Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Security in Yandex Cloud
  • Key security features
  • Division of responsibility for security
  • Compliance
  • Security measures on the Yandex Cloud side
  • Security tools available to cloud service users
    • All recommendations
    • IaaS security checklist
    • Authentication and authorization security checklist
    • Ransomware attack prevention checklist
    • Kubernetes security
    • Reference architecture for cloud infrastructure in isolated mode without internet access
  • User support policy during vulnerability scanning
  • Security bulletins
  • Public IP address ranges

In this article:

  • Severity levels
  • Multi-factor authentication for privileged accounts is in place
  • Yandex ID accounts are used only in exceptional cases
  • Service account keys are periodically rotated
  • Disk and database backups are in place
  • Last service account authentication date and last use of access keys date are tracked
  • Object Storage has Object Lock enabled
  • Yandex Audit Trails is enabled
  • Service accounts have minimal privileges
  1. Best practices for securing your cloud infrastructure
  2. Ransomware attack prevention checklist

Ransomware attack prevention checklist

Written by
Yandex Cloud
Updated at August 5, 2026
View in Markdown
  • Severity levels
  • Multi-factor authentication for privileged accounts is in place
  • Yandex ID accounts are used only in exceptional cases
  • Service account keys are periodically rotated
  • Disk and database backups are in place
  • Last service account authentication date and last use of access keys date are tracked
  • Object Storage has Object Lock enabled
  • Yandex Audit Trails is enabled
  • Service accounts have minimal privileges

This section presents security requirements for protection of your Yandex Cloud infrastructure against ransomware attacks. Ransomware is one of the most common and destructive types of cyberattacks: attackers encrypt the victim's data and demand a ransom for recovery. In cloud environments, ransomware attacks can affect object storages, virtual machine disks, databases, and backups.

Each requirement has a severity level, link to relevant rules in the Yandex Security Deck Cloud Security Posture Management module (CSPM), and link to relevant section of the Yandex Cloud infrastructure protection standard.

Severity levelsSeverity levels

Severity Description
High Prioritized resolution. Significantly increases resistance to attack.
Medium Recommended for implementation. Reduces attack surface.
Low Additional security measure.
Informational Recommendation to increase maturity.

Multi-factor authentication for privileged accounts is in placeMulti-factor authentication for privileged accounts is in place

Severity Yandex Cloud standard requirement Rule in Security Deck
High IAM17 cspm.access.userpool-mfa

Accounts with privileged roles, such as admin, editor, resource-manager.admin, and similar must use multi-factor authentication (MFA). A compromised privileged account without MFA allows the attacker to gain immediate access to all the organization's resources and delete backups before running encryption.

Yandex ID accounts are used only in exceptional casesYandex ID accounts are used only in exceptional cases

Severity Yandex Cloud standard requirement Rule in Security Deck
High IAM3 cspm.yid.organization

Personal Yandex ID accounts are not managed by corporate security policies: you cannot force MFA, set a password policy, or revoke access centrally. Use federated accounts through Yandex Identity Hub for access to cloud resources. Yandex ID accounts are only permissible for technical purposes (e.g., initial organization setup) and must be documented as exceptions.

Service account keys are periodically rotatedService account keys are periodically rotated

Severity Yandex Cloud standard requirement Rule in Security Deck
High IAM11 cspm.iam.sa-key-rotation

Static access keys for service accounts must be regularly rotated. The recommended rotation period is at least once every 90 days. Keys without an expiration date increase the window of opportunity for attackers if leaked.

Whenever possible, use ephemeral keys or temporary tokens via Yandex Security Token Service instead of static keys.

Disk and database backups are in placeDisk and database backups are in place

Severity Yandex Cloud standard requirement Rule in Security Deck
High ENV37 cspm.backup.compute-disks

Automatic backups must be in place for all critical resources:

  • VM disks. Use Yandex Cloud Backup or a snapshot schedule. Recommended frequency: daily. Retention period: at least 14 days.
  • Managed databases (MDB). Make sure automatic backups are enabled and retention period is at least 14 days.
  • Backup storage. It is recommended to store backups in a separate folder with limited access. Ideally, in a separate cloud organization or outside it.

Last service account authentication date and last use of access keys date are trackedLast service account authentication date and last use of access keys date are tracked

Severity Yandex Cloud standard requirement Rules in Security Deck
Medium IAM26 cspm.iam.unused-service-account
cspm.iam.unused-key

Unused static access keys and service accounts that have not been authenticated in a long time present a risk: attackers can use forgotten credentials to gain access. We recommend tracking the dates of last service account authentication and last use of access keys. Delete or deactivate keys and accounts unused for more than 90 days.

Whenever possible, use ephemeral keys or temporary tokens via Yandex Security Token Service instead of static keys.

Object Storage has Object Lock enabledObject Storage has Object Lock enabled

Severity Yandex Cloud standard requirement Rule in Security Deck
Medium ENV9 cspm.s3.used-object-lock

Object Lock is a mechanism that protects Yandex Object Storage objects against deletion and overwriting for a specified period. With Object Lock on, the attacker who gains access to the bucket will not be able to delete or modify protected objects until the lock expires. The recommended minimum lock period is 30 days. Object Lock only works when bucket versioning is on.

Yandex Audit Trails is enabledYandex Audit Trails is enabled

Severity Yandex Cloud standard requirement Rule in Security Deck
Medium AUDIT1 cspm.o11y.audit-trails

Audit Trails logs all management actions with cloud resources: resource creation and deletion, access permission changes, operations with keys, etc. Audit Trails must be enabled at the organization or cloud level and configured to log events to a secure Object Storage bucket (with Object Lock on) or log group. The actual log bucket must be deletion-protected.

Service accounts have minimal privilegesService accounts have minimal privileges

Severity Yandex Cloud standard requirement Rules in Security Deck
Informational IAM9 cspm.access.sa-privileges-org-roles
cspm.access.sa-privileges-service-roles

Service accounts with excessive privileges (e.g., with the editor or admin role at the organization or cloud level) are targets of choice for ransomware: if compromised, an account like that allows the attacker to delete all backups and encrypt data. Assign to service accounts only the roles they need to perform their functions, and only at the proper level of the resource hierarchy (for folder, not cloud).

Was the article helpful?

Previous
Authentication and authorization security checklist
Next
Kubernetes security
© 2026 Direct Cursus Technology L.L.C.