During 2022, based on the mandate granted by the National Security Council, the NÚKIB worked on a bill aiming to significantly limit the impact of high-risk contractors on the country‘s most important infrastructure. While cybersecurity threats arising from technology supply chains have long been known, there is still no comprehensive legal mechanism in the Czech legal system to enable targeted assessment and mitigation of the risks arising from these threats (more in the chapter: Ensuring Cybersecurity on a National Level: Strengthening Resilience against Cyber Threats). Cyber Threat Actors ! State-sponsored and cybercrime activities in cyberspace have long been among the most serious threats to the Czech Republic’s cybersecurity. ! State-sponsored groups are typically highly sophisticated actors using a wide range of techniques to achieve their goals and constantly refining their tools. Russian state actors in particular represented an increased risk for the Czech Republic during the last year. In the context of the Russian invasion, a cyberattack from early 2022 was attributed by all member states through the process of coordinated attribution to the Russian Federation. This attack had also indirect impact on Czech entities (see Box). Cyberattack on Satellite Internet Provider Viasat In the early morning of February 24, 2022, around the same time as the invasion of the Russian armed forces, a cyberattack was launched against Viasat‘s ground terminals providing satellite internet connectivity in Ukraine. The attack gradually limited their functionality, with a spillover effect impacting tens of thousands of users in North Africa, the Middle East and Europe, including some in the Czech Republic. Thanks to the relatively low number of Viasat users, this attack had no significant impact on the Czech Republic. In 2022, the NÚKIB also registered a cyber espionage campaign against one of the national strategic institutions, highly likely (75-85 %) carried out by the Russian state-sponsored actor APT29 (also known as Cozy Bear, The Dukes, or NOBELIUM). This actor is usually attributed to the Russian Foreign Intelligence Service (SVR). In this campaign, the email account of one of the target institution’s employees was compromised. The attacker then used the account to send spear-phishing emails to over a thousand addresses of partner organizations. The list of victims of this campaign indicates that the actor’s goal was to gain access to strategic information. Last year, the NÚKIB also registered increased activity of pro-Russian hacktivist groups Killnet and Anonymous Russia, which carried out DDoS attacks against a number of Czech entities. These groups represent rather less sophisticated actors and the effects of their attacks have been marginal. 20

Select target paragraph3