More than half of IT and cybersecurity professionals who dealt with a breach in the past year say they were instructed to keep it confidential, even when disclosure was required. That figure comes from the 2026 Bitdefender Cybersecurity Assessment, a study Bitdefender has conducted for multiple years. Despite significant expansion of disclosure regulations since the question was first posed in 2023, the pressure to conceal breaches persists.

Approximately half of the 1,200 IT and security professionals surveyed reported experiencing a breach or security incident over the past 12 months. Among that group, 55.2% said they had been asked to keep a breach confidential even when it should have been disclosed, according to the report. The trend shows sustained pressure: in 2023, 42.0% of respondents said they'd been asked to keep a breach quiet, climbing to 57.6% by 2025 before settling at 55.2% in 2026. IT and security professionals in the United States face the highest likelihood of being pressured into hiding a breach, though significant numbers of professionals in every surveyed country encounter similar pressure. A majority in the U.S., Germany, the UK, and Singapore said they were asked to keep a breach silent during the last 12 months, while just under 50% in France and Italy reported having to stay silent.

During a recent webinar on Cybersecurity Benchmarks and Blind Spots, a panel of Bitdefender experts identified three primary reasons organizations might conceal a breach: attackers are turning silence into a business model, the perceived cost of disclosure exceeds the perceived risk of staying quiet, and there could be a culture of silence within the organization. "What this means, if you are a victim, is that instead of shutting down the whole company and showing every single employee on the monitor that you have been hacked, the attacks are now much quieter, with attackers sometimes talking secretly to the IT team," says Martin Zugec, Bitdefender Technical Solutions Director. Threat actors increasingly design attacks that only a handful of people ever witness, offering IT or security teams clean recovery with confidentiality pitched as part of the deal.

The report explains that organizations weigh the risks of reporting a breach—including potential fines, reputational damage, and customer retention impacts—against the risks of non-disclosure. However, threat actors are raising the stakes on non-disclosure by threatening to make data public or inform regulators if victims don't pay. According to Nicholas Jackson, Director of Cybersecurity Services at Bitdefender, if attackers reveal both the breach and the attempted cover-up, "that could have a longer negative impact than disclosing the breach yourself." A culture of silence within organizations also erodes cybersecurity by discouraging rapid incident reporting. When employees fear admitting mistakes, they can wait hours to report clicking on something suspicious, giving attackers time to establish persistence, steal credentials, and move laterally through networks. This culture of silence costs organizations dwell time, an extremely expensive variable in incident response.

The report recommends that security leaders decide their disclosure posture before an incident occurs, not during one. They should build a no-blame internal reporting culture that rewards speed and treat prevention as the strategy that keeps them out of the decision entirely, because the cheapest breach is the one that never happened. The study drew responses from more than 1,200 IT and security professionals across six countries, covering breach disclosure, attack surface challenges, AI's role for both attackers and defenders, and the pressures shaping key security decisions. Organizations that cultivate transparency internally and prioritize prevention may find themselves better positioned when—not if—an incident occurs. The fundamental tension between regulatory obligation and business fear won't resolve quickly, but leaders who prepare disclosure frameworks in advance can avoid making high-stakes decisions under duress.