Summary of the Report on the State of Cybersecurity in the Czech Republic 2023 80% increase in the number of cyber incidents Work on legislation improvement and security measures In 2023, NÚKIB recorded an almost 80% increase in the number of cybersecurity incidents, rising from 146 last year to 262. This surge is mainly attributed to repeated waves of DDoS attacks by Russian-affiliated hacktivist groups and ransomware attacks targeting Czech strategic institutions or companies. Despite the overall increase, the number of significant cyber incidents decreased year-on-year. NÚKIB’s notable activities in 2023 included the drafting of a new cybersecurity law, continuing the organisation’s work to ensure a robust legislative framework for cybersecurity in the Czech Republic following the NIS 2 Directive published during the Czech Presidency of the Council of the European Union in 2022. The year 2023 was similar, marked by discussions, consultations with stakeholders and the public, and commencement of the formal legislative process. The most common types of cyberattacks and their context The most prevalent cyberattacks in 2023 included various forms of phishing (spear-phishing, vishing, quishing) and fraudulent CEO emails. DDoS attacks were primarily directed at the public and financial sectors. Many of the recorded incidents were linked to Russian aggression in Ukraine, and in a few cases, to the Israeli-Palestinian conflict. Cyber espionage threats Project BIVOJ: Increasing the resilience of the Czech Republic NÚKIB detected at least four distinct threat actors attempting to or succeeding in penetrating the networks of Czech strategic institutions, with a high probability (75–85%) that cyber espionage was the objective. In collaboration with partners, NÚKIB also advanced its work on the BIVOJ Project. The project aims to create a unified, secure shared platform that provides security and communication services for public sector institutions. GOV.CZ One of the project’s key results in 2023 was the migration of central state administrative bodies to a single gov.cz domain. This single domain will increase user-friendliness for citizens, improve legal certainty, and fortify resilience to DDoS attacks. Awareness activities and cyber exercises NÚKIB also continued its initiatives in raising cybersecurity awareness and organising cybersecurity exercises. This included collaboration on educational programmes for primary and secondary schools and raising the profile of cybersecurity within the retraining system. In 2023, the TELCO23 sectoral exercise for telecommunications service providers was held, and NÚKIB representatives participated in international cybersecurity exercises such as Locked Shields and Cyber Coalition. Looking ahead NÚKIB anticipates several key trends over the next two years: cyberattacks via the supply chain, geopolitically motivated cyberattacks, and the increasing impact of artificial intelligence on cybersecurity. 9

Select target paragraph3