CZECH CYBERSECURITY IN 2022
ACCORDING TO THE NÚKIB1
Number of Cybersecurity Incidents in 2022
Registered by the NÚKIB
In 2022, the NÚKIB received a total of 764 reports from regulated and unregulated entities under
the Cybersecurity Act, 146 of which it assessed as cybersecurity incidents and subsequently
addressed accordingly. Despite the significant increase in reporting by entities, there was
a slight year-on-year decline in recorded incidents in 2022.
200
157
150
100
50
99
78
50
146
54
0
2017
2018
2019
2020
2021
2022
Graph 1: Number of Incidents Registered by NÚKIB
One of the possible reasons for the decrease of the number of incidents is the fact that there
was no major campaign in 2022 involving exploitation of a specific vulnerability on a massive
scale. In contrast, 2021 saw campaigns exploiting the ProxyLogon and ProxyShell vulnerabilities
targeting the widely used Microsoft Exchange Server service. Furthermore, towards the end of
2021, the Log4Shell vulnerability was discovered. To a certain extent, proactivity on the part of
the NÚKIB has also decreased (in the form so-called threat hunting, where incidents are being
proactively discovered), which was primarily due to personnel limitations. Broadly speaking,
it is important to establish that neither the NÚKIB nor the individual entities have the ability
to detect all incidents. Especially the most sophisticated types of attacks are very difficult to
detect, because attackers make extraordinary efforts to remain undetected. Some organisations
may also fail to properly identify a cybersecurity incident or may decide not to report a detected
incident to the NÚKIB. Given the growing rate of cybercrime and incidents recorded by CSIRT.
CZ, it is likely (55-70%) that the true number of incidents in the Czech Republic for 2022 is in
the upper hundreds.
Events related to the Russian invasion of Ukraine were also reflected in the number of recorded
incidents in 2022. The highest incidence was registered in April and October, which was driven
by a significant increase of DDoS attacks during both months (see Graph 2). This increase was
primarily due to the attacks by Russian-speaking hacktivist groups. Killnet was behind the April
DDoS campaign, while Anonymous Russia claimed responsibility for part of the October attacks.
The attacks of both groups are almost surely (90-100 %) related to the Czech support of Ukraine.
The presented information comes from NÚKIB sources and evaluations of 317 questionnaires (see the section About
the Report).
1
7