Ukraine data protection

Russia's Data-Center Seizure Decree Is Nationalization Risk Dressed Up as Drone Defense

Putin's Aug. 24 decree lets Moscow seize 'unprotected' data centers indefinitely — a warning for how not to regulate critical infrastructure.

Russia's Infrastructure-Seizure Decree, By the Numbe… People of Internet Research · Ukraine 181 Data centers nationwide Russia had 181 data centers as of … ~80% Capacity in drone range Most Russian data-center capacity … Aug 24, 2026 Decree signed and effective Decree No. 604 took effect immedia… Jul 17, 2026 EU critical-entity ID deadline The EU's CER Directive set a stand… peopleofinternet.com
Russia's Infrastructure-Seizure Decree… People of Internet Research · Ukraine 181 Data centers nationwide ~80% Capacity in drone range Aug 24, 2026 Decree signed and effective Jul 17, 2026 EU critical-entity … peopleofinternet.com

Key Takeaways

The Decree

On August 24, 2026, Vladimir Putin signed Decree No. 604, "On Measures to Ensure the Security of Critical Infrastructure Facilities of the Russian Federation." It lets the state place a facility under temporary management — with no fixed time limit — if its owner fails to implement required security measures, is slow to repair damage, or otherwise leaves the site "inadequately protected," including against drone attacks (TASS). Rosimushchestvo, the federal property agency, or another entity the government names, can then take over the facility's property and operations.

Data centers were not previously classified as critical infrastructure in Russia, but operators have been told the decree applies to them too, especially facilities hosting government, banking, and major service-provider systems (The Record). Russia has 181 data centers, and more than 80% of that capacity sits in the country's European region — Moscow and St. Petersburg above all — squarely inside the range of Ukraine's long-range drone campaign (Risky Business News). Operators are now racing to harden generators, cooling systems, and exposed engineering equipment before an inspector decides they haven't done enough.

The Real Problem It Responds To

It's worth stating the case for concern plainly, because it's genuine. Data centers were engineered for uptime and cybersecurity, not for withstanding loitering munitions, and a strike on a facility hosting banking or government workloads doesn't just knock out one company — it cascades through everyone who depends on that cloud. Ukraine has lived this itself: a July 2026 strike damaged a major Kyiv data center and forced several local ISPs to fully or partially suspend service, and a January cyberattack on the Parkovyi facility disrupted operations for multiple state-linked clients (The Record). A state pushing operators to invest in physical resilience during a war is not, on its face, unreasonable.

Why Coercion Isn't Regulation

But a security mandate and an open-ended expropriation power are not the same instrument, and Decree No. 604 is written as the second. "Adequate protection" is undefined, the government decides case by case, there is no judicial review specified, and the decree sets no end date on state management once imposed. That combination turns a physical-security rule into a discretionary lever the Kremlin can pull against any operator — Russian or foreign-owned — it wants to control, with drone risk as the pretext. Given that Moscow has already used similar "external administration" tools against departing Western companies since 2022, operators have good reason to read this as an asset-control mechanism first and a hardening mandate second.

That distinction matters for outcomes, not just optics. A rule that says harden your cooling systems by this date or face a fine gives an operator a predictable target to invest against. A rule that says harden your systems, and a government agency will later decide, retroactively and without a deadline, whether it was enough gives an operator every incentive to under-invest in visible compliance and over-invest in political relationships instead — the opposite of resilience.

The Alternative Ukraine and the EU Are Building

The contrast is closest at hand. Ukraine's own critical-infrastructure framework — cyber-protection rules dating to a 2019 Cabinet resolution, updated by a 2025 cybersecurity law aligning with the EU's NIS2 standard — runs through the State Service of Special Communication and Information Protection (SSSCIP), which sets baseline requirements, audits against them, and coordinates incident response through CERT-UA (SSSCIP CSIRT). It is a country under active bombardment, and it has still built its critical-infrastructure rules around fixed standards and a regulator, not an unbounded seizure clause.

The EU's Critical Entities Resilience Directive (2022/2557) is the sharper comparison because it targets the exact same physical-security gap Moscow claims to be closing. It requires member states to identify critical entities, including digital infrastructure, and mandates that those entities run risk assessments and adopt technical and organizational resilience measures — with a compliance deadline, a named competent authority, and support obligations running the other way, from state to operator (EUR-Lex, Directive 2022/2557). Nowhere in its text does the CER Directive grant a government the power to seize a facility's assets. Security and control are treated as separate problems, because conflating them corrodes trust in exactly the operators a state needs to invest more, not less.

Why This Matters Beyond Russia

For a policy outlet arguing for proportionate, evidence-based regulation, Decree No. 604 is a useful negative case study. Wartime physical-security requirements for data centers are defensible; a discretionary, indefinite seizure power layered on top of them is not a security measure, it's a nationalization tool wearing a hard hat. Governments elsewhere weighing how to harden their own digital infrastructure against physical or cyber threats — the EU under the CER Directive, Ukraine under its own wartime standards, or any state watching drone and cyberattack risk migrate onto their networks — have a live example of the model to avoid, sitting right across the border.

Sources & Citations

  1. The Record: Russian data centers face new security requirements
  2. TASS: Putin signs decree on critical infrastructure protection
  3. Risky Business News: Russia tells data centers to deploy drone defenses
  4. EUR-Lex: Directive (EU) 2022/2557 on critical entities' resilience
  5. SSSCIP CSIRT: Ukraine regulatory and legal framework