Avast and Utah-based website-certification company DigiCert suspend sales in Russia
Thomas Brewster / Forbes : Tweets: @iblametom , @iblametom , and @iblametom Tweets: Thomas Brewster / @iblametom : The second one here is significant - it could push Russia to taking more control over authenticating websites, which would come with some, err, interesting ramifications for surveillance in the country. https://twitter.com/... Thomas Brewster / @iblametom : NortonLifeLock confirmed it is suspending sales too fwiw. ESET had previously announced it was out. Kaspersky set for a boost in business at home? https://twitter.com/... Thomas Brewster / @iblametom : NEW - Two major security companies are suspending sales in Russia. First, Avast, the $6 billion antivirus business that has a large presence in the country and in Ukraine. The other is DigiCert, one of the world's biggest website certificate authorities. https://www.forbes.com/...
Context & Ripple Effects
This lands mid-wave: days after Activision Blizzard and Epic Games pulled their games from Russia, the consumer-security tier follows — Avast and DigiCert now out, with NortonLifeLock confirming its own suspension and ESET having already announced its exit. The security-vendor retreat matters more than the game publishers' because it touches trust infrastructure, not entertainment.
The pressure point already exists: as sanctions cut Russian sites off from renewing Western-issued certificates, Moscow stood up its own trusted TLS certificate authority. Brewster's reporting flags the stakes — if foreign certifiers leave, Russia takes over authenticating its own web, with obvious surveillance upside for the state.
First-order effects
- Russian consumers lose paid access to Avast, NortonLifeLock, and ESET overnight, leaving Kaspersky as the dominant domestic option — the reporting explicitly frames it as 'set for a boost in business at home.'
- DigiCert's exit means new Russian customers can no longer buy TLS certificates from one of the major Western CAs, compounding the renewal freeze that pushed Russian sites toward the national authority.
Second-order effects
- With Western CAs and AV vendors gone, demand consolidates behind the state-built certificate authority and Kaspersky, moving both website authentication and endpoint security under institutions the Kremlin can reach.
- The exit sets up the mirror-image move seen later abroad: the US Commerce Department's ban on Kaspersky antivirus sales and Treasury's sanctions on 12 Kaspersky executives show each side purging the other's security vendors.
Third-order effects
- Trust infrastructure is bifurcating into parallel stacks — Western CAs and AV on one side, a Russian state CA and domestic vendors on the other — so a site's or user's 'trusted' status depends on which bloc issued it.
- If the pattern holds, security software and certificate issuance become instruments of sanctions policy on both sides, ending the era when either country's users could assume globally shared roots of trust.
The trend: Geopolitical decoupling is splitting consumer security and web-trust infrastructure into separate Western and Russian ecosystems, with each side's vendors exiting the other's market.