About the Report Questionnaire Survey At the beginning of 2024, NÚKIB distributed a survey with 63 questions to entities regulated by Act No. 181/2014, on Cybersecurity and on Amendments to Related Acts (the Cybersecurity Act), as amended, and to several other key institutions and organizations not regulated by the Cybersecurity Act. The questions covered a wide range of topics, including cyberattacks, cybersecurity costs, cybersecurity staffing, users, technology and existing processes. A total of 423 entities responded, with 339 being regulated and 84 unregulated. The information obtained from these responses was used to inform NÚKIB for the 2023 Report on the State of Cybersecurity in the Czech Republic (hereinafter „Report“). All data from the survey were anonymised. Evaluation process Assessment of the state of cybersecurity in the Czech Republic is based on an analytical process that includes quantitative and qualitative evaluations of the data from the completed surveys, NÚKIB’s findings, information from its partners and open-source information. NÚKIB does not independently verify the data provided by the respondents or validate the accuracy of their statements. The analytical conclusions in the Report assume that the survey responses are unbiased. Probabilistic expressions (see below) are used to express the analytical evaluation. The Report does not provide a complete list of activities related to cybersecurity. Its purpose is to describe and evaluate the threats faced by the Czech Republic in cyberspace in 2023 and the activities that help mitigate these threats. Probabilistic expressions used in the 2023 Report on the State of Cybersecurity in the Czech Republic 6 Almost surely 90–100 % Highly likely 75–85 % Likely 55–70 % Cannot be ruled out/Real possibility 25–50 % Unlikely 15–20 % Highly unlikely 0–10 %

Select target paragraph3