
Welcome to My Blog
My name is Konstantin Starodubov. I lead information security compliance in Yandex’s fintech division. Previously, I worked at the Bank of Russia.
Here I’ll share my experience with information security, regulatory requirements, and standards — what I apply in practice and find useful.
Main Blog Topics
Fintech Compliance
Regulatory requirements, compliance verification practices, real cases from my experience.
Security Standards
ISO 27001, PCI DSS, and other standards: how to implement them so they work, not just decorate reports.
Practical Security
How to embed security requirements into development processes, find the balance between protection and convenience, measure effectiveness.
Photography
Occasionally — notes about my favorite hobby and shots from personal projects.
Upcoming Topics
In future posts I plan to cover:
- Fintech compliance: where to start and what to pay attention to
- Security standards: how to choose and implement the right one
- Practical cases from my experience at the Bank of Russia and Yandex
Opinions in this blog are my own and do not necessarily reflect the views of my employers.

