evidoria

← Back to browse

Good practice Imported

NÚKIB's Flowmon ADS — Czech Republic's Machine-Learning Anomaly Detection Across the Civil Service

Czechia · Brno · See the Czechia profile · See the Brno profile

Evidence: Descriptive / self-reported Top 66% 53/100 · Ask Evidence Copilot about this practice

Since 2020, Czech Republic's NÚKIB has run Flowmon's machine-learning network anomaly detection—combining ML, heuristics and behavioural analytics across ~40 algorithms—across ministries and civil-service bodies, though tool-specific detection figures remain unpublished.

~40
Detection algorithms combined (machine learning, heuristics, statistical analysis, policy rules, signatures)
6 years (since September 2020)
Continuous operational deployment across the civil service (2020-2026)
NÚKIB's Flowmon ADS — Czech Republic's Machine-Learning Anomaly Detection Across the Civil Service

Details

Maturity
Established
Promoter
NÚKIB (National Cyber and Information Security Agency) / Government CERT (CSIRT.CZ)
Period
2020–2026
Region (NUTS)
CZ064
Keywords
cybersecurity, network security, government IT, anomaly detection

Context

The National Cyber and Information Security Agency (NÚKIB), the Czech Republic's national cybersecurity authority headquartered in Brno, deployed Flowmon Anomaly Detection System (ADS), now marketed by Progress Software, across selected ministries and government institutions under the Government CERT (CSIRT.CZ) umbrella, starting in September 2020.

Objectives

The deployment aims to harden the security of the Czech civil service's networks by flagging deviations from normal traffic behaviour rather than relying on signature-based detection alone.

Activities

The system analyses network traffic flows using a combination of roughly 40 detection algorithms spanning machine learning, heuristics, statistical analysis, policy rules and traditional signatures, and in 2026 NÚKIB's CYRIS research-and-development platform hosted a spring working session explicitly connecting ongoing R&D to the practical use of tools like Flowmon across partner organisations.

Results

Flowmon ADS has remained an active part of NÚKIB's toolkit for six years since its September 2020 rollout, but NÚKIB's annual reports document only agency-wide incident totals (262 in 2023, 268 in 2024) that are not broken out by detection tool, so no independently verifiable count of threats caught specifically by Flowmon ADS is publicly available.

Conclusions

Most available sourcing on this deployment originates from vendor press materials and vendor-adjacent trade coverage rather than independent investigative reporting, and NÚKIB has not published a tool-specific performance evaluation, false-positive rate, or detection count, though the deployment's six-year continuity and its integration into NÚKIB's ongoing CYRIS R&D programme are the clearest available evidence it remains a genuine, sustained operational tool rather than an abandoned pilot.

Implementation

Indicative cost
Medium (€50k–€500k)
Time to results
Long (> 3 years)
Staffing & skills
NÚKIB (National Cyber and Information Security Agency), operating the deployment under the Government CERT / CSIRT.CZ umbrella, Progress Software / Flowmon as the commercial platform vendor

Conditions for success

  • Integration into NÚKIB's ongoing CYRIS research-and-development programme, connecting research to practical use across partner organisations
  • Combining multiple detection methods (machine learning, heuristics, statistical analysis, policy rules, signatures) rather than relying on any single approach
  • Deployment across multiple ministries and civil-service institutions under a shared Government CERT umbrella rather than a single agency

Common failure modes

  • No tool-specific detection or false-positive rate has ever been published by NÚKIB
  • Available sourcing is dominated by vendor press releases and trade coverage rather than independent evaluation
  • National incident totals in NÚKIB's annual reports are agency-wide and cannot be attributed specifically to Flowmon ADS

Commonly funded by

Digital Europe Programme National / regional programmes

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful