EU and UK sanction Russian cyber actors

The EU and the UK have issued statements announcing sanctions against a number of Russian nationals and entities, including GRU leadership and individuals behind Lumma Stealer. The statements also attribute the infiltration of government networks and sabotage of critical infrastructure in multiple EU member states to Russia and Russia-affiliated third parties.

What this means for your organisation

When sabotage of critical infrastructure is attributed to a state actor at this level, the threat picture moves from the IT department to the boardroom. For organisations in scope of NIS2 this means the board carries an independent duty to understand the exposure, and that resilience planning must be sized for scenarios where the adversary is not after money but after disruption. Sanctions also have a practical dimension: you need to know whether any of your suppliers or ownership interests are affected.

Berigo recommends

  • Put the state actor threat picture on the board agenda as its own item, not a line in the IT report.
  • Screen the supply chain against current sanctions lists, and repeat the screening when they are updated.
  • Exercise a scenario involving prolonged loss of a critical service with no ransom demand and no counterparty to negotiate with.
  • Clarify who in the organisation notifies the authorities, and how quickly, if you suspect state activity in your own systems.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch