10. Other national regulation specifics


The tenth topic has less in common with the content of the NIS2 Directive, but it still forms a very substantial part of what cybersecurity means or will mean in the Czech Republic in terms of legal regulations. At the same time, the NIS2 Directive requires Member States to have instruments with similar parameters to the current measures in Article 32(4).

Current specifics of regulation in the Czech Republic


MEASURES

In addition to the security measures to be implemented by the obliged persons themselves, the Cybersecurity Act also contains tools that the NCIB can use to respond to threats or incidents in cyberspace. These are called measures in the current wording of the Act.

The current Act on Cyber Security contains three types of measures - warning, reactive and protective measures.

With the warning, the NUKIB warns regulated entities that there is a threat that they must consider in their risk analyses. Simply put, the NUKIB is telling entities that they should focus on a particular hazard that is more imminent than usual at the time. An example of this would be a situation where the NUKIB has identified based on its monitoring that a campaign of ransomware attacks targeting hospitals is coming and has alerted them to this danger.

By reactive and protective measures, the NUKIB directly sets out specific steps that regulated persons affected by the reactive or protective measure must take to enhance cyber security. The main difference between the two is that while a reactive measure represents an effort to prevent an imminent incident (attack), a protective measure is issued following an incident that has already been resolved so that it is not repeated by other regulated persons.

An instrument that the current Act on Cyber Security does not yet contain is the instrument mentioned in Article 32(4) of NIS2, where it requires Member States to have the power to draw attention to the fact that regulated organisations (essential and important entities) are in breach of the obligations arising from the Directive.

STATE OF CYBER EMERGENCY

The Act on Cyber Security contains a special type of state of emergency that the NUKIB is supposed to declare in the event that it is unable to manage threats in cyberspace through its standard procedures. It is called a state of cyber emergency. It allows NUKIB to access some of the information normally collected only by the National CERT, use nationwide radio and television broadcast, and expands the range of powers towards some of the regulated entities.

Future specifics of regulation in the Czech Republic

The draft Act on Cyber Security also introduces some changes or new tools in the abovementioned national cybersecurity regulation. Thus, the following text describes these changes, in particular the measures (now countermeasures), state of cyber emergency and a new institute - the Assessment Mechanism for Supply Chain Security.


COUNTERMEASURES

The countermeasures reflect the original regulation of measures in the current Act on Cyber Security. In principle, from the point of view of practical application, there will not be a fundamental change to these institutes; the changes and new parameters are described in this article.


ALERT

Most of the content of the alert provision of the proposal was originally part of the warning provision. The name of this institution and its regulation reflects the requirement of Article 32(4) of the NIS2 Directive and serves as a tool primarily aimed at informing the public. The alert should be noted at least by the regulated entities, and more preferably by the whole professional public, and when appropriate, considered within their information security management system. Formally, however, the alert is not connected to any specific enforcement process and is rather informative.


WARNING

The alert continues to draw attention to a specific threat, but now it can also draw attention to a vulnerability as an input into the risk analyses of the affected regulated entities. The warning has always been published on the official notice board, but now there is also an option not to publish it in justified cases and only to send it to the regulated persons concerned. Unlike the reactive countermeasure, the warning only applies to regulated service providers under the higher obligations regime.


REACTIVE COUNTERMEASURE

The proposal includes merging of reactive and protective measures into one institute - reactive countermeasure, which should be newly issued in similar cases as the existing reactive and protective measures. The procedural requirements are then merged into a single procedure, which allows the NUKIB to impose variable measures to prevent, avert or mitigate an incident in the form of a decision for one specific regulated entity or in the form of a general measure binding a wider defined range of regulated entities or all of them. Reactive countermeasures may be imposed on the provider of a regulated service under both the higher and lower obligation regimes.


STATE OF CYBER EMERGENCY

The state of cyber emergency has undergone some changes in the proposal mainly based on the experience gained with the application of the current Act on Cyber Security. The proposed changes are thus in the interest of its greater practical usability in the event of a threat to the Czech Republic. The state of cyber emergency in its measures replicates the characteristics that are usual for states of emergency used in crisis management.

At a time of a declared state of cyber emergency, the Director of the NUKIB has measures at his disposal that can reverse a situation that significantly threatens the Czech Republic. These tools include: providing NUKIB property (physical assets) for use by others (e.g. providing a probe to monitor traffic on the network under attack), requesting the provision of human resources and physical assets, ordering persons outside the scope of regulated entities to implement measures to deal with the incident, ordering regulated entities to be on standby within their capabilities, making a non-public telecommunications network available for use by NUKIB, or prohibiting the use of technical assets threatened by the incident (also outside the circle of regulated entities).


