The cybersecurity industry has become really good at sharing information about threats. We exchange threat intelligence across industries and catalogue vulnerabilities within hours. But when it comes to organisations talking openly about their own security incidents, we’re not at that same level of transparency.
A new assessment from Bitdefender suggests that culture continues to influence how breaches are handled behind closed doors. More than half (55.2%) of the IT and cybersecurity professionals surveyed said they had been told to keep a breach confidential. While the figure has dipped slightly from 57.6% in 2025, it remains well above the 42% reported in 2023, which suggests that progress has largely stalled – despite a growing body of disclosure regulations.
That raises an important question for the industry: if organisations understand the value of transparency, why does silence remain such a common response?
Compliance can set the rules, but culture influences the response
The regulatory landscape has changed dramatically over the past few years. The US Securities and Exchange Commission's cybersecurity disclosure requirements, Europe's NIS2 Directive and the Digital Operational Resilience Act (DORA) have all strengthened expectations around reporting significant cyber incidents.
These frameworks have established clearer obligations for organisations, investors and regulators. They’ve also elevated cybersecurity from a technical issue to a boardroom responsibility.
But, as any seasoned cybersecurity practitioner knows, regulation and organisational behaviour don't always move at the same pace.
Bitdefender argues that while disclosure rules have created a baseline expectation for transparency, disclosure can still be painful. Reputation, customer confidence, commercial relationships and legal concerns all continue to influence how organisations communicate about cyber incidents.
And on top of that, the survey suggests those pressures are felt differently around the world. In the US, 69% of respondents reported being told to keep a breach confidential, compared with 57% in both Germany and the UK, 53% in Singapore, 47% in France and 46% in Italy.
Silence doesn't make cyber risk disappear
The report also notes how common security incidents have become. More than half of respondents said their organisation experienced a cybersecurity breach or incident during the previous year.
The most widely reported incidents globally were:
- Unauthorised access to cloud infrastructure or applications (41.8%).
- Business email compromise resulting in financial or data loss (35.9%).
- Ransomware, intellectual property theft and data exfiltration also featured prominently in the survey.
These figures illustrate an important reality: cyber incidents are now a routine operational challenge for organisations of every size.
This means that transparency is valuable not just for regulators, but for the wider cybersecurity community. Every disclosed incident helps security teams understand how attackers are adapting, where controls failed and which defensive measures proved effective. Shared experiences allow organisations to learn from each other instead of repeating the same mistakes in isolation.
Building a culture of transparency
Greater transparency doesn't mean publishing every technical detail of an incident before investigations are complete. It means creating an environment where timely disclosure is viewed as responsible governance rather than reputational failure.
And that starts well before an incident occurs.
Boards should agree on clear disclosure processes as part of incident response planning, ensuring communications, legal, executive and security teams understand their respective responsibilities. Security leaders also need confidence that raising concerns will be supported rather than discouraged, particularly during the critical early stages of an investigation.
Perhaps most importantly, the industry itself can continue shifting how it views breach disclosure. Organisations that communicate openly about incidents often provide valuable lessons that strengthen the wider cybersecurity ecosystem – so we need to emphasise the value of that.
Threat actors already collaborate, exchange techniques and build on one another's successes. Greater transparency gives defenders the opportunity to do the same.
Regulations have helped establish the expectation of disclosure. Our next step is building a culture where openness is recognised as a sign of resilience and responsible leadership – not as something to be feared.