TARGETS OF CYBERCRIME ATTACKS Critical Information Infrastructure: Increase of Attacks on Availability of Services As in previous years, critical information infrastructure (CII) entities were exposed to cyberattack attempts during 2022. The number of incidents registered by the NÚKIB in this category almost doubled. This is a significant increase, which was probably (55-70%) due to the increase in DDoS and other service availability attacks, which made up the majority of recorded incidents in this category. The share of incidents that resulted in a disruption of availability of services remained about the same year-on-year, but in nominal terms, the number of incidents increased by about 70%. For CII, disruption of availability can have major consequences (see Box). According to Section 2(b) of the Cybersecurity Act, CII is an element or a system of critical infrastructure elements in the sector of communications and information systems in the field of cybersecurity. Pursuant to Section 2(g) of Act No.240/2000 Coll., on Crisis Management and on Amendments to Certain Acts (the Crisis Act), as amended, critical infrastructure is defined as an element of critical infrastructure or a system of elements of critical infrastructure, the disruption of which would have a serious impact on national security, basic needs and welfare of the population, or national economy. Typical elements of critical infrastructure include power plants, dams, airports, and telecommunications networks, but also strategic financial institutions and government agencies. Disabling any of these elements may paralyse the delivery of critical services (e.g. electricity, heat, water, or pension payments) and, in extreme cases and in the event of targeted cyber sabotage, cause even physical damage. On the positive side, despite the increase in the number of attacks, there has been a year-onyear improvement in the speed of incident resolution within the CII. In two thirds of incidents, systems were restored into full functionality within hours from compromise, with no incident taking more than a week to resolve (see Graph 17). 40% 37 30% 20% CII 27 27 20 23 17 17 10 10% Other subjects 7 10 6 0 0% Immediately Within minutes Within hours Within a day Within a week Within a month Graph 17: Average Time from Cyber Incident Identification to its Resolution (% of incidents) 22

Select target paragraph3