Kyberbezpečnost
OK
When One Click Stops Production
A cyber attack does not have to affect just one device – it can disrupt production, logistics and the everyday running of a carmaker. Among the most serious threats is so-called ransomware, which can encrypt data, lock people out of systems and bring operations to a stop.
How to protect yourself
If something does not match the usual behaviour of your device, check it out. Even a seemingly small detail can help prevent bigger damage.
1
Verify attachments and links
If you are not sure, do not open the attachment or the link and verify the message in another trustworthy way.
2
Update your device
Regular updates are what fix the vulnerabilities that attackers can exploit.
3
Use approved software
Unverified applications can pose a security risk.
4
Protect your login details
Only enter your password on verified sites and do not log in via suspicious links.
5
Act fast
If you suspect your device has been compromised, stop working and do not open any further files.
Deset varovných signálů
1
Nesedí adresa odesílatele
Jméno je správné, ale doména za zavináčem je podezřelá, má například koncovku @micros0ft-support.com.
2
Nátlak na rychlou reakci
Odesílatel vám píše slova jako „okamžitě“, „poslední výzva“ apod.
3
Požadavek na heslo nebo přihlášení
Nikdy se nepřihlašujte z odkazu v e-mailu.
4
Nečekaný finanční požadavek
Všímejte si v e-mailu změny čísla účtu nebo žádosti o platbu.
5
Podezřelé přílohy
Nikdy neotevírejte dokumenty s makry a přílohy s příponami .ZIP, .EXE a vše nahlaste IT Security v útvaru FIG/2.
6
Podivný jazyk
E-mail může být psán špatnou češtinou nebo má nepřirozený tón a slovosled.
7
Nesedí kontext
Jestliže jste žádáni o potvrzení objednávky, ačkoli jste si nic neobjednali, e-mail nejlépe nahlaste nebo ignorujte.
8
Neobvyklé odkazy
V e‑mailu se objevují zkracovače (bit.ly) nebo cizí domény. Skutečnou adresu zkontrolujete tak, že na odkaz najedete myší.
9
Nesoulad v brandingu
Logo v e-mailu je rozmazané nebo má jiný počet písmen či odlišné barvy.
10
Žádost o diskrétnost
V e-mailu se objevují spojení: „nikomu nic neříkejte“ nebo od „vedení“.
The road to a ransomware attack begins inconspicuously – with an e-mail that looks trustworthy, an attachment, a link or a login on a fake page. A single moment like that can open up access to a device or an account for attackers.
How ransomware works
After the initial breach, attackers usually try to get their bearings in the environment and find out which systems, accounts or shared data they can access. The compromise does not have to be visible at first glance and can go on for some time without any obvious signs.
Once the attackers have the overview they need, they try to extend their permissions, get into other devices and search for important data. The encryption itself often comes only at the point when the attack is prepared to cause the greatest possible impact.
Access to data or systems may then be blocked, followed by a ransom demand.
Modern attacks often also involve stealing data and threatening to publish it. The company then has to deal not only with restoring its systems, but also with protecting sensitive information and managing the impact on operations.
An example from practice
In 2025, Jaguar Land Rover car maker faced a large-scale cyber incident that shut down part of its IT systems and significantly disrupted its production. The effects hit plants, employees, suppliers and the dealer network, and delayed the return to normal operations. According to available sources, the estimated damage may have reached around 2.5 billion dollars. This case shows that a cyber attack can quickly affect an entire production chain and have a major impact on operations.
Warning signs
You receive an e-mail with an attachment or a link that asks you to allow macros or content to run. After opening it, you find that your computer and applications are behaving unusually. Installations of unknown applications or error messages pop up on your computer. You then find that files and folders are inaccessible and that you are repeatedly prompted to log in.
If several of these signs appear at the same time, it may not be an ordinary technical fault, so contact Service Desk immediately.
Tip
Reporting in good time helps to limit the spread of the problem and protects devices, colleagues, systems and the operations of Škoda Auto. So if you suspect malware, ransomware or non-standard behaviour of your device, always contact Service Desk and follow their instructions. The Service Desk operates 24/7 and accepts requests via a web form, by phone on +420 326 817 777 or through e‑mail.
Cyber Security