About the Report At the beginning of 2023, the NÚKIB sent out a questionnaire with 77 questions to entities regulated by the Act No. 181/2014, on Cybersecurity and on Amendments to Related Acts (Cybersecurity Act), as amended, as well as to several other key institutions and organizations that are not regulated by the Cybersecurity Act. Questions covered a wide range of topics, such as cyberattacks, cybersecurity costs, cybersecurity staffing, users, technology, and processes in place. The questionnaire was filled out by 317 entities in total, 236 of which were regulated and 81 were unregulated. From the data obtained, the NÚKIB drew information for the purposes of the 2022 Report on the State of Cybersecurity in the Czech Republic (hereinafter also referred to as the „Report“). All questionnaire data are anonymised. Evaluation Process The assessment of the state of cybersecurity in the Czech Republic is based on an analytical process which includes quantitative and qualitative evaluations of data from completed questionnaires, findings of the NÚKIB, information provided by its partners, and open-source information. The NÚKIB does not verify the data provided by the respondents nor validate the accuracy of their statements. The analytical conclusions in the Report are based on the premise that the questionnaire responses are not biased. Probabilistic expressions (see below) are used to express the analytical evaluation. The Report does not provide a complete list of all activities related to cybersecurity. The purpose of the document is to describe and evaluate the threats in cyberspace that the Czech Republic faced in 2022, as well as the activities that help mitigate them. Probabilistic Expressions Used in the 2022 Report on the State of Cybersecurity in the Czech Republic Probabilistic expressions and representation of its percentage values: EXPRESSION LIKELIHOOD Almost surely 90–100 % Highly likely 75–85 % Highly likely 55–70 % Cannot be ruled out/Real possibility 25–50 % Unlikely 15–20 % Highly unlikely 0–10 % 6

Select target paragraph3