
The EU now has the ability to impose sanctions on hackers and their supporters, freezing their assets and banning them from entering the EU. The new legal regime, which came into effect in May, has been welcomed by politicians, including Foreign Secretary Jeremy Hunt.
But is it a practice that can pay off? A survey conducted by Computer Business Review, asking various business sectors, yielded mixed results.
Bridewell Consulting director Anthony Young said he considered the legal regime in question a very good step for businesses, as until now there was no substantive law protecting them from cybercriminals .
Matt Aldridge, Senior Solutions Architect at Webroot, told Computer Business Review that while the initiative has good foundations, there are serious questions that need to be taken seriously, such as how culpability will be verified to the point where the EU Council can be certain enough to impose sanctions on an individual.
He added: “Blame on any cyberattack is extremely difficult to attribute and serious threat actors take care to cover their tracks, hide their identities and even manage to appear as if they are someone else.”

Aldridge expressed concerns that the EU could potentially shift responsibility to ethical hackers or organizations, leaving a false trail that could lead the EU union to the wrong people.
Laurie Mercer, a security engineer at HackerOne, told us that while most initiatives designed to reduce the threat of malicious actors online should be welcomed, they may hinder the work of ethical hackers.
Dave Klein, senior director of engineering and architecture at Guardicore in Tel Aviv, was not particularly enthusiastic about the new legislation. He said that if the main requirement is to protect the EU’s critical infrastructure, as this article suggests, then this will do very little.
Malicious actors operating at a national level often work with the most sophisticated tools and are very adept at hiding their tracks and leading security experts in the wrong direction.
Klein concluded that any attempt to deal with this type of criminal would prove extremely difficult.
There are of course some cases where hackers involved in attacks on well-known businesses have been discovered and arrested.
However, whether the EU's enhanced legislative powers are sufficient to prevent the undermining of EU infrastructure remains an open question: one that most agree is unlikely.
