SUPERVISORY ACTIVITIES OF THE NÚKB IN 2022 Audit and inspection activities carried out by the NÚKIB in 2022 were particularly affected by the escalation of the global geopolitical situation. Therefore, the NÚKIB focused its audit and inspection activities, among other things, on the most critical state administration systems, auditing their business continuity management.7 In addition, a tailored table-top exercise covering this area was offered and delivered to the aforementioned organisations. A total of 20 audits and inspections were carried out in 2022 in accordance with Decree No. 82/2018, on security measures, cyber security incidents, reactive measures, filing requirements in the field of cybersecurity and data disposal (Cybersecurity Decree), as amended. As a part of a routine inspection and audit, approximately 150 control points are inspected, while four to six NÚKIB staff members are involved in this activity, depending on the size of the entity, the complexity of the systems being audited, and other conditions requiring specific expertise or personnel of the NÚKIB. Typical inspection or audit takes approximately two to three months from start to finish. The Most Frequent Shortcomings Identified During Inspection and Audit The cybersecurity assurance system in place does not meet the requirements of interested parties; Entities do not sufficiently manage resources and risks related to cybersecurity; Security policies and documentation are not put into practice or are not being updated; Entities do not sufficiently manage risks related to suppliers; Use of out-of-date hardware and software which is no longer supported by manufacturers and lack management of related risks; Shortage of cybersecurity experts; Insufficient education of employees and persons responsible for cybersecurity; Improper segmentation of communication network. 7 Business continuity – readiness to react to critical situations and ability to minimise eventual effects of such a situation. 36

Select target paragraph3