Classification of cyber incidents reported to NÚKIB 2 Percentage of representation in incidents 2022 2023 58 % ↗ 64 % Availability Intrusions 12 % ↗ 14 % 10 % ↘ 9 % Information security Malicious code 8% → 8% 11 % ↘ 2 % Fraud Intrusion attempt Other Information Gathering Offensive content 0% ↗ 2% 3% ↘ 2% 0% ↗ 1% 0% → 0% Availability - Availability disruption caused by DoS/DDoS attacks or sabotage Intrusions - Compromising of applications or user accounts Information security - Unauthorized data access, unauthorized data modification Malicious code - Viruses, worms, Trojan horses, dialers or spyware Fraud - Phishing, identity theft or ICT unauthorized use Intrusion attempt - Vulnerability exploitation attempts, login attempts etc. Information Gathering - Scanning, sniffing, social engineering Visualization 2: Classification of cyber incidents reported to NÚKIB In terms of incident classification, incidents targeting the availability of websites or services were dominant in relation to the high number of observed DDoS attacks. This category also includes incidents caused by technical errors leading to system failures.³ The second largest category was intrusions, mainly consisting of social engineering attacks, most often in the form of phishing, leading to the compromise of email or other accounts. The third most frequently recorded incident category was information security, ransomware attacks being prevalent. ² Classification of cyber incidents is based on ENISA taxonomy: Reference Incident Classification Taxonomy – ENISA (europa.eu) ³ Under the provisions of the current Act on Cybersecurity, regulated entities are required to report all cyber incidents, i.e., information breaches in information systems, security breaches in services or security breaches in the integrity of electronic communications networks due to a cybersecurity incident. 14

Select target paragraph3