Over a quarter (27%) of UK IT and cyber professionals say they have felt pressure to cover up a security breach or data loss incident.
These are the findings of new research from Kocho, a UK-based provider of cybersecurity, identity, cloud transformation and managed services. Surveying 501 UK CIOs, security analysts and IT professionals, the findings revealed that while 92% of respondents think their boardrooms understand the day-to-day realities of cyber security, it’s different when a breach occurs.
Despite efforts to improve information sharing and collective industry resilience, a fifth (20%) of survey respondents disclosed there still a culture of blame around breaches. In fact, despite incidents being a shared, sector-wide threat, 14% of professionals revealed they were held personally responsible in their organisations.
When an organisation does suffer a breach, more than four-in-ten (45%) said a more measured response from their board would make the handling of a breach easier and faster.
In the UK, GDPR requires organisations to notify the relevant supervisory authority within 72 hours of discovering a breach involving personal data. Seriously affected individuals should be contacted “without undue delay”. Failures in notification can potentially result in an £8.7m fine or 2% of global turnover.
Tensions with the top team
The survey also uncovered some of the tensions between security teams and senior executives. Nearly three-quarters of cyber and IT professionals (73%) say managing the expectations and pressures from the C-suite is demanding.
In organisations with between 100 and 250 employees, the figure rises to 81%, reflecting the pressure on smaller teams. More than half of respondents (52%) said their board (or customers) had asked them for assurances about cyber security that they could not give.
Despite generally good relations with their bosses, almost four-in-ten (39%) believe clearer support and recognition from their senior leadership would alleviate the stress that is common among cyber security and IT teams, particularly as attacks become more common.
There are also signs that some senior leadership teams are too disengaged, with 28% of cyber professionals saying clear executive backing for cyber security priorities would help them feel positive about their current role.
Recommended reading
- Report: Cyber Breaches Are Tanking Share Prices
- Negligence Stirring Rise in Cyber Incidents
- Human Error Costing UK Business Billions in Data Breach Losses
- Inside the Aftermath: What Really Happens When You Get Hacked
- Report: 93% of Data Breaches Expose Financial Records
“As an industry, we must move away from viewing every cyber breach as a sign of organisational or reputational failure,” Hannah Birch, CEO, Kocho, said.
“Today’s threats target entire sectors, supply chains, and ecosystems, not just individual businesses, with similar techniques often used against multiple organisations in quick succession.
“A breach should not automatically be seen evidence of negligence but the result of a coordinated, well‑resourced criminal campaign, therefore, we need a culture of openness, where leaders can share insights and experiences.”





