Security1 publisher2 min readPublished
Bitdefender counts 55.2% of breached practitioners asked to keep the incident quiet
The figure sits 13.2 points above the 2023 reading after three years of expanded disclosure rules. The survey captures the request itself, leaving the requester's identity, whether anyone complied, and whether the breach went unreported outside its scope.
The Watch · Security desk

What happened
- In the 2026 Bitdefender Cybersecurity Assessment, 55.2 percent of respondents who had a breach in the past 12 months said they were asked to keep it confidential even when it should have been disclosed.
- Roughly half of the 1,200 IT and security professionals on the panel reported a breach or security incident in the previous 12 months, and the confidentiality question was put to that group.
- The same question returned 42.0 percent in 2023 and 57.6 percent in 2025, so the 2026 figure sits below the peak and well above the first reading.
- US respondents were the most likely to report being pressured, with majorities also reporting it in Germany, the UK and Singapore.
- A Bitdefender panel attributed the pressure to three causes: attackers selling silence, a perceived cost of disclosure that outweighs the perceived risk of hiding, and an internal culture of silence.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure When silence is bought rather than kept, the party holding proof of both the breach and the cover-up is the extortionist, and per Jackson the disclosure then happens on the attacker's schedule and includes the concealment.
- cost Armstrong's version of the same culture is paid for in dwell time: hours between a user's click and the ticket are hours the SOC spends later chasing persistence, stolen credentials and lateral movement.
- constraint The 55.2 percent measures requests made, not breaches concealed: the published survey stops at the request and never reaches compliance or outcome.
- decision Fixing a disclosure posture in advance, as Bitdefender recommends, is the only version of that decision made without a counterparty offering money for the quiet option.
Martin Zugec, Bitdefender's technical solutions director, describes attacks engineered so that only a handful of people ever see them: rather than lighting up every monitor in the building, the intruder opens a private channel to the IT team [10]. The pitch is clean recovery with confidentiality attached, and the price is payment [11]. Nicholas Jackson, the company's director of cybersecurity services, says the leverage now runs in the other direction too, with attackers threatening to publish the data or to notify regulators if the victim does not pay, and he argues that a concealment exposed by the attacker does more lasting damage than self-reporting would have [12]. The fears on the other side of that ledger, per Jackson, are fines, reputational damage and customer retention [13].
The 55.2% is a share of a subset. Of 1,200 respondents [1], roughly half reported an incident in the past 12 months [2], which puts the breached group near 600 and the group asked to stay silent near 331 people, about 28% of the full panel [17]. Measured against 42.0% in 2023 [4], that is 13.2 points of movement [18]. Measured against the 57.6% high in 2025 [5], it is 2.4 points down [19], which Bitdefender reads as a plateau rather than a reversal [7]. In France and Italy the share came in just under half [9].
What the published survey carries is the request. It reports that a confidentiality request was made, leaving the requester's identity, whether the respondent complied, and whether the incident ultimately went unreported outside its scope [20]. That bounds how far the number travels: it counts pressure applied to practitioners, not breaches successfully hidden, and