Czech cyber agency warns against Chinese tech in critical infrastructure

Padlock

The Czech Republic’s National Cyber and Information Security Agency (NUKIB) is instructing critical infrastructure organizations in the country to avoid using Chinese technology or transferring user data to servers located in China.

The agency warned that these actions constitute a significant cybersecurity threat and should be entirely avoided unless there’s a reasonable justification for continuing the practice.

The NUKIB states that it has re-evaluated its risk estimate of significant disruptions caused by China, now assessing it at a “High” level, indicating a high probability of occurrence.

“Current critical infrastructure systems are increasingly dependent on storing and processing data in cloud repositories and on network connectivity enabling remote operation and updates,” reads NUKIB’s warning.

“In practice, this means that technology solution providers can fundamentally influence the operation of critical infrastructure and/or access important data, making trust in the reliability of the supplier absolutely crucial.”

NUKIB noted that it has already confirmed malicious activities of Chinese cyber-actors targeting the Czech Republic, including a recent APT31 campaign targeting the Czech Ministry of Foreign Affairs.

Additionally, the agency emphasizes that the Chinese government has access to data stored by private cloud service providers within the country, ensuring that sensitive data is always within its reach.

Apart from critical infrastructure, NUKIB also warns about consumer devices, such as smartphones, IP cameras, electric cars, large language models, and even medical devices and photovoltaic converters manufactured by Chinese firms.

These are all characterized as risky devices that can transfer potentially sensitive data to Chinese infrastructure.

All entities subject to the Czech Cybersecurity Act, including energy, transport, healthcare, public administration, financial services, and other critical industries, must adopt security measures to mitigate risks.

NUKIB’s warning does not impose a ban on transferring data to the PRC or allowing remote administration from it, but critical infrastructure organizations must now include the threat in their risk analysis and decide what measures need to be applied to mitigate it.

The order, with its full text available here, is not legally binding for the general public.

However, NUKIB still recommends that Czech nationals carefully consider the bulletin and evaluate the products they use.

Read More
Bill Toulas

Latest

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

Newsletter

Don't miss

The Outer Worlds 2 studio Obsidian accused of “violating state wage and hour laws” for profit in California lawsuit

The company denied the allegations earlier this year Image credit: Microsoft Obsidian Entertainment, developers of The Outer Worlds 2 and Avowed, have been sued in California for allegedly engaging "in a systematic pattern of wage and hour violations". The case was initially filed in the Superior Court of Orange County by plaintiff Victoria Turner in

PlayStation CEO Responds to Reports They Are No Longer Releasing Single-Player Games on PC

by William D'Angelo , posted 2 days ago / 15,994 Views Sony Interactive Entertainment CEO Hideaki Nishino was asked about the recent reports that claim first-party narrative single-player PlayStation games would no longer release on PC and remains exclusive to PlayStation consoles, while live service titles would still come to PC to reach a wider

2026 World Cup: How Portugal can get the best from Cristiano Ronaldo – Ex-Super Eagles captain Oliseh

Soccer Cristiano Ronaldo of Portugal. Copyright: xBahhoxKarax Former Super Eagles...

2026 World Cup: Ex-Nigeria striker warns ‘tactically dull’ South Africa ahead of must-win Korea clash

Soccer South Africa head coach Hugo Broos. Copyright: Imago Former...

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID