Incidents According to Entities: Growing Frequency and Higher Sophistication of Phishing Attacks The most common types of cyberattacks experienced by surveyed organisations during 2022 were phishing, external network scanning, and fraudulent emails (see Graph 4). These types of attacks are less technically demanding and easy to detect; they appear regularly in our statistics. A key difference compared to the previous year has been the entities´ perception of spear-phishing, which has been declared the most serious type of attack according to the surveyed organizations (see Graph 5). This is probably (55-70 %) due to growing sophistication and persistence of attackers carrying out such attacks. Various forms of phishing and fraudulent e-mails also continue to represent one of the most common vectors of cyberattacks globally.3 Overall, 68% of surveyed organizations experienced an attempted cyberattack during 2022; however, only 24% experienced a breach of confidentiality, integrity, or availability of information or services (see Graph 6). 50% 40% 40 37 39 30% 27 20% 26 16 21 17 14 15 14 10% 7 6 3 0% Phishing Scanning Scam e-mail Harmful content 2 6 4 Spear-phishing 2020 6 Other 2021 2022 Graph 4: Most Frequent Types of Cyberattacks in 2020 - 2022 (in % of Respondents) 50% 44 40% 32 30% 21 20% 10% 13 11 15 9 17 12 11 19 18 9 6 2 0% Spear-phishing Phishing Scam e-mail 9 0 Vulnerability exploitation attempt 2 Scanning Other 2020 2021 2022 Graph 5: Most Severe Types of Cyberattacks in 2020 - 2022 (in % of Respondents) Microsoft. 2022. Microsoft Digital Defense Report 2022. https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/ RE5bUvv?culture=en-us&country=us 3 10

Select target paragraph3