Site navigation

Report: 42% of IT Leaders Told to Conceal Data Breaches

Thom Carter

,

Report 42% of IT Leaders Told to Conceal Data Breaches
According to new research published by Bitdefender, the cybersecurity tech firm, 42% of IT and security leaders have been told to keep security breaches confidential, with 30% obliging and keeping a confirmed breach concealed.

These unsettling stats come from the Bitdefender 2023 Cybersecurity Assessment report, which surveyed over 400 IT and security professionals across the USA, UK, and the European continent, working in large organisations with over 1,000 employees.

The report’s survey was conducted to uncover new cybersecurity challenges, key practices, and concerns that IT and security experts are facing, and to also throw further spotlight on existing issues.

The survey found more than half (52%) of respondents had experienced a data breach or related incident in the last 12 months, with respondents in the USA and UK being the two most affected. 74.7% of USA-based respondents and 51.4% of UK respondents confirmed incidents.

However, 42% of overall respondents had been advised to keep breaches under wraps, despite the regulatory, legislative, and moral obligation to report them.

Specifically, when it comes to geography, 70.7% of respondents in the USA said they were advised to keep breaches hushed, with 54.7% of American respondents acting on what they’ve been told and keeping breaches concealed. For the UK, these stats are 44.3% and 35.7% respectively. The stats then fall further when it comes to respondents in the countries of Italy, Germany, Spain, and France, highlighting both a transatlantic and continental divide.

There’s also statistical differentiation concerning job roles. Just under half (44.6%) of CTOs were told to conceal breaches, in comparison with 38.8% of CIOs, and then 32.3% of junior managers.

The push-and-pull of being advised against reporting breaches despite the moral, regulatory, and legislative reasons for doing so is causing IT professionals apprehension, especially as more laws in the US and Europe regarding cyber breach reporting come into effect.

When responding to the statement “I’m worried about my company facing legal action due to a security breach being handled incorrectly,” 54.3% of overall respondents agreed, with over three-quarters (78.7%) of USA-based respondents agreeing.


Recommended


Breach concealment aside, the report also underscored some interesting aspects, attitudes, and worries regarding 2023’s threat landscape.

For example, IT and security leaders in the USA are particularly concerned with software vulnerabilities and zero-days (80%), while in the UK, the primary concern is supply-chain attacks (47%).

The ranking of concerns overall are as follows:

  • Software vulnerabilities and zero-days (53.9%)
  • Phishing and social engineering (52.2%)
  • Supply-chain attacks (49%)
  • Ransomware (48.5%)
  • Insider threats (36.5%)
  • Espionage (34.1%)
  • Privilege escalation (24.1%)

In terms of the most pressing cybersecurity challenges, more than two-in-five (43%) of respondents said extending capabilities across multiple environments — on-premises, cloud, and hybrid — is the greatest challenge they face.

This challenge is tied with complexity of security solutions (43%). Further, not having the security skill set to drive full value came in as a strong second at 36%, pointing to the sector’s deeply felt skills gap.

To read the full report, click here.

Thom Carter

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data