BIS Annual Report Reveals How Russia Is Changing Its Tactics and China Is Stepping Up Intelligence Pressure
The Security Information Service’s new annual report shows that the Czech security environment continues to evolve. According to the BIS, Russia continues its intelligence, cyber, and influence operations and is also using new methods to recruit individuals for specific tasks. China focuses primarily on acquiring information, technology, and strategic know-how. In addition, cyberattacks, extremism, terrorism, and the circumvention of sanctions remain significant risks. For the Czech Republic, this means that national defense is no longer solely a matter for the military. Equally important is the resilience of institutions, critical infrastructure, industry, and the information space.
According to the BIS, 2025 was one of the most serious periods in terms of the security environment since the end of the Cold War. Russia’s war against Ukraine continued, international tensions rose, and at the same time, the way in which both state and non-state actors pursue their interests was changing.
Therefore, in its annual report, the BIS does not focus solely on traditional espionage. It also monitors cyber operations, foreign influence, the protection of sensitive technologies, the circumvention of sanctions, and other activities that could harm the security or economic interests of the Czech Republic.
It devotes the most attention to Russia. While the reduction of Russia’s diplomatic presence in the Czech Republic has made the traditional work of Russian intelligence services more difficult, it does not mean the end of such activities. Moscow is seeking other ways to gather information, influence the environment in European countries, and support activities that could undermine their stability.
This development fits into a broader picture also described by NATO. The Alliance considers Russia to be the most significant and direct threat to the security of its allies and highlights a combination of conventional, cyber, and hybrid tools. These include, for example, sabotage, cyberattacks, electronic jamming, disinformation, political influence, and economic coercion.
One notable trend highlighted by the BIS is the so-called “disposable agents.” These are not necessarily professional intelligence operatives. Individuals may be approached via the internet and accept a specific task in exchange for financial compensation.
The main advantage of this model for the client is the low risk involved. There is no need to build a long-term relationship with the agent or integrate them into an extensive intelligence network. The individual is given a task that may be relatively simple to carry out, and contact can then be severed.
At the same time, the BIS draws attention to an important fact: in the Czech Republic in 2025, it was not possible to reliably confirm Russian coordination or preparation of such attacks. It is therefore not possible to automatically attribute every similar activity in Europe to Russian state authorities.
This nuance is crucial. The role of an intelligence service is not to draw political conclusions, but to identify specific links and assess their significance. That is precisely why it is more accurate to speak of a trend that the BIS has observed than to claim that every single case is part of a centrally coordinated Russian operation.
For NATO, this development has broader implications. Hybrid operations allow an adversary to act below the threshold of open military conflict. In recent years, the Alliance has recorded cases in member states of sabotage, violent incidents, cyberattacks, and other activities that it attributes to Russian hybrid operations.
According to the BIS, Chinese activities are of a different nature. The report highlights, above all, efforts to acquire information, knowledge, and technologies that may have strategic value.
Attention need not be focused solely on government institutions. Academic and research institutions, technology firms, and companies possessing specific know-how are also significant targets.
It is precisely here that security and economic policies are increasingly intertwined. Information on artificial intelligence, semiconductors, energy, advanced manufacturing, or defense technologies may not be classified in and of itself. However, the systematic acquisition of such information can be significant for the state’s technological and strategic competitiveness.
NATO views China as a systemic challenge. Among other things, it highlights China’s military growth, cyber activities, and cooperation with Russia. In its 2025 report, NATO also notes that following a cyber campaign against the Czech Ministry of Foreign Affairs in May 2025 – which the Czech Republic attributed to China – the North Atlantic Council issued a statement of solidarity with the Czech Republic.
The Czech experience is thus not an isolated case. It is part of a broader European problem concerning the protection of technology, research, and critical systems.
At the same time, the importance of cybersecurity is growing rapidly. Modern conflict does not necessarily begin with an attack on a military target. The first strike may be directed against information systems, the energy sector, transportation, communications, or government administration.
