Outlook on cybersecurity trends in the Czech Republic for 2024 and 2025 Cyberattacks through the supply chain As predicted in the 2021 Report, cyberattacks targeting supply chains have increased, affecting the Czech Republic, and are almost certain (90–100%) to remain a highly attractive vector for attackers.⁷ It is very likely (75–85%) that not only primary suppliers but also secondary and tertiary suppliers will be compromised more frequently than before. Given the sophistication required, this vector is very likely (75–85%) to be used primarily by state actors. Organisations heavily reliant on a single key supplier should be particularly vigilant. Geopolitically motivated cyberattacks Cyberattacks against state institutions and critical infrastructure by state actors are almost always motivated by events in the physical world rather than mere financial gain or exploiting weak security. Historically, NÚKIB has observed cyberattacks by state actors linked to the political stance of the Czech Republic or specific events (e.g., DDoS attacks by Russian-affiliated hacktivists). It is almost certain (90–100%) that this trend will persist, with attackers primarily seeking to gather information. It cannot be ruled out (25–50%) that some malicious actors will also attempt to infiltrate networks of major organisations and companies to exploit access for other destructive purposes in the event of conflict. Generative artificial intelligence and large language models The year 2023 saw significant advancements in generative artificial intelligence (GenAI), particularly chatbots based on large language models (LLMs), such as the groundbreaking ChatGPT.⁸ These AI chatbots and the products derived from them were rapidly adopted across many types of organisations. The methods to exploit them, such as generating phishing content or writing malicious code, emerged just as quickly. Despite efforts by service operators to limit the abilities of chatbots to produce malicious outputs, the potential to bypass these restrictions (known as jailbreaking) has consistently proved greater. ⁷ ⁸ In 2024, it is almost certain (90–100%) that the use and capabilities of AI services will expand. New services will be introduced, and the functionalities of existing ones will continue to grow. The ability of operators to filter malicious queries is not expected to significantly improve in 2024, and therefore an increase in attackers’ capabilities is anticipated. Specifically, a higher proportion of generative outputs beyond text, for example images, audio, video and deepfakes, is expected. Chatbots are increasingly incorporating these capabilities, therefore an increase in audiovisual phishing forms, such as vishing, and other sophisticated phishing schemes combining various formats is expected. Worth mentioning are, for example, the compromise of authentication service provider Okta, software company JetBrains or Microsoft. In the latter two cases, state-sponsored actors were behind the malicious activities. Although ChatGPT was launched in late November 2022, the massive surge in its popularity can only be dated back to early 2023. 47

Select target paragraph3