b) Public authorities and legal or natural persons specified in Section 3, letters c) to f)
(4) Protective measures are obligatorily applied by public authorities and legal or natural persons
specified in Section 3, letters c) to f).
Section 12
Warning
(1) The Agency shall issue a warning if, particularly on the grounds of its own operation or on the
grounds of a notification of the operator of the national CERT or public authorities in a field of
cyber security abroad, it observes that there is a threat in the field of cyber security.
(2) A warning shall be issued by the Agency on its website and the Agency shall also inform public
authorities and legal or natural persons specified in Section 3 whose contact details are kept on
the record according to Section 16, paragraph 4.
(3) In order to protect internal order and security, to protect people’s lives and health, or to protect
the state’s economy, the Agency is entitled, after consulting the public authority or legal or natural
person specified in Section 3, letters c), d), f), g) or h) that is affected by the cyber security incident,
to inform the public about the incident or assign the concerned public authority or legal or natural
person to do so.
Reactive and protective measures
Section 13
(1) The Agency shall issue a decision on reactive measures to resolve the cyber security incident or to
secure information systems or networks and electronic communication services1) from a cyber
security incident, which is the first legal act in the given situation. If it is not possible to deliver the
decision into the hands of the addressee within 3 days from the day of its issuance, it is considered
to be delivered and enforceable upon its publication on the Agency’s official notice board. The
decision in the first sentence may be issued by the Agency in on site proceedings according to the
Code of Administrative Procedure.
(2) Appeal against the decision of the Agency according to paragraph 1 does not have a suspensive
effect.
(3) If a reactive measure to solve a cyber security incident or to protect information systems or
electronic communication networks and services1) from a cyber security incident concerns an
unspecified group of public authorities or legal or natural persons, the Agency shall adopt such a
measure in the form of a measure of general nature.
(4) Public authorities and legal or natural persons specified in Section 3, letters a) to f) are obliged to
notify the Agency about their application of a reactive measure and its outcome without undue
delay. The requirements for the notice shall be set out by an implementing legal regulation.
Section 14
In order to strengthen the protection of information systems or networks and electronic
communication networks1) and on the basis of an analysis of an already solved cyber security incident,
the Agency shall adopt a protective measure of general nature in which it sets out a method of