The NÚKIB is also registering a trend of increasing persistence of attackers, who often deploy automated methods of infrastructure creation to keep the campaign running even in the event of proactive interventions. The sophistication of attackers is also improving, especially the credibility of fraudulent emails and fake websites (more on this topic in the chapter: Outlook: Cybersecurity Trends in the Czech Republic for 2023 and 2024). Supply Chain Attacks: Low Incidence, but with High Potential Impact In 2022, less than 6% of surveyed institutions and organizations experienced an attempt or a successful attack through a service provider. This is an identical amount as in 2021, with this type of attack remaining among the least frequent. This is probably (55-70%) due to the combination of several factors, in particular the lower incidence of this attack type in the Czech Republic in general, low detection capability on the part of organizations and significant efforts of attackers to be undetected in the victim’s systems. However, the NÚKIB dealt with several serious cases in May of last year that highlight the need for a supplier management process. In one cyber incident that caused significant damage to the victim organization, the attacker penetrated victim’s network through a compromised VPN account of their servicing company. Two more examples of poor security measures were discovered by organizations themselves, probably (55-70%) before attackers could exploit the vulnerabilities. The two organisations found that their information system supplier was storing their sensitive data on web storage without authentication. Supplier management is one of the organizational security measures that selected entities covered by the Cybersecurity Act are required to implement. The supplier management process serves primarily to identify risks associated with the use of third-party services and their subsequent mitigation. The year-on-year comparison of the number of respondents whose organisations manage the risks associated with suppliers shows a slight decrease (see Graph 15). Within Critical Information Infrastructure (CII), 86% of responding organisations manage these risks. 80% 72 Yes 66 60% 40% 34 28 20% 0% 2021 2022 Graph 15: Does Your Organization Manage Supplier-Related Risks? (Year-on-year Comparison, in % of Respondents) 19 No

Select target paragraph3