CZECH CYBERSECURITY IN 2022 ACCORDING TO THE NÚKIB1 Number of Cybersecurity Incidents in 2022 Registered by the NÚKIB In 2022, the NÚKIB received a total of 764 reports from regulated and unregulated entities under the Cybersecurity Act, 146 of which it assessed as cybersecurity incidents and subsequently addressed accordingly. Despite the significant increase in reporting by entities, there was a slight year-on-year decline in recorded incidents in 2022. 200 157 150 100 50 99 78 50 146 54 0 2017 2018 2019 2020 2021 2022 Graph 1: Number of Incidents Registered by NÚKIB One of the possible reasons for the decrease of the number of incidents is the fact that there was no major campaign in 2022 involving exploitation of a specific vulnerability on a massive scale. In contrast, 2021 saw campaigns exploiting the ProxyLogon and ProxyShell vulnerabilities targeting the widely used Microsoft Exchange Server service. Furthermore, towards the end of 2021, the Log4Shell vulnerability was discovered. To a certain extent, proactivity on the part of the NÚKIB has also decreased (in the form so-called threat hunting, where incidents are being proactively discovered), which was primarily due to personnel limitations. Broadly speaking, it is important to establish that neither the NÚKIB nor the individual entities have the ability to detect all incidents. Especially the most sophisticated types of attacks are very difficult to detect, because attackers make extraordinary efforts to remain undetected. Some organisations may also fail to properly identify a cybersecurity incident or may decide not to report a detected incident to the NÚKIB. Given the growing rate of cybercrime and incidents recorded by CSIRT. CZ, it is likely (55-70%) that the true number of incidents in the Czech Republic for 2022 is in the upper hundreds. Events related to the Russian invasion of Ukraine were also reflected in the number of recorded incidents in 2022. The highest incidence was registered in April and October, which was driven by a significant increase of DDoS attacks during both months (see Graph 2). This increase was primarily due to the attacks by Russian-speaking hacktivist groups. Killnet was behind the April DDoS campaign, while Anonymous Russia claimed responsibility for part of the October attacks. The attacks of both groups are almost surely (90-100 %) related to the Czech support of Ukraine. The presented information comes from NÚKIB sources and evaluations of 317 questionnaires (see the section About the Report). 1 7

Select target paragraph3