14/05/2020 (Agence Europe) – On Thursday 14 May, the Council of the EU adopted a decision to extend the framework for restrictive measures against cyber attacks for a year, until 18 May 2021 (see EUROPE 12257/9). The sanctions regime, which was adopted in May 2017, does not currently include any listings. It allows the EU to impose targeted restrictive measures on persons or entities involved in cyber-attacks which cause a significant impact, and constitute an “external threat” to the EU or its Member States. In its communiqué, the Council of the EU stated that measures may also be adopted to deal with cyber-attacks against third states or international organisations where such measures are considered necessary to achieve the objectives of the Common Foreign and Security Policy. Sanctions may also be imposed for attempted cyber-attacks if they have “significant potential impacts”. (CG)