BIS After Ten Years Under Lt. Gen. Michal Koudelka: A Stronger Service in a More Dangerous World?
The Security Information Service’s 2025 Annual Report is not just another annual summary of Russian, Chinese, cyber, economic, or extremist threats. From a broader perspective, it also serves as a review of an exceptionally significant phase in the history of the Czech intelligence system. This is, in fact, the last public annual report issued under the leadership of Lieutenant General Michal Koudelka, whose second term will end in February 2027. That is precisely why it is appropriate to read this year’s document not only as a description of the security environment in 2025, but also as an indirect assessment of nearly a decade of BIS leadership and as an opportunity to ask a broader question: Is the Czech Republic truly safer after this decade, or does it primarily have a significantly more capable, self-assured, and publicly visible intelligence service in an environment that is itself substantially less secure?
Public annual reports by intelligence agencies are unique in nature. By their very nature, they cannot contain the most critical information, because an agency that disclosed its key sources, methods, operational procedures, and most valuable intelligence would cease to fulfill its fundamental function. Nevertheless, these documents have extraordinary analytical value. They reveal not only what the service knows, but also what it wants the public to know it knows, what it considers significant, and how it interprets the security environment. It is precisely in this sense that the 2025 annual report is exceptionally interesting.
In his opening remarks, Koudelka describes the year 2025 as one of the most serious in terms of security since the end of the Cold War. This statement is not merely dramatic rhetoric. Russia continues its aggression against Ukraine and its hybrid operations against European states; China is ramping up its intelligence and cyber pressure; proliferation activities are taking on new technological dimensions; European security is burdened by conflicts in the Middle East; and, at the same time, the long-term assumptions underpinning the transatlantic order are changing. However, a decade-long review of the BIS annual reports allows us to draw an even more significant conclusion: perhaps we are no longer witnessing a series of separate security crises, but have entered an environment of permanent strategic instability, in which the emergence of a crisis is not exceptional – only its specific form is.
From Espionage to Permanent Confrontation
When Michal Koudelka took the helm of the BIS in 2016, the Czech Republic found itself in a security environment that might seem almost comfortable by today’s standards. Although Russia had already occupied Crimea and was waging war in eastern Ukraine, and Europe was grappling with the consequences of the migration crisis and terrorist attacks, the perception persisted that these were isolated problems that could be gradually stabilized. Developments in the years that followed showed that this perception was overly optimistic.
Throughout virtually the entire period under review, Russia and China remained the two most significant foreign state actors of intelligence interest. Thus, while the fundamental identification of adversaries has not changed, the nature of their activities – as well as the Czech state’s willingness to publicly name these activities – has changed fundamentally. Traditional espionage and influence operations have gradually evolved into hybrid confrontation; hybrid confrontation has given way to open subversion; and the state has moved from merely drawing general attention to hostile activities to public attributions, sanctions, the expulsion of diplomats, and specific countermeasures.
The year 2021 saw the public attribution of the explosions in Vrbětice to members of GRU Unit 29155; 2022 brought Russia’s full-scale invasion of Ukraine; 2024 brought the phenomenon of so-called “Telegram agents” and the public attribution of the APT28 attack to Russia; and 2025 marked another qualitative milestone in the form of the first-ever public political attribution of a serious cyberattack against the Czech Republic to the People’s Republic of China – specifically, to the actor APT31 linked to the Chinese intelligence apparatus.
This development represents a gradual transition from traditional counterintelligence secrecy to strategic attribution. A modern intelligence service does not merely expose the adversary; under certain circumstances, it also publicly identifies the adversary, compromises its infrastructure, provides the basis for sanctions decisions, and helps the state increase the political, economic, and operational costs of hostile activities. During Koudelka’s decade in office, the BIS thus became not only the state’s “sensor” but, increasingly, one of the tools of active security policy. It is precisely here, however, that one of the important questions for the future arises: where does intelligence information end and security policy begin, and how should this boundary be institutionally controlled?
Russia: From Diplomatic Cover to Disposable Agents
Russia best illustrates this shift in the nature of threats. Following the reduction of Russia’s diplomatic presence after the Vrbětice incident, one might have gotten the impression that Czech counterintelligence had significantly narrowed the adversary’s operational space. To a certain extent, this was indeed the case. Limiting the number of Russian diplomats made the traditional model of intelligence operations conducted under diplomatic cover significantly more difficult. At the same time, however, it forced the adversary to adapt.
A classic intelligence officer operating under diplomatic cover can be monitored, restricted in his movements, or expelled. It is more difficult to counter an individual whom an enemy service recruits via the internet, social media, or an encrypted platform to carry out a single task. Modern subversion is thus becoming decentralized. An adversary’s intelligence service no longer needs to establish an extensive, long-term network of agents within the target country. For many operations, a remote control mechanism, financial incentives, cryptocurrency, anonymized communication, and an individual willing to set a building on fire, photograph infrastructure, or carry out another act of sabotage may be sufficient.
