Classification of Cyber Incidents Reported to the NÚKIB2
Incidents targeting availability were dominant in Czech cyberspace over the past year; this
was largely because our country faced extensive waves of DDoS attacks. However, incidents
targeting availability included not only DDoS attacks, but in some cases, also simple technical
errors leading to system downtime. Within the availability and malicious code categories,
ransomware continued to be a consistent trend, with cases present every month in 2022 except
in October. However, the number of cases decreased compared to previous year which was
reflected in general decrease in the malicious code category. The number of intrusions incidents
also decreased. This was namely given by the aforementioned absence of campaigns exploiting
vulnerabilities which occurred in 2021.
Percentage of representation in incidents
2021
2022
Availability
availability disruption caused by
DoS/DDoS attacks or sabotage
34 %
58 %
Malicious code
viruses, worms, Trojan horses,
dialers or spyware
25 %
8%
Intrusions
compromising of applications or
user accounts
22 %
12 %
Fraud
phishing, identity theft or ICT
unauthorized use
10 %
11 %
Information security
unauthorized data access,
unauthorized data modification
8%
10 %
Intrusion attempt
vulnerability exploitation attempts,
login attempts etc.
1%
0%
Information Gathering
scanning, sniffing, social
engineering
0%
0%
Offensive content
0%
0%
Other
0%
3%
Development during
the year
The classification of cyber incidents is based on ENISA taxonomy: Reference Incident Classification Taxonomy —
ENISA (europa.eu).
2
9