary transformation was made possible thanks to the launch of several significant changes within the Solar JSOC. Firstly, we use our own technologies, which means that fewer external licenses and integrations are needed. Secondly, the cloud architecture eliminates the need for the client to deploy and maintain a SIEM themselves. Thirdly, automation using AI helps us quickly process the growing flow events. Finally, the modular architecture makes it possible to expand the service as new tasks arise, rather than purchasing the entire stack of capabilities at once,” said Anton Yudakov, director of the Solar JSOC Cyberattack Center, as quoted by the press service.
The combination of EDR and SIEM has a special effect. In this architecture, EDR processes events on its side and only sends alerts to the SIEM, which reduces the load on the monitoring system and reduces its performance requirements.
As a result, the information security center ceases to be a project that takes several months to launch. It can be connected as a cloud service, starting with the desired section of the infrastructure and then expanding the coverage and depth of control. The JSOC ONE cost calculator for specific customer tasks is available on the Solara website.

Specialists from the MegaFon center tested the new 5G router Vivins S150 for the first time. The device successfully passed the tests, confirming the characteristics of speed and connection stability declared by the manufacturer.

Russia is creating an intelligent system for data analysis, similar to Palantir’s Maven Smart System, said Vadim Kozyulin, chief researcher at the MGIMO Diplomatic Academy.

Expert Ilya Rybalchenko warned that the use of AI agents to clear computer memory could threaten the confidentiality of personal files. The decision to delete should be made by the user, not the neural network.

The European Union may deploy its own network of spy satellites to provide better data coverage, European Commissioner for Defense and Space Andrius Kubilius said.

The creation of an organization to regulate AI similar to the IAEA is unlikely due to the difficulties of verification, the secrecy of developments and dual-use technologies, expert Vadim Kozyulin believes.

OpenAI CEO Sam Altman told Politico that the benefits of developing artificial intelligence fully justify the risks involved, and the world must come to terms with the possible negative consequences.