
The UK and the EU have unveiled their first joint cyber sanctions package, targeting 24 individuals and entities linked to Russian state-sponsored cyber operations. The coordinated action is intended to disrupt the networks behind cyber attacks, election interference and disinformation campaigns across Europe.
The sanctions come after the UK and its allies attributed a cyber attack against Poland’s energy infrastructure to Russia’s Federal Security Service (FSB). The package also targets members of the GRU and cybercriminal groups accused of acting as proxies for the Russian state.
While the move signals closer cooperation between the UK and the EU on cyber policy, security experts say organisations should not expect the threat to diminish overnight.
"Although disrupting these hybrid networks at a diplomatic level is crucial, it doesn’t alleviate the immediate risk for corporate defenders," said Dermot Duffy, Senior Director of Engineering at Expel.
"Because state-aligned actors use automated tooling to rapidly weaponise stolen credentials and software flaws, the historical buffer window for security teams has dissolved."
The comments reflect a broader shift in the cyber threat landscape. Automated exploitation means attackers can move from disclosure to compromise in a matter of hours. That leaves organisations with far less time to assess vulnerabilities, test patches and deploy fixes.
Duffy argues that many organisations are still working to outdated timelines.
"Historically, organisations preferred to delay remediation and patching for weeks to avoid business disruption, often despite the guidance of their security teams," he said. "Today, when adversaries are aggressively targeting critical infrastructure like energy grids, that old calculus is a massive risk."
The sanctions themselves are unlikely to stop cyber operations immediately. State-backed groups often rely on distributed infrastructure, criminal affiliates and constantly evolving tactics that are difficult to dismantle through sanctions alone.
Instead, the announcement serves as another reminder that organisations cannot rely on geopolitical measures to reduce cyber risk. Strong vulnerability management, rapid patching, identity security and continuous monitoring remain essential as state-sponsored activity continues to evolve.
As Duffy concluded, "These sanctions should be treated as an urgent operational directive that the realistic timeline to respond to an exposure is no longer weeks or days, it’s hours."
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543