SUMMARY OF THE 2020 REPORT ON CYBER SECURITY IN THE CZECH REPUBLIC The year 2020 was marked by an increase in cyberattacks against Czech institutions, organisations, and companies across all sectors. Compared to 217 inci­ dents in 2019, a total of 468 incidents were reported to the NÚKIB in 2020. Nearly one-third of the incidents handled were reported by non-regulated entities. This increase was very likely caused by both a higher number of cyberattacks and greater awareness of the existence and activities of the NÚKIB. The severity of the incidents has also increased, which is evident from the attacks against the University Hospital Brno and the Psychiatric Hospital in Kosmonosy. The most frequent types of at­ tack in 2020 included spam, phishing, and scanning. intended for sharing legislative, strategic, and other 5G network security tools the countries adopted over the past year. The most serious cyber threats in the Czech Republic have long included cybercrime. In 2020, this was most visible with ransomware attacks affecting the Czech healthcare sector. The increase in attacks against hos­ pitals can largely be attributed to the ongoing pandemic as well as cybercrime groups concentrating on specific institutions where they see a higher chance that the ransom will be paid. Yet three-quarters of healthcare facilities consider the funds allocated to ensuring cyber security insufficient. Many organisations questioned through the survey said they faced a lack of experts and insufficient cyber security budgets in 2020. The situation was more pronounced in the public sector than in private undertakings. Almost none of the respondents had all cyber security posts occupied. More than half the organisations considered insufficient salaries to be the main factor. In 2020, the NÚKIB, in cooperation with the Office of the Government and the Ministry of Foreign Affairs, organised the second two-day Prague 5G Security Conference, the world’s premier forum for discussion of the risks associated with the building of 5G infra­ structure. As last year, the conference was held under the auspices of Andrej Babiš, the Prime Minister of the Czech Republic. Despite the fact that the conference was virtual for the first time due to the COVID-19 situ­ ation, more than 50 speakers from Europe, the USA, South Korea, Israel, Australia, India, and other countries spoke at it. The main outcome of this second confer­ ence was the presentation and launching of the socalled Prague 5G Security Repository, a virtual library In 2020, the NÚKIB continued the training of public administration staff and trained more than 18‚209 civil servants, 214 employees of the Armed Forces of the Czech Republic, and 2‚000 employees of Bulovka Hospital in the ‘Dávej kyber!’ [Get Cyber Skilled!] e-learning course. Another 1,690 prevention officers were trained in the professional ‘Bezpečně v kyber’ [Stay Safe in Cyberspace] course, which presents school envi­ ronment situations to staff. In response to events during the pandemic, the NÚKIB issued several recommendations, warnings, and reactive measures. These included, for example, warn­ ings about the risks associated with online conference services, Safe Remote Working recommendations, the Secure Videoconferencing manual, and the Minimum Safety Standard document for securing smaller organ­ isations prepared in cooperation with NAKIT. Despite the pandemic measures, Cyber Coalition – the international cyber defence exercise organised by the North Atlantic Treaty Organisation – took place in 2020, for the first time in virtual form. The Czech Republic thus again contributed as much as possible to one of the largest international cyber defence exercises. Summary of the 2020 Report on Cyber Security 3

Select target paragraph3