NATO explicitly states that adversaries use cyber operations to gather intelligence, steal intellectual property, disrupt government services, and damage critical infrastructure. The Alliance therefore views cyberspace as an environment of constant competition.
Furthermore, in July 2026, NATO once again condemned Russia’s ongoing malicious cyber activities directed against allies and critical infrastructure. At the same time, the Alliance stated that it had further strengthened its ability to integrate cyber effects into its operations, missions, and activities.
For the Czech Republic, this means that cyber defense cannot be viewed merely as a technical matter for a few agencies. It is part of the country’s overall defense capability.
Another area where security and economic interests intersect is technology protection and export control.
The Czech Republic is home to industrial companies whose products can have both civilian and military applications. This heightens the importance of export controls and preventing the circumvention of sanctions regimes.
It is not just a matter of preventing the direct sale of prohibited goods. Complex supply chains, intermediaries, and re-exports via third countries can also pose risks.
This issue is also significant for the Czech defense industry. At a time when NATO is significantly increasing defense production and European countries are expanding their manufacturing capacities, the value of technologies, production facilities, and know-how is also growing. Protecting these capacities is therefore not merely a matter of economic security; it is part of defense policy.
The BIS Annual Report fits into a broader shift in the European security environment.
Today, NATO is not merely addressing the possibility of a conventional military attack. At the same time, the Alliance is strengthening its ability to respond to cyber operations, sabotage, information manipulation, and other hybrid activities.
In June 2026, NATO described the security environment as the most dangerous since the end of the Cold War. In addition to Russia’s war against Ukraine, it highlighted accelerating hostile activities against member states, including cyberattacks and sabotage of critical infrastructure.
At the same time, the importance of the technological and industrial base is growing. At the summit in Ankara in July 2026, the allies announced more than $50 billion in new acquisitions and a commitment to further expand joint production capabilities. Among the new priorities are, among other things, deep precision strikes, integrated air and missile defense, unmanned systems, advanced technologies, and intelligence capabilities.
This is an important shift. Security policy is becoming increasingly intertwined with technology policy, industry, and the state’s ability to protect its own know-how.
The most important message from the BIS for 2025 is not a single specific case. It is the changing environment in which Czech security operates.
According to the BIS, Russia continues its intelligence, cyber, and influence operations and is seeking new ways to operate in European countries. China is taking a different approach and focusing, among other things, on information, technology, and strategic knowledge. At the same time, other threats remain relevant, ranging from cybercrime to extremism and terrorism.
It is crucial for the Czech Republic to recognize that none of these threats exists in isolation.
Espionage may be linked to technology. Technology is linked to the defense industry. The defense industry is linked to manufacturing capacity. Manufacturing capacity is linked to energy, transportation, and supply chains. And all of these areas may simultaneously be exposed to cyber or information operations.
That is why the very meaning of defense capability is changing.
A modern state needs more than just soldiers, tanks, aircraft, and ammunition. It needs secure data networks, a resilient energy sector, protected critical infrastructure, functional intelligence services, control over strategic technologies, and an industrial base capable of functioning even in times of crisis.
The BIS Annual Report shows that the Czech Republic’s security borders no longer lie solely on a map.
They can run through the server room of a government agency, a university laboratory, a manufacturing plant, a data network, a railway hub, or a person whom someone contacts via the internet with an offer of financial reward for a specific task.
This does not mean that the Czech Republic is facing an imminent military attack. It does mean, however, that adversaries can advance their interests over the long term, gradually, and without crossing a threshold that would automatically trigger a military response from NATO.
That is precisely why, in the coming years, it will not only be the amount of money invested in defense that matters, but also the resilience of the entire state.
The military must be capable of fighting. Intelligence services must be able to detect the adversary. Industry must protect its technologies while also producing for defense. Critical infrastructure must withstand an attack. And society must be able to recognize attempts at manipulation.
Today, the security of the Czech Republic is not defended solely on the battlefield. Its resilience is also determined in cyberspace, industry, the energy sector, academia, and the information sphere.

















