Sanctions have long been used as a geopolitical wrist-slapping tool, with the efficacy of its effects on a country’s ability to trade, build and conduct business arguably up for debate. But, how do they work with regards to cyber and nation-state actors?
The Royal United Services Institute (RUSI), a long-established London-based defence and security think-tank, convened the Cyber Sanctions Taskforce to examine just this.
A new insight paper, reporting on that first meeting of the Cyber Sanctions Taskforce, recognises sanctions as an instrument for countering state-backed cyber threats, but stressed that their practical effect is uneven unless measures are better targeted, sequenced and integrated into broader national strategies (don’t worry, it goes into more detail than that).
The first meeting of the RUSI Cyber Sanctions Taskforce brought together current and former officials from the UK, US and EU, sanctions and cybersecurity researchers and private-sector experts to assess how restrictive measures are being used to expose, disrupt and impose costs on malicious cyber actors.
Sanctions as part of a new cyber toolkit
Malicious, state-enabled cyber activity and organised criminal ransomware campaigns have become recurring features of international insecurity. In response, sanctions have emerged as “one of the principal tools available to governments seeking to expose and disrupt malicious cyber operations and impose costs on the perpetrators,” the paper reporting the taskforce meeting states.
Yet the effectiveness of sanctions remains contested: while some argue that listings have limited direct bite because many targets hold no assets in Western jurisdictions, others pointed to important indirect effects, including disruption of enabler networks, reputational damage and pressure on third-party intermediaries.
The taskforce emphasised that sanctions are most useful when embedded in cross-domain strategies that combine diplomatic initiatives, law-enforcement action, technical advisories and, where appropriate, covert measures.
In that context, the objective is not to prevent every intrusion – which would be unrealistic given the deniable and persistent nature of most malicious activity – but to make hostile operations slower, riskier and less rewarding.
The US model: naming individuals and sequencing measures
The United States has built the most sustained practice of cyber-related sanctions since 2015, according to the report.
A defining feature of the US approach has been the emphasis on naming individuals rather than only groups or networks. Taskforce participants argued that identifying people provides a persistent target for reputational and operational pressure and supports follow-on action, such as criminal indictments or asset freezes.
“Designations that are issued in isolation are understood to have limited effect, but when they form part of a wider campaign, they generate friction across adversary ecosystems and reinforce diplomatic messages to partners and third countries alike,” the meeting paper notes.
Officials and former officials speaking at the taskforce described how the US frequently sequences sanctions alongside indictments, public technical advisories and diplomatic activity to amplify their effect.
This layered approach does not always stop hostile activity outright, but it can change tactics, introduce delays and raise costs for adversaries.
The report highlighted that outcomes vary by actor type: some state intelligence officers are insulated by domestic praise or protection, while others – and criminal groups in particular – have seen meaningful disruption to their operations when sanctions are coordinated and enforced.
The EU’s cautious route: signalling more than disruption
The EU’s cyber sanctions framework, launched in 2019, is horizontal in design and intended to be applied globally to both state and non-state actors. In practice, however, the regime has been used sparingly.
The paper points out that only a limited number of designations have followed the regime’s adoption, a pattern shaped by the practical need for unanimity among 27 member states and the political difficulty of sharing sensitive intelligence widely. That consensus requirement, delegates argued, tends to slow the EU’s ability to act rapidly and limits the amount of evidence that is made public.
For many member states, EU cyber listings function as a diplomatic signal: a collective way to express concern and to align strategically without single governments taking on the full political risk of attribution.
The report suggests that this makes the EU approach effective for signalling and reinforcing narratives, but less reliably a means of direct operational disruption – particularly where companies or intermediaries lack clear public guidance on how to enforce listings.
The UK’s position: coordination and practical detail
Since leaving the EU, the UK has developed its own autonomous sanctions framework that policymakers say is designed to work closely with allies.
UK officials at the taskforce argued that unilateral sanctions rarely achieve much on their own and that measures are most effective when coordinated with partners, especially the US, whose financial system and enforcement reach can add weight to designations.
The UK has tried to make its listings more detailed to help private-sector actors understand the context and to encourage industry to withdraw services from sanctioned individuals or entities.
A specific constraint for the UK is the difficulty of pairing designations with criminal indictments. The high evidentiary threshold required by the Crown Prosecution Service makes prosecutions of foreign intelligence officers or overseas cybercriminals uncommon, so sanctions in the UK context are often framed as instruments of attribution, business disruption and diplomatic signalling rather than as a direct path to law-enforcement action.
What sanctions can realistically achieve
Participants agreed that the value of sanctions should be judged against realistic, narrowly defined objectives. Rather than expecting complete deterrence, policymakers should evaluate whether measures impose friction, increase costs and shape decision-making in ways that change adversary behaviour at the margins.
The taskforce noted that sanctions tend to have the greatest operational effect when they target enablers – financial and technical intermediaries, contractors, or third-party service providers – because these actors are more exposed to reputational and financial disruption.
The paper points to cases in which exposure and coordinated action have damaged criminal brands and made monetisation harder.
Such outcomes – described in the report through the example of groups whose ecosystems fractured after public designation – illustrate how sanctions can “toxify” entities, forcing affiliates away and prompting rebranding. But the report is also clear that effects vary widely and that evidence gaps, especially in the EU, complicate systematic assessment of impact.
Policy priorities: clearer goals, better coordination, and measurement
The taskforce concluded with a set of practical priorities for policymakers.
First, governments should be explicit about the behaviour they intend sanctions to change so measures can be precisely targeted and evaluated.
Second, sanctions need to be embedded in cross-domain strategies that include diplomacy, law enforcement, intelligence and technical disruption.
Recommended reading
- Report: Supply Chain Attacks a ‘Daily Reality’ As Vendor Security Lags
- Chief Supply Chain Officers: Overly Confident or Undervalued?
- Less Than A Quarter of Supply Chain Leaders Have An AI Strategy
- New Report Reveals Extent of Cyber-risk in Global Supply Chain
Third, the focus should shift from solely naming perpetrators to also targeting enabling ecosystems – cryptocurrency exchanges, technology suppliers and intermediaries – where sanctions are likelier to bite.
Fourth, transparency matters: public indictments and technical advisories increase the value of designations by equipping private sector actors to act.
Finally, international coordination is essential to prevent circumvention and to maximise the political signal of collective action.
The paper calls for better methodologies to monitor both direct and indirect impacts of sanctions so that policy can be adapted on the basis of evidence. Without systematic evaluation – on whether assets have been frozen, services withdrawn, or operational tempo reduced – officials and industry alike will struggle to judge whether measures are substantive or merely symbolic.
The RUSI Cyber Sanctions Taskforce report makes clear that sanctions are now an established part of statecraft in the cyber domain across the US, EU and UK. Used strategically and in coordination with other instruments, sanctions can complicate hostile operations, raise costs, disrupt enabling infrastructures and signal collective resolve.
Yet the taskforce’s first meeting also underlined the limits of current practice: without clearer aims, better sequencing, focused targeting of enablers and more transparent monitoring, sanctions risk being more performative than practical.