ASSESSMENT MECHANISM FOR SUPPLY CHAIN SECURITY

By its resolution of 21 June 2022, the Security Council of the State instructed the NUKIB to prepare a draft law to increase the security of supply chains of the strategic infrastructure of the state in the field of information and communication technologies (ICT). The issuance of the resolution itself was preceded by a number of impulses from the domestic and EU level, such as the proclamation of the Programme Statement of the Government or the task of the Action Plan of the National Cyber Security Strategy, which mandates the development of a draft framework for an assessment of the risk profile of suppliers with the possibility of limiting high-risk suppliers.

The reason for the creation of the Assessment Mechanism for Supply Chain Security, which the above-mentioned resolution instructed the NUKIB to design, is primarily due to the strategic threats emanating from the supply chain and the risks arising therefrom. Although the standard features of ICT products can be familiarised, the security of these products cannot be effectively verified by technical means alone due to their high complexity. The trustworthiness of the supplier is an important factor in this respect, as the supplier has the ability to compromise the security of its products and services. The purpose of the proposed regulation is thus, inter alia, to identify high-risk suppliers by means of a proportionate assessment mechanism.


SUPPLIER RISK ASSESSMENT

According to the proposed legislation, the NUKIB conducts supplier assessment in cooperation with ministries, intelligence services and other state authorities with relevant information for assessing the supplier's credibility. However, the process is based on elementary information on suppliers provided by individual providers of strategically important services. This information, in combination with information from the NUKIB and cooperating authorities, is subjected to an assessment based on the supplier credibility criteria.

Supplier Risk Criteria


WHO WILL BE ASSESSED?

SThe state will be able to carry out the assessment itself, focusing both on suppliers who are already delivering their services to the infrastructure for the provision of strategically important services, and on their subcontractors or potential suppliers who have an impact on the final product.


WHAT WILL BE ASSESSED?

The characteristics of the supplier's country of residence and other countries affecting the supplier will be assessed. In addition, the characteristics of the suppliers themselves and the previous harmful activity of both the suppliers and the States having influence on the suppliers will be examined. The aim is to identify threats emanating from the supplier or the country affecting it to the security of the Czech Republic or to internal or public order.

In cases where the NUKIB, after a thorough evaluation of all relevant information, identifies a possible significant threat to the security of the Czech Republic or its internal security or public order, it should now be able to issue a general measure in which it imposes conditions on providers of strategically important services or prohibits the use of the supplier's products and services. Apart from this general measure, the NUKIB may also use existing, less invasive tools, such as warnings, to proportionally limit the risk.


THE MECHANISM IN THE PROPOSED ACT ON CYBER SECURITY AND IMPLEMENTING DECREES

The assessment mechanism can be primarily found in the proposed Act on Cyber Security, which defines the relevant terms, such as strategically important service, security important supply, or its supplier. The law also defines the assets that are subject to the mechanism's limitations, or how credibility is assessed. The actual criteria on which the assessment is based and the essential functions carried out with the use of assets in the defined scope of ISMS are set out in the proposed implementing legislation for the Act, which are:

  • Decree on the Supplier Risk Criteria,

  • Decree on the Regulated Services,

  • Decree on the Essential Functions of the Defined Scope.


CONSEQUENCES OF THE INTRODUCTION OF THE MECHANISM

Apart from the suppliers themselves, the mechanism will mainly affect the regulated entities in scope of the assessment mechanism, the so-called providers of strategically important services, determined according to the criteria set by the proposal and the Decree on Regulated Services. The aim of the mechanism is to minimise the restriction of the use of suppliers to the necessary cases where the threats are significant. Therefore, the general measure may be applied only in the most serious cases of a threat to the security of the Czech Republic or its internal or public order.

The next topic briefly describes how entities can prepare for the arrival of the new Act on Cyber Security. In short, where to begin.

Continue by clicking on the blue arrow on the right side or select one of the other topics in the index below.

Topic index
  1. General information about the future national regulation
  2. Who is affected by the new obligations
  3. Differentiation of regulated entities
  4. Obligation to implement security measures
  5. Incidents and how to report them
  6. Registration and communication with NUKIB
  7. Methods of ensuring compliance
  8. Sanctions and enforcement measures
  9. National and international cooperation
  10. Other national regulation specifics
  11. How to prepare for the new legislation
  12. Financial aspects of the new Act on Cyber Security