Bitdefender survey of 400+ IT and security professionals: 42% were told to cover up data breaches that should have been reported and 29.9% admit doing so
Have you ever wondered how many companies are keeping their data breaches under wraps? … Tweets: Phil Muncaster / @philmuncaster : With 42% of IT pros (and 70% in the US) told to keep quiet over data breaches, should we be concerned? cc @Bitdefender https://www.infosecurity-magazine.com/ ...
Context & Ripple Effects
Breach non-disclosure has been visible at the edges for years: a 2017 UK government survey found only 24% of breached businesses reported incidents to police, while a later analysis of disclosure practices concluded organizations routinely obfuscate or stay silent and argued regulation was needed to force transparency (calls for mandated breach transparency). What Bitdefender adds is an inside view of why — the suppression is often instructed, not chosen.
The survey's numbers make the pattern hard to dismiss as anecdote: 42% of 400+ IT and security professionals were told to keep quiet about reportable breaches, 29.9% admit complying, and the figure climbs to 70% among US respondents. That sits alongside evidence that attackers exploit organizational blind spots — including insider recruitment approaches at large firms (ransomware groups seeking insider access) and third-party privilege as a leading breach vector.
First-order effects
- IT and security professionals bear the direct cost — a substantial minority are ordered to conceal incidents they know should be reported, and nearly three in ten comply despite personal and legal exposure.
- Customers and partners of covering-up companies lose the timely breach notifications that disclosure obligations exist to provide, with US respondents reporting the highest instruction rate at 70%.
Second-order effects
- Vendors like Bitdefender convert survey findings into market positioning: quantifying customer-side misconduct strengthens the case for the security tooling and advisory services they sell, while peer researchers gain ammunition for disclosure reform.
- Regulators and policymakers get fresh empirical support for mandatory disclosure regimes — the argument that voluntary transparency fails now has named-source data showing instructed silence rather than mere negligence.
Third-order effects
- If instructed suppression is as common as the survey suggests, trust-based self-reporting becomes structurally unreliable, pushing jurisdictions toward enforcement-heavy disclosure rules with penalties aimed at executives who order silence, not just the breach itself.
- Persistent under-reporting also distorts the risk picture that cyber insurers, auditors, and boards price against — meaning the true breach base rate is higher than recorded data implies, and any statistics built on disclosed incidents systematically understate exposure.
The trend: Breach disclosure is shifting from voluntary corporate discretion toward externally enforced mandates, as survey evidence accumulates that organizations will suppress incidents absent regulatory compulsion.