OUTLOOK: CYBERSECURITY TRENDS IN THE CZECH REPUBLIC FOR 2023 AND 2024 Threats for Energy Industry and Transportation One of the last year’s prominent trends was the growing interest of malicious attackers in the energy and transportation sectors. Importance of such threats significantly increased with the beginning of the Russian invasion of Ukraine and related events, which was soon exploited by state or state-sponsored actors, as well as cybercriminal and hacktivist groups. It is probable (55-70%) that more or less serious attacks on entities in the energy and transport sectors in the forthcoming period will take place. The risk of such attacks will be highly likely (75-85%) growing as a result of political decisions and other developments associated with the RussianUkrainian war. Persistence of Campaigns In 2022, the Czech Republic faced several persistent campaigns. The first case involved vishing, which was used to make users install remote administration software on their computers. The second persistent campaign was phishing distributed via text messages targeting bank identity and subsequent theft of funds. Both campaigns were notable due to persistence of the attackers, who continued their attacks despite active interventions by various institutions. This shows a trend where attackers are deploying more automated methods of infrastructure creation to keep their campaign running even in case of proactive interventions. We are also observing and expecting to continue the trend of growing sophistication of attackers, especially with regard to credibility of fraudulent emails or websites used in attacks. Ransomware The NÚKIB records ransomware incidents almost every month, and this trend will almost certainly (90-100%) continue in the coming years. Ransomware offered as a service (ransomware-as-a-service), which usually operates on the basis of multiple extortion (including data exfiltration, the possibility of data publication/sale or other activities aimed at increasing the pressure to pay the ransom), has become the predominant form. Although ransomware is primarily the domain of cybercriminal groups, it cannot be ruled out (25-50%) that selected countries under sanction mechanisms will resort to using it as well, either for financial gain or to cover up their true destructive or cyberespionage goals. There is also a real possibility (2550%) of cooperation between non-state and state actors, with non-state actors gaining funding through this activity and state actors gaining access to exfiltrated information along with a higher level of plausible deniability. 42

Select target paragraph3