The NÚKIB is also registering a trend of increasing persistence of attackers, who often deploy
automated methods of infrastructure creation to keep the campaign running even in the
event of proactive interventions. The sophistication of attackers is also improving, especially the
credibility of fraudulent emails and fake websites (more on this topic in the chapter: Outlook:
Cybersecurity Trends in the Czech Republic for 2023 and 2024).
Supply Chain Attacks: Low Incidence, but with High Potential Impact
In 2022, less than 6% of surveyed institutions and organizations experienced an attempt or
a successful attack through a service provider. This is an identical amount as in 2021, with
this type of attack remaining among the least frequent. This is probably (55-70%) due to the
combination of several factors, in particular the lower incidence of this attack type in the Czech
Republic in general, low detection capability on the part of organizations and significant efforts
of attackers to be undetected in the victim’s systems.
However, the NÚKIB dealt with several serious cases in May of last year that highlight the
need for a supplier management process. In one cyber incident that caused significant damage
to the victim organization, the attacker penetrated victim’s network through a compromised
VPN account of their servicing company. Two more examples of poor security measures were
discovered by organizations themselves, probably (55-70%) before attackers could exploit the
vulnerabilities. The two organisations found that their information system supplier was storing
their sensitive data on web storage without authentication.
Supplier management is one of the organizational security measures that selected entities
covered by the Cybersecurity Act are required to implement. The supplier management
process serves primarily to identify risks associated with the use of third-party services and
their subsequent mitigation.
The year-on-year comparison of the number of respondents whose organisations manage
the risks associated with suppliers shows a slight decrease (see Graph 15). Within Critical
Information Infrastructure (CII), 86% of responding organisations manage these risks.
80%
72
Yes
66
60%
40%
34
28
20%
0%
2021
2022
Graph 15: Does Your Organization Manage Supplier-Related Risks?
(Year-on-year Comparison, in % of Respondents)
19
No