Over Half of Security Pros Pressured to Hide Data Breaches, Study Finds
A 2026 Bitdefender assessment reveals a systemic culture of silence that persists despite strict global disclosure laws.
More than half of cybersecurity and IT professionals are being pressured to conceal data breaches, even when those incidents are legally required to be reported. This trend suggests a systemic failure in organizational culture that prioritizes immediate reputation management over legal compliance and long-term security.
According to the 2026 Bitdefender Cybersecurity Assessment, 55.2% of IT and security professionals who experienced a breach in the last 12 months were asked to keep the incident confidential. This pressure has remained stubbornly high over the last few years; the rate rose from 42.0% in 2023 to a peak of 57.6% in 2025 before settling at the current 55.2%. The pressure is most acute in the U.S., Germany, the UK, and Singapore. In the United States specifically, reporting from NetSec.news indicates that 7 out of 10 IT professionals were told to keep a breach quiet, and 30% of professionals actually followed those instructions to withhold reports despite legal requirements.
The Cost of Silence
This culture of secrecy persists despite the expansion of global disclosure mandates, including the GDPR in Europe and HIPAA in the United States. Organizations often fear the immediate fallout of a public disclosure—such as heavy fines, loss of customers, and immediate reputational damage—more than the latent risks of non-disclosure.
Compounding this issue is a shift in attacker behavior. Threat actors are now integrating "confidentiality" into their ransom business models. Martin Zugec, Bitdefender Technical Solutions Director, notes that attackers are turning silence into a business model, moving away from disruptive attacks toward quieter operations where they communicate secretly with IT teams to keep the breach hidden from the rest of the company and the public.
Industry Implications
This trend creates a dangerous security vacuum by increasing "dwell time," the duration an attacker remains undetected within a network. When breaches are hidden, attackers can establish deeper persistence and move laterally through systems without interference.
Furthermore, relying on the "honor system" of a threat actor creates a precarious dependency. If an organization pays for silence but the attacker later leaks the data or notifies regulators, the resulting fallout is far more severe. Nicholas Jackson, Director of Cybersecurity Services at Bitdefender, warns that if an attacker reveals both the breach and the attempt to hide it, the negative impact could be longer-lasting than if the organization had disclosed the event voluntarily.
What to Watch
As regulators continue to tighten disclosure windows and increase penalties for non-compliance, the tension between corporate image and legal duty is likely to intensify. The industry must now determine if these pressures are driven by mid-level management fear or top-down executive mandates. Future assessments will likely focus on whether the plateau in pressure signals a shift toward transparency or a permanent acceptance of shadow security practices.