Director’s
Foreword
It is my great pleasure to present the Report on the State
of Cybersecurity in the Czech Republic for the past year. Let
me also thank you for your continued interest in our nation’s cybersecurity efforts.
The year 2023 was characterised by significant challenges in
the cybersecurity landscape, dominated by rises in hacktivism and cybercrime. Hacktivism, previously a less prominent issue, has surged in the context of Russia’s aggression towards Ukraine. Over the past two years, it has
evolved into a more organized and sophisticated threat.
Many hacktivist groups operate with direct support from
certain states and operate in alignment with the geopolitical interests of their governments. Consequently, the Czech
Republic has experienced a substantial increase in DDoS
attacks, bringing the total number of incidents handled by
our agency to a record 262.
Cybercriminal activity also intensified, with a notable increase in incidents reported
by the Police of the Czech Republic. The professionalization of these cybercriminals,
particularly in relation to phishing attacks, has become increasingly apparent. The use
of artificial intelligence (AI) has enhanced their ability to manipulate victims effectively, a trend that shows no signs of slowing. In response, we have strengthened our
awareness-raising initiatives in collaboration with our partners. Prevention remains
the most effective defence against phishing.
The past year also highlights a persistent and troubling interest from actors associated with the Russian Federation and the People’s Republic of China. These covert
actors have targeted Czech strategic institutions, with at least four confirmed intrusion
attempts in the past year, cyber espionage very likely being the goal.
A major concern revealed in our findings is the stagnation of cybersecurity budgets
across many organisations in the Czech Republic. This challenge is compounded by
a shortage of cybersecurity professionals, particularly within the public sector. The inability to attract, compensate, and retain these professionals under the current economic conditions threatens our nation’s ability to combat cyber threats effectively. Raising
public sector salaries to the level of the private sector may not be feasible, yet state
institutions struggle to remain competitive and lack the necessary experts to meet their
cybersecurity and IT needs, even with external contractors. If this trend continues, our
ability to maintain a secure and resilient cyberspace will be severely compromised.
To address these issues and to move forward, we must act decisively. It is .imperative to close the increasing salary gap for IT and cybersecurity professionals in the
public sector. A secure, resilient, innovative and competitive nation requires that we
invest in the people who safeguard our digital infrastructure. I firmly believe that such
investment will yield significant returns for our country.
2
Ing. Lukáš Kintr
Director of the National
Cyber and Information
Security Agency