Outlook on cybersecurity trends
in the Czech Republic for 2024 and 2025
Cyberattacks through the supply chain
As predicted in the 2021 Report, cyberattacks targeting supply
chains have increased, affecting the Czech Republic, and are
almost certain (90–100%) to remain a highly attractive vector
for attackers.⁷
It is very likely (75–85%) that not only primary suppliers but
also secondary and tertiary suppliers will be compromised
more frequently than before. Given the sophistication required, this vector is very likely (75–85%) to be used primarily by
state actors.
Organisations heavily reliant on a single key supplier should be
particularly vigilant.
Geopolitically motivated cyberattacks
Cyberattacks against state institutions and critical infrastructure
by state actors are almost always motivated by events in the
physical world rather than mere financial gain or exploiting
weak security.
Historically, NÚKIB has observed cyberattacks by state actors
linked to the political stance of the Czech Republic or specific
events (e.g., DDoS attacks by Russian-affiliated hacktivists).
It is almost certain (90–100%) that this trend will persist, with
attackers primarily seeking to gather information. It cannot
be ruled out (25–50%) that some malicious actors will also
attempt to infiltrate networks of major organisations and
companies to exploit access for other destructive purposes in
the event of conflict.
Generative artificial intelligence and large language models
The year 2023 saw significant advancements in generative
artificial intelligence (GenAI), particularly chatbots based on
large language models (LLMs), such as the groundbreaking
ChatGPT.⁸
These AI chatbots and the products derived from them were
rapidly adopted across many types of organisations. The
methods to exploit them, such as generating phishing content or
writing malicious code, emerged just as quickly. Despite efforts
by service operators to limit the abilities of chatbots to produce
malicious outputs, the potential to bypass these restrictions
(known as jailbreaking) has consistently proved greater.
⁷
⁸
In 2024, it is almost certain (90–100%) that the use and capabilities of AI services will expand. New services will be introduced,
and the functionalities of existing ones will continue to grow. The
ability of operators to filter malicious queries is not expected to
significantly improve in 2024, and therefore an increase in attackers’ capabilities is anticipated. Specifically, a higher proportion of
generative outputs beyond text, for example images, audio, video
and deepfakes, is expected. Chatbots are increasingly incorporating these capabilities, therefore an increase in audiovisual
phishing forms, such as vishing, and other sophisticated phishing
schemes combining various formats is expected.
Worth mentioning are, for example, the compromise of authentication service provider Okta, software company JetBrains or Microsoft.
In the latter two cases, state-sponsored actors were behind the malicious activities.
Although ChatGPT was launched in late November 2022, the massive surge in its popularity can only be dated back to early 2023.
47