A new global incident reporting and disclosure survey by Keeper Security has revealed the top three reasons for not reporting cyber-attacks: fear of repercussion (43%), not thinking it was necessary (36%), and forgetting to report the incident altogether (32%).
According to the survey, which surveyed 400 security and IT leaders, 40% of them had personally experienced a cyber-attack and a quarter felt guilty for not reporting the attack or breach to leadership.
“The numbers point to a need for organisations to make significant cultural changes around cybersecurity, which is a shared responsibility,” said Darren Guccione, CEO and co-founder of Keeper Security.
Of those who experienced a cyber-attack, nearly half (48%) told Keeper Security that they chose to keep the incidents a secret from external authorities. Two significant reasons being the fear of short-term harm to the organisation’s reputation and the potential for financial impacts.
A further 41% confessed they didn’t even report it to internal leadership, due to a quarter believing their organisation would not care about the incident, while 23% thought it wouldn’t take action to address it, and 22% thought their company had no system in place to report such breaches.
Recommended
- Is It Okay to Break Cybersecurity laws? Depends, UK Citizens Say
- Fears of Cyberwarfare Driving IT Professionals to Improve Security Culture
- Home Office Data Incidents Nearly Double Over Past Year
“Accountability starts at the top, and leadership must create a corporate culture that prioritises cybersecurity incident reporting, otherwise they will open themselves up to legal liabilities and costly financial penalties, and place employees, customers, stakeholders and partners at risk.”
This comes on the backdrop of about one third of businesses and one quarter of charities identifying and reporting a cyber-attack over the last 12 months. According to estimates from the government, there were approximately 2.39 million instances of cyber-crime over the last year.
The report points out that almost three quarters (74%) say they remain concerned about a cybersecurity disaster impacting their organisation in the future.





