Summary of the Report on the State of
Cybersecurity in the Czech Republic 2023
80% increase in the
number of cyber
incidents
Work on legislation
improvement and
security measures
In 2023, NÚKIB recorded an almost 80%
increase in the number of cybersecurity incidents, rising from 146 last year
to 262. This surge is mainly attributed to
repeated waves of DDoS attacks by Russian-affiliated hacktivist groups and ransomware attacks targeting Czech strategic
institutions or companies. Despite the
overall increase, the number of significant
cyber incidents decreased year-on-year.
NÚKIB’s notable activities in 2023 included the drafting of a new cybersecurity
law, continuing the organisation’s work
to ensure a robust legislative framework
for cybersecurity in the Czech Republic
following the NIS 2 Directive published
during the Czech Presidency of the
Council of the European Union in 2022.
The year 2023 was similar, marked by discussions, consultations with stakeholders
and the public, and commencement of
the formal legislative process.
The most common
types of
cyberattacks and
their context
The most prevalent cyberattacks
in 2023 included various forms of
phishing (spear-phishing, vishing,
quishing) and fraudulent CEO emails.
DDoS attacks were primarily directed
at the public and financial sectors.
Many of the recorded incidents
were linked to Russian aggression in
Ukraine, and in a few cases, to the
Israeli-Palestinian conflict.
Cyber espionage
threats
Project BIVOJ:
Increasing the resilience of the Czech
Republic
NÚKIB detected at least four distinct
threat actors attempting to or succeeding in penetrating the networks
of Czech strategic institutions, with
a high probability (75–85%) that cyber
espionage was the objective.
In collaboration with partners, NÚKIB
also advanced its work on the BIVOJ
Project. The project aims to create
a unified, secure shared platform that
provides security and communication
services for public sector institutions.
GOV.CZ
One of the project’s key results in
2023 was the migration of central
state administrative bodies to a single
gov.cz domain. This single domain will
increase user-friendliness for citizens,
improve legal certainty, and fortify
resilience to DDoS attacks.
Awareness
activities and
cyber exercises
NÚKIB also continued its initiatives in
raising cybersecurity awareness and
organising cybersecurity exercises. This
included collaboration on educational
programmes for primary and secondary schools and raising the profile
of cybersecurity within the retraining
system. In 2023, the TELCO23 sectoral exercise for telecommunications
service providers was held, and NÚKIB
representatives participated in international cybersecurity exercises such
as Locked Shields and Cyber Coalition.
Looking ahead
NÚKIB anticipates several key trends
over the next two years: cyberattacks
via the supply chain, geopolitically motivated cyberattacks, and the
increasing impact of artificial intelligence on cybersecurity.
9