Public Sector: Decrease of Incident Numbers to Values From 2020 The public sector has traditionally been one of the most targeted sectors, and 2022 was no different. A total of 51 cyber incidents were recorded in this sector, representing more than a third of the total. However, the nominal and proportional representation of incidents slightly decreased compared to the previous year (see Graph 18). The highest number of cyberattacks was aimed at data availability, which can be partially explained by several DDoS campaigns, mostly carried out by Russian-language hacktivists in connection with Czech support for Ukraine. These attacks often targeted various government or public institutions but tended to be less sophisticated and very limited in terms of real impact. 70 62 60 52 50 51 40 30 20 10 0 2020 2021 2022 Graph 18: Development of the Number of Incidents in the Public Sector Recorded by the NÚKIB in 2020-2022 Despite the year-on-year decrease of the number of incidents, there is an increasing number of respondents in the public sector who perceive the level of their cybersecurity as insufficient (see Graph 19). This increase by more than 10% of respondents assessing the level of cyber security in a negative light may be to some extent related to the fact that 7% of respondents in the public sector also said that their organization had decreased their cybersecurity budget. Another factor may also be the serious impact of incidents on the public sector, especially in terms of damage to reputation and service disruptions, which were mentioned by nearly a onefifth of critical infrastructure entities. 100% 80% 71 77 66 60% 2020 2021 2022 40% 20% 7 16 27 22 8 0% Yes No Cannot assess Graph 19: D  o you Perceive the Level of Cybersecurity in Your Organization as Sufficient? (Comparison of 2020–2022 in %) 23 7

Select target paragraph3