Since 2020, Czech Republic's NÚKIB has run Flowmon's machine-learning network anomaly detection—combining ML, heuristics and behavioural analytics across ~40 algorithms—across ministries and civil-service bodies, though tool-specific detection figures remain unpublished.
Continuous operational deployment across the civil service (2020-2026)
Details
Maturity
Established
Promoter
NÚKIB (National Cyber and Information Security Agency) / Government CERT (CSIRT.CZ)
Period
2020–2026
Region (NUTS)
CZ064
Keywords
cybersecurity, network security, government IT, anomaly detection
Context
The National Cyber and Information Security Agency (NÚKIB), the Czech Republic's national cybersecurity authority headquartered in Brno, deployed Flowmon Anomaly Detection System (ADS), now marketed by Progress Software, across selected ministries and government institutions under the Government CERT (CSIRT.CZ) umbrella, starting in September 2020.
Objectives
The deployment aims to harden the security of the Czech civil service's networks by flagging deviations from normal traffic behaviour rather than relying on signature-based detection alone.
Activities
The system analyses network traffic flows using a combination of roughly 40 detection algorithms spanning machine learning, heuristics, statistical analysis, policy rules and traditional signatures, and in 2026 NÚKIB's CYRIS research-and-development platform hosted a spring working session explicitly connecting ongoing R&D to the practical use of tools like Flowmon across partner organisations.
Results
Flowmon ADS has remained an active part of NÚKIB's toolkit for six years since its September 2020 rollout, but NÚKIB's annual reports document only agency-wide incident totals (262 in 2023, 268 in 2024) that are not broken out by detection tool, so no independently verifiable count of threats caught specifically by Flowmon ADS is publicly available.
Conclusions
Most available sourcing on this deployment originates from vendor press materials and vendor-adjacent trade coverage rather than independent investigative reporting, and NÚKIB has not published a tool-specific performance evaluation, false-positive rate, or detection count, though the deployment's six-year continuity and its integration into NÚKIB's ongoing CYRIS R&D programme are the clearest available evidence it remains a genuine, sustained operational tool rather than an abandoned pilot.
Implementation
Indicative cost
Medium (€50k–€500k)
Time to results
Long (> 3 years)
Staffing & skills
NÚKIB (National Cyber and Information Security Agency), operating the deployment under the Government CERT / CSIRT.CZ umbrella, Progress Software / Flowmon as the commercial platform vendor
Conditions for success
Integration into NÚKIB's ongoing CYRIS research-and-development programme, connecting research to practical use across partner organisations
Combining multiple detection methods (machine learning, heuristics, statistical analysis, policy rules, signatures) rather than relying on any single approach
Deployment across multiple ministries and civil-service institutions under a shared Government CERT umbrella rather than a single agency
Common failure modes
No tool-specific detection or false-positive rate has ever been published by NÚKIB
Available sourcing is dominated by vendor press releases and trade coverage rather than independent evaluation
National incident totals in NÚKIB's annual reports are agency-wide and cannot be attributed specifically to Flowmon ADS
An open-source Analyzer module, built by STACC for Estonia's Information System Authority (RIA), applies adaptive statistical models to X-Road's data-exchange …
In a 2023–24 operational pilot ordered under a presidential AI directive, CISA compared AI/LLM-based vulnerability-detection tools against its existing methods …