Classification of Cyber Incidents Reported to the NÚKIB2 Incidents targeting availability were dominant in Czech cyberspace over the past year; this was largely because our country faced extensive waves of DDoS attacks. However, incidents targeting availability included not only DDoS attacks, but in some cases, also simple technical errors leading to system downtime. Within the availability and malicious code categories, ransomware continued to be a consistent trend, with cases present every month in 2022 except in October. However, the number of cases decreased compared to previous year which was reflected in general decrease in the malicious code category. The number of intrusions incidents also decreased. This was namely given by the aforementioned absence of campaigns exploiting vulnerabilities which occurred in 2021. Percentage of representation in incidents 2021 2022 Availability availability disruption caused by DoS/DDoS attacks or sabotage 34 % 58 % Malicious code viruses, worms, Trojan horses, dialers or spyware 25 % 8% Intrusions compromising of applications or user accounts 22 % 12 % Fraud phishing, identity theft or ICT unauthorized use 10 % 11 % Information security unauthorized data access, unauthorized data modification 8% 10 % Intrusion attempt vulnerability exploitation attempts, login attempts etc. 1% 0% Information Gathering scanning, sniffing, social engineering 0% 0% Offensive content 0% 0% Other 0% 3% Development during the year The classification of cyber incidents is based on ENISA taxonomy: Reference Incident Classification Taxonomy — ENISA (europa.eu). 2 9

Select target paragraph3