Digital Services: Targeted Through a Wide Range of Attacks Within the Czech digital services sector (telecommunications, digital infrastructure, internet services, etc.), the NÚKIB recorded a total of eight incidents during 2022. Majority of them targeted availability of services or data. The scanning of external network ports was the most common type of cyberattack attempts according to the respondents. Compared to other sectors, scanning reached a relatively high frequency score, which can be explained to some extent by the nature of digital sector entities and their specialization. As digital services providers of internet connection, etc., they can detect automated and massive scanning of the outer perimeter of the network by attackers. Web application attacks, phishing, DoS and DDoS attacks, and attempts to exploit vulnerabilities present additional common types of attacks (see Graph 28). 40% 37 30% 20% 16 16 11 10% 5 0% Scanning Web application attacks Phishing Denial of service (DoS, DDoS) Vulnerability exploitation attempt Graph 28: Most Common Types of Recorded Cyberattacks in the Digital Services Sector (in % of Respondents) Compared to the previous year, the share of respondents whose organizations manage supply chain security risks decreased. Exactly 80% of the surveyed respondents do so, while the majority of these entities take into account technical as well as non-technical risks in accordance with the NÚKIB recommendation for assessing the credibility of 5G network technology suppliers in the Czech Republic (see Graph 29). 100% 80% 80 60% 40% 20 20% 0% Yes No Graph 29: Do You Control Risks Related to Suppliers? (% of Respondents) 29

Select target paragraph3