Healthcare: Ransomware Remains a Relevant Threat The number of registered incidents within the healthcare sector increased slightly year-onyear by 3, to a total of 29 incidents. However, the NÚKIB registered a higher number of minor incidents in the healthcare sector and a 50 percent reduction in the category of significant and very significant incidents. According to respondents, there was a slight year-over-year increase in the number of organizations experiencing an attempted ransomware attack, by two percentage points. Ransomware thus remains a relevant threat to a quarter of healthcare organizations even after the end of the covid-19 pandemic (see Graph 22). 35% 29 30% 25% 25 23 20% 15% 10% 5% 0% 2020 2021 2022 Graph 22: S hare of Healthcare Sector Respondents whose Organizations Experienced a Ransomware Attack Attempt (Comparison 2020-2022 in %) In terms of severity of different types of cyberattacks, ransomware was rated by respondents from the healthcare sector as less serious than phishing and spear-phishing attacks or fraudulent emails, which also accounted for the majority of recorded attacks. Despite the perceived severity and the frequency of these attacks, only a third of healthcare respondents test the resilience of their staff with simulated phishing campaigns, while more than half of respondents do not test them at all (see Graph 23). 60% 55 50% 40% 34 30% 19 20% 10% 5 14 0% No tests Simulated phishing campaigns Penetration tests Technical or non-technical exercises Other Graph 23: Do you Test the Resilience of your Staff Against Cyber Threats? (% of Respondents) The reason for this deficiency is probably (55-70%) the long-term unsatisfactory cybersecurity funding levels in healthcare, with more than 70% of respondents assessing the level of the budget in this field as insufficient. The situation can be further demonstrated by a comparison of cybersecurity budgets in healthcare compared to other sectors, which shows that healthcare entities on average allocate lower budgets than the cross-sector average (see Graph 24). 26

Select target paragraph3