Executive Summary • In 2022, there was a slight decrease in cyber incidents recorded by the NÚKIB from 157 to 146. However, the Police of the Czech Republic recorded an almost twofold increase in cybercriminal activities. The activities of state-sponsored cyber actors and cybercriminal groups continue to represent the greatest threat to the Czech Republic‘s cyber security. • Various types of phishing, spear-phishing, vishing, and fraudulent e-mails or attacks on availability, mainly in the form of DDoS attacks, were among the most common types of attacks during the past year. On the other hand, there was a lower incidence of vulnerability exploitation and ransomware attacks. Nevertheless, they continue to represent a relevant threat. The NÚKIB also recorded several incidents related to the invasion of Ukraine. • The majority of cyber incidents registered by the NÚKIB occurred in the public sector, followed by the healthcare and private sectors. The NÚKIB also recorded a significant, nearly twofold, increase in incidents within the critical information infrastructure, the majority of which constituted attacks on availability of services. • During 2022, the NÚKIB issued a total of 16 alerts and 3 warnings in response to current threats or vulnerabilities. Some of the warnings were directly related to the risks resulting from the Russian invasion to Ukraine. • A significant part of the NÚKIB‘s 2022 agenda consisted of preparations for and implementation of the Czech Presidency of the Council of the European Union (hereinafter “CZ PRES“). Cooperation on the new NIS 2 Directive, which was adopted during the CZ PRES, was particularly significant. The NÚKIB worked intensively with EU and NATO partners to promote cybersecurity and develop international cooperation beyond CZ PRES as well. • A highly important process in terms of cybersecurity at the national level, which began in 2022, is the drafting of a new cybersecurity law, which is closely related to the aforementioned NIS 2 Directive. As part of the preparations for this legislative change, which is expected to take effect in autumn 2024, five internal expert groups were established in which over 40 NÚKIB employees prepared a draft of the new Cybersecurity Act and its implementing regulations. • Last but not least, the NÚKIB was also intensively involved in awareness-raising activities and held cyber exercises. A large part of awareness-raising projects took place within the education sector. Their main objective was to raise awareness of current cyber threats and create conditions for the education of future experts in the field of cybersecurity. During the year, seven domestic and three international cybersecurity exercises took place, including a sector-focused Health Czech exercise for healthcare sector organisations. 2

Select target paragraph3