Business Insights Cybersecurity Blog by Bitdefender

Why Are So Many Security Professionals Keeping Breaches Quiet?

Written by Bruce Sussman | Sep 03, 2026

More than half of IT & cybersecurity professionals who experienced a breach in the past 12 months say they were told to keep it confidential, even when it was reportable.

That finding comes from the 2026 Bitdefender Cybersecurity Assessment, and it’s a trend we’ve tracked for several years running. Disclosure rules have expanded significantly since we first asked about this topic in 2023 but the pressure to hide breaches continues.

How Many Organizations Hide Breaches?

Roughly half of 1,200 IT and security professionals surveyed reported a breach or security incident in the last 12 months. Of that group, 55.2% said they had been asked to keep a breach confidential even when it should have been disclosed.

That’s a snapshot. Now, here’s the trendline:

Image: Data from the 2026 Bitdefender Cybersecurity Assessment.

In 2023, 42.0% of respondents said they’d been asked to keep a breach quiet. By 2025 that number had climbed to 57.6%. In 2026 it settled back to 55.2%, which appears to be a plateau, not a reversal.

According to the assessment, IT & security professionals in the U.S. are most likely to be pressured into hiding a breach, but a significant number of professionals in every country surveyed face similar pressure. Here are the data points:

Image: Data from the 2026 Bitdefender Cybersecurity Assessment.

A majority of IT & cybersecurity professionals in the U.S., Germany, the UK, and Singapore say they were asked to keep a breach silent during the last 12 months. In France and Italy, just under 50% report having to stay silent.

What Are 3 Top Reasons Companies Hide a Data Breach?

During a recent webinar on Cybersecurity Benchmarks and Blind Spots, our panel of experts uncovered three significant reasons organizations might hide a breach:

1. Attackers are turning silence into a business model.
2. The perceived cost of disclosure is higher than the perceived risk of staying quiet.
3. There could be a culture of silence within the organization.

Let’s take a brief look at each of these explanations.

How Are Attackers Turning Silence Into a Business Model?

Threat actors are increasingly designing attacks that only a handful of people ever see. They've discovered that selling silence to a subset of the business is often cheaper and more effective than interfering with all of it.

“What this means, if you are a victim, is that instead of shutting down the whole company and showing every single employee on the monitor that you have been hacked, the attacks are now much quieter, with attackers sometimes talking secretly to the IT team,” says Martin Zugec, Bitdefender Technical Solutions Director.

Attackers offer the IT or security team clean recovery, and pitch confidentiality as part of the deal: pay up and this stays between us. The organization can potentially hide the breach from the outside world, and the threat actors make money. Silence is now a business model.

What Are the Perceived Risks of Breach Disclosure vs. Non-Disclosure?

Cybersecurity is always about balancing risk, and organizations may think the risks from reporting a breach are too high. “It could be concern over potential fines, reputational damage, the impact on customer retention, or similar fears,” says Nicholas Jackson, Director of Cybersecurity Services at Bitdefender. 

Organizations who fail to report breaches hope to avoid these consequences. However, threat actors are increasing the risk from non-disclosure, unless an organization pays them.

Says Jackson, “It's more likely now that attackers will make your data public or threaten to inform regulators about what happened if you fail to pay. If they reveal your breach and the fact you tried to hide it, that could have a longer negative impact than disclosing the breach yourself.”

How Can a Culture of Silence Hurt Cybersecurity?

Some organizations send the message that they would prefer perfect end-users instead of having fast reporters who see something and say something. This creates a culture of silence where no one wants to admit mistakes.

“In that kind of environment, people can wait hours to report they clicked on something. Meanwhile, the attacker is establishing persistence, stealing credentials, and trying to move laterally,” says Josh Armstrong, Sr. Manager of the Bitdefender Global SOC.

A culture of silence costs you dwell time, which is an extremely expensive variable in incident response. If this type of culture exists within leadership, it’s not surprising the organization will choose to keep a breach silent.

What Should Security Leaders Do Now, Before a Breach?

Decide your disclosure posture before an incident, not during one. Build a no-blame internal reporting culture that rewards speed. And treat prevention as the strategy that keeps you out of the decision entirely, because the cheapest breach is the one that never happened.

Want the full picture? Download the 2026 Bitdefender Cybersecurity Assessment. More than 1,200 IT & security professionals across six countries share their views on breach disclosure, attack surface challenges, AI for threat actors and defenders, and the pressures shaping key security decisions.