The 2025 Annual Report states that the risk of such operations declined in the first half of the year but subsequently returned to an upward trend. At the same time, however, it notes a crucial fact: none of the incidents investigated on the territory of the Czech Republic in 2025 was reliably confirmed as Russian sabotage. It is precisely this distinction that is important. The existence of a threat must not be confused with automatic proof of its realization. High-quality counterintelligence is not that which sees the GRU behind every fire or incident, but rather that which can accurately distinguish between a criminal act, spontaneous extremism, coincidence, and a state-directed operation – and at the same time is capable of intervening before the adversary achieves the intended effect.
Vrbětice: The Moment When Intelligence Changed Foreign Policy
If we were to choose a single moment symbolizing Koudelka’s decade, it would likely not be a statistic or a graph from an annual report, but rather Vrbětice. The public attribution in April 2021 of the 2014 ammunition depot explosions to members of Russian military intelligence demonstrated just how far-reaching the consequences of high-quality intelligence can be.
This was followed by a massive reduction in Russia’s diplomatic presence, a diplomatic conflict with Moscow, reactions from allied nations, and a significant shift in the Czech political perspective on Russian activities. In this case, the intelligence report turned into a political event of the highest order. Vrbětice therefore represents one of the most significant successes of Koudelka’s BIS, but at the same time highlights the enormous responsibility that such capabilities entail. For if intelligence can fundamentally influence a state’s foreign policy, the opposite question must always be asked: what happens if it is misinterpreted?
The Ricin Case as a Reminder of the Limits of Intelligence Work
That is precisely why the so-called ricin case from 2020 is also part of an honest assessment of Koudelka’s era. For several weeks at that time, the Czech public was gripped by the notion of an imminent threat against Czech local politicians. However, the subsequent investigation revealed that the case stemmed from an internal dispute among employees of the Russian diplomatic mission.
It would be incorrect to use this case as simple proof of a failure on the part of the BIS. On the contrary, it illustrates the very essence of intelligence work. Intelligence operates with incomplete information, probabilities, deliberate deception, and an adversary who actively seeks to lead the analyst to a false conclusion. Intelligence, therefore, is not a court verdict but a qualified assessment of uncertainty.
The problem arises when a preliminary intelligence indicator enters the public sphere and begins to be perceived as a definitively confirmed fact. Koudelka’s BIS has learned to communicate publicly much better over the past decade than its predecessors did. However, it will be all the more important in the future to be able to communicate just as openly not only about successes but also about corrections, uncertainties, or mistakes.
The BIS has learned to speak. The question is, where does credibility end and PR begin?
One of the most striking institutional changes of the Koudelka decade is the transformation of the BIS’s public image. Earlier annual reports were predominantly technical, legalistic, and graphically austere documents. Since 2020, their format has changed significantly. They now feature photographs, graphics, more readable language, a greater emphasis on explaining the service’s activities, and, gradually, more active management of the institution’s public image.
In the 2025 report, we already find separate chapters dedicated to careers at the BIS and communication with the public. The service publishes data on media appearances, social media, and communication with journalists and citizens. This is not merely a change in graphic design, but evidence of a broader transformation of the institution’s very identity. In his latest foreword, Koudelka speaks of building a bridge of trust between the service and the public, and it can be said that this project has been largely successful.
The BIS is no longer a secretive institution about whose activities citizens know practically nothing. It actively explains security threats, communicates, presents results, recruits new staff, and builds its own institutional brand. But this is precisely where another question arises: should a secret service have a brand, and where does legitimate public communication end and institutional PR begin? A democratic state needs trustworthy intelligence services, but it does not need services that are popular. The difference between trust and popularity is, in fact, much more fundamental than it may seem at first glance.
The budget is growing, but the technology gap may be growing even faster
In addition to its operational and communications transformation, the BIS has also seen significant budget growth. The agency’s actual expenditures rose from approximately 1.37 billion crowns in 2017 to 2.48 billion crowns in 2025 – a nominal increase of roughly 81 percent. However, this figure alone can be misleading if we do not place it within a broader technological context.
The security environment of 2025 is, in fact, incomparably more technologically demanding than that of 2017. Intelligence services must invest in cyber capabilities, data analytics, cryptography, technical surveillance, working with large datasets, and, increasingly, artificial intelligence. The annual report itself highlights a structural mismatch between the service’s needs and available capital resources.
This is more important than the nominal budget growth itself. The state may have high-quality analysts and operatives, but if it provides them with yesterday’s technology, they will systematically lose out to adversaries using tomorrow’s technology. Future competition among intelligence services may not be decided by the number of agents, but rather by computing power, data superiority, the quality of algorithms, the speed of the analytical cycle, and the ability to integrate HUMINT, SIGINT, OSINT, and artificial intelligence into a single decision-making system.
The greatest threat may not fly a national flag
One of the most interesting topics in this year’s report is the online radicalization of minors. The number of recorded cases is not high, but the significance of this phenomenon cannot be assessed solely on the basis of statistics. What is significant is the shift in the mechanism of radicalization. It is increasingly moving from organized structures to the digital environment; ideologies are fragmenting, and an individual no longer needs to be a member of an extremist organization or personally know another radical. The algorithmically driven information ecosystem itself can become the environment in which radicalization takes place.
This brings us to a threat that may gradually transcend the traditional paradigm of counterintelligence work. Russia and China are state actors with institutions, budgets, doctrines, and identifiable strategic interests. An algorithmically driven information environment may not have such an actor, yet it can still create polarization, radicalization, social fragmentation, and, consequently, concrete security implications. For intelligence services, this represents a fundamental shift: the adversary may no longer be solely a person, an organization, or a foreign state, but also an emergent effect of a digital system.
The Koudelka Era and the Conflict with Politics
It is impossible to assess the BIS’s ten-year leadership without mentioning the extraordinary political conflict surrounding its director. During Miloš Zeman’s presidency, Michal Koudelka became the subject of repeated public criticism, and the dispute gradually came to concern not only the director himself but also the BIS’s very stance on Russian and Chinese activities. Koudelka’s position became a major political issue for several years.
The subsequent change at Prague Castle brought about a symbolic reversal, and President Petr Pavel gradually promoted Koudelka to the rank of lieutenant general. One president had long questioned his tenure, while another honored him with the highest general’s rank attainable within the intelligence services. The director remained; the political landscape changed.
This fact can be interpreted as evidence of the BIS’s institutional resilience. At the same time, however, it serves as a warning. The director of the intelligence service must not become a symbol of one political camp against another. The intelligence service must outlast governments, presidents, parliamentary majorities, and ideological conflicts. Its loyalty lies not with specific politicians, but with the constitutional state.
Ten Years of Koudelka: A Successful Transformation, or Just the First Stage?
Based on publicly available data, Koudelka’s decade can be assessed as a period of significant institutional strengthening of the BIS. The service has gained a stronger international standing, has helped uncover exceptionally serious Russian operations, has contributed to the reduction of Russian intelligence infrastructure, has increased its ability to publicly attribute hostile activities, has expanded its role in economic security and the vetting of foreign investments, and has significantly strengthened its public communications.
However, the greatest success of this era may also be its future risk. The BIS has become a visible, self-assured, respected, and politically relevant institution. Following Koudelka’s departure, it will be all the more important to verify whether its strength has become overly dependent on the personality of a single director. A truly mature institution is not recognized by how well it functions under a strong leader, but by whether it functions just as well after his departure.
The latest report is not a full stop, but a handover protocol
The BIS Annual Report for 2025 is therefore not merely a final report on a single career. It is also a handover protocol. Koudelka will hand over to his successor a service that is undoubtedly more self-assured, technologically capable, internationally connected, and more visible to the public than it was ten years ago. At the same time, however, he will hand over a world that is significantly more dangerous.
Russia has shifted from influence operations to open warfare and subversion. China is gradually evolving from an economic and intelligence issue into a full-fledged cyber adversary. Technology is dramatically shortening the time between the emergence of a new threat and its widespread use. Artificial intelligence enables the automation of information operations, radicalization is becoming individualized, and the boundaries between external and internal security are increasingly blurring.
Therefore, the main question in 2027 will not be merely who will become the new director of the BIS. More importantly, the question will be what kind of BIS the Czech Republic will need in 2035. Will a service that gathers information and alerts the government be sufficient, or will the country need an institution capable of identifying and attributing hybrid, cyber, economic, and information operations in near real time – and, together with other elements of the security system, helping to neutralize them before they achieve a strategic effect?
If the latter is true, the Czech intelligence system may face an even greater transformation than the one it underwent during Koudelka’s ten years in office. And with that, one more principle must hold true: the stronger the intelligence services are, the stronger the democratic oversight of their activities must be. Otherwise, we could win the fight against our adversaries while simultaneously weakening the very system we are meant to protect.
Four Questions for Lieutenant General Michal Koudelka
Ten years at the helm of counterintelligence is long enough that the director of the service need not limit himself to assessing just one year. It is an opportunity to also acknowledge his own successes, mistakes, and unfinished work; that is why our editorial team posed the following four questions to BIS Director Lt. Gen. Michal Koudelka:
General, in your first annual reports, you described the Russian threat using the language of hybrid strategy and conceptual frameworks; in 2021, you faced the most politically explosive moment of your career – the public attribution of the Vrbětice incident – and in connection with the year 2025, the Czech Republic publicly attributed a serious cyberattack to China for the first time. Looking back over the past decade, which of these moments marked a true structural turning point in the Czech Republic’s security environment, and which was, conversely, merely a louder variation on the same old problem? And how do you assess the year 2020 in retrospect, when you admitted to using more cautious wording in the annual report – was it purely a matter of professional restraint, or did the political climate at the time also play a role?
The most significant and pivotal moment was undoubtedly the uncovering of the Vrbětice case – not only for its intelligence value, which definitively confirmed the capabilities of the BIS, but especially for its political and, above all, security value. The subsequent massive reduction in the number of diplomatic (intelligence) personnel from the Russian Federation in the Czech Republic restored balance to the previously disproportionate diplomatic representation between our mission in Moscow and the Russian mission in Prague. It was a crucial, truly historic step for national security. Incidentally, we had been drawing attention to the problem of the Russian diplomatic corps’ disproportionately large presence for many years.
I’m not sure if you’re referring to the annual report published in 2020 – that is, the report for 2019 – or the actual annual report for 2020 published in 2021. In any case, the content of public annual reports is never influenced by any form of self-censorship, but is determined solely by the information available for the given period.
The public annual report is, by necessity, only a fraction of what the BIS actually produces. Based on your ten years of experience, which types of intelligence products have proven to be most useful for decision-making by the government, ministers, and the President of the Republic? Conversely, where is there still a gap between what the BIS is able to uncover and convey, and what political leaders are willing or able to actually do based on this information? And how do you distinguish in practice between a tip that may turn out to be overrated and a finding that must lead to an immediate response from the state?
Governments should not simply obey intelligence agencies, but should listen to them, assign them specific tasks, oversee them, and use their information to inform their strategic decision-making. The amount of information that an intelligence service can gather is enormous, but the intended recipients must receive only the truly critical information – that which we have assessed as important for a given area and worthy of the attention of the country’s leadership. Therefore, we cannot categorize our information as critical, important, or less significant. If, for example, we submit a piece of information to the Government of the Czech Republic, then it is undoubtedly important. What I consider crucial in this regard is how the approach of all governments to our information has changed over the past ten years: it no longer ends up shelved and forgotten, but rather the highest representatives of the state actively work with it and use it in their decision-making.
In your article, you mention the so-called “Ricin Case.” In its own way, this was also a landmark case. Although it was an exceptionally successful intelligence operation handled with record speed, at the time, disinformation sources managed to push a narrative into the public sphere – and even into the mainstream media – about an alleged blunder by the BIS. Nothing could be further from the truth. Just a quick summary:
- The BIS received anonymous, credible, and verifiable information about a potential threat to certain politicians. Everything described in the email actually took place and was generally confirmed by other, highly reliable sources. No security agency in the world can ignore such information.
- A decision was made to provide police protection to those politicians as a precautionary measure. The fundamental problem was that one of them leaked this information to journalists. The story thus took on a life of its own.
- Meanwhile, the BIS carried out outstanding intelligence work. Within 48 hours, we identified the source of the anonymous tip and his motivation. The perpetrators were two members of the Russian intelligence services.
- Both were declared persona non grata and had to leave the Czech Republic.
- Our agency was subsequently publicly commended by Prime Minister Babiš. This, too, clearly demonstrates just how successful this case was.
The annual report highlights artificial intelligence and disinformation, growing Chinese cyber activities, and the online radicalization of minors. Which of these trends do you consider to be the most underestimated by both the government and the public over the next five to ten years? And is the BIS’s current legislative and institutional framework even capable of keeping pace with security phenomena whose cycles of emergence, spread, and escalation are no longer measured in years, but sometimes in months or weeks?
Security threats do not diminish over time; on the contrary, new ones keep emerging, and we must be able to respond to them. Ten or more years ago, cyber threats were largely marginal; today, they rank among the primary threats. The phenomenon of AI falls into the category of “a good servant but a bad master.” It is an area to which we are devoting significant attention, both in terms of its use for intelligence work and as a potential threat and risk.
In your most recent opening remarks, you spoke about building a bridge of trust between the BIS and the public. If you look at the agency not as its current director, but as someone who will be handing it over to a successor, what three specific structural changes – whether legislative, budgetary, technological, or related to the coordination of the Czech intelligence and security system – do you consider to be unfinished business? And was the long-standing political conflict surrounding you a one-time episode, or did it reveal a structural vulnerability in Czech intelligence institutions against which the system should be better protected in the future?
One crucial area awaits my successor, and that is changing the legislative framework for our work. The laws that define our activities date back to 1994. Since then, the world has certainly not become safer – quite the opposite. I am convinced that our powers and a number of restrictions – which were understandable during the transition from a communist to a democratic system – no longer hold up today and may, at critical moments, unduly constrain the BIS in its operations, thereby limiting our capabilities.

















