Logo webu

Cyberattacks in the Czech Republic are increasing. NIS2 and DORA alone will not protect companies the weak point remains the response to cyberattacks.

 ​

Prague, March 12, 2026

 

The number of cybersecurity incidents in the Czech Republic has significantly increased, putting growing pressure on companies and public institutions. The Czech National Cyber and Information Security Agency (NÚKIB) recorded a record 32[1] ​incidents in January 2026, the highest number in the past twelve months. In February the number dropped to 23 incidents[2], but it still remained above the average of the past year. At the same time, organizations are dealing with the impact of the new Czech Cybersecurity Act implementing the NIS2 Directive and the European Digital Operational Resilience Act (DORA). According to experts, whether a company withstands a cyberattack today often depends not on audit results, but on how quickly the attack is detected and how effectively the organization responds. The importance of connecting regulation, operational security, and real resilience was highlighted by experts at the Axelum Security Day conference, which annually brings together managers, IT specialists, and cybersecurity experts from companies, the financial sector, and public administration.

The Czech Cybersecurity Act implementing the European ​NIS2 Directive ​affects thousands of organizations across more than twenty sectors – from energy and healthcare to manufacturing, digital services, and public administration. The regulation introduces direct responsibility of statutory bodies for cybersecurity risk management and penalties of up to ​CZK 250 million ​or two percent of global annual turnover[3]. For the financial sector, the ​DORA regulation ​is already in force, tightening requirements for digital operational resilience and often affecting ICT service providers as well.

Data from NÚKIB show that cyber threats are not an abstract risk but a real and growing challenge, and organizations must prepare not only for audits but primarily for real cyberattacks. ​“Statistics confirm what security teams see in practice – the number of incidents is increasing and attacks are becoming more sophisticated. Organizations therefore cannot rely solely on preventive measures or formal compliance with regulations. The ability to quickly detect an attack and respond effectively is just as important,” ​said ​Filip Štolle, CEO of axelum.

 ​

Complying with regulation does not mean surviving an attack

The biggest misconception among companies is treating NIS2 compliance as the ultimate goal. In reality, it is only the entry point to real cybersecurity. While audits, documentation, and registration with NÚKIB are necessary, they alone will not protect organizations from sophisticated attacks.

Similar experiences are shared by organizations from the public and financial sectors that must integrate new regulatory requirements into everyday operations. In these environments, cybersecurity is increasingly perceived as part of ​asset management and risk management, rather than merely a technical issue. Regulatory requirements such as NIS2 and DORA are pushing organizations to build ​real resilience ​– from properly configured processes and employee training to the ability to ​respond effectively to incidents.

“Cybersecurity is no longer just an IT department issue; it has become a strategic concern for the leadership of every organization. Companies that see regulatory compliance merely as a checkbox exercise are at risk. Attackers do not follow audit checklists – they exploit the places where organizations respond too slowly,” ​added ​Marian Bartl, Managing Director of axelum.

 ​

Technology alone is not enough without timely response

One of the most discussed topics in modern cybersecurity is the use of ​Security Operations Centers (SOC) ​and ​Security Information and Event Management (SIEM) ​systems that help detect potential cyberattacks. These tools are an important part of a modern security framework, but their real value does not lie in the technology itself.

In practice, companies often invest in security technologies but underestimate the operational side of cybersecurity. According to experts, a SOC without the ability to respond quickly is like an alarm system without a dispatch center – it signals a problem but does not protect the organization on its own.

Many organizations generate enormous volumes of security alerts today, but the real challenge lies in distinguishing which alerts represent an actual incident. The goal of modern SOC and SIEM solutions is not to produce more data, but to help security teams quickly understand what is happening and respond correctly. The ability to separate noise from real threats is increasingly what determines whether an organization can successfully handle an attack.

 ​

Security as a continuous process

Experience from real projects and incident response shows that organizations that approach cybersecurity ​systematically and over the long term ​handle crisis situations significantly better – both in terms of damage mitigation and regulatory impact. The proper setup of processes and the involvement of ​experts with real-world experience play a key role.

Experts therefore recommend focusing on three key areas. ​“Companies should pay particular attention to identifying critical assets and conducting a realistic risk assessment, building an effective incident detection and response system, and continuously educating both management and employees. The human factor remains the weakest link in most security systems,” ​advised Filip Štolle to the participants at the conclusion of the Axelum Security Day conference.

Cybersecurity is not a project with a defined end date. It is ​a continuous process that must constantly adapt to evolving threats.

 ​

Data available only in Czech. ​

[1] https://nukib.gov.cz/download/publikace/vyzkum/Kyberneticke-incidenty-pohledem-NUKIB-leden-2026.pdf

[2] https://nukib.gov.cz/download/publikace/vyzkum/Kyberneticke-incidenty-pohledem-NUKIB-unor-2026.pdf

[3] https://portal.nukib.gov.cz/informacni-servis/faq/prehled-faq/67b3013799765117db010852 ​

 ​

Be prepared for a real cyberattack. Prevention matters, and you can start with a no-obligation meeting with our experts.

All infosec
We are an information security company. Our purpose is to safeguard the clients' most valuable information and protect their business.

© 2026 Axelum s.r.o.

Contact

Axelum s.r.o.

CIN: 25639056

VAT ID: CZ699004029

V Kapslovně 2767/2

130 00 Prague CZ

info@axelum.eu

+420 221 400 111


Created by uuWebKit
document_check.svg
We use cookies on this website to ensure its functionality and to personalise ads, solely with your consent and in accordance with our Cookies Policy.

By clicking on the "Accept cookies" button, you consent to the use of selected cookies and agree to the transfer of behavioural data for the display of targeted advertising on social and advertising networks. You can choose which information you want to share with us by clicking on the Cookie settings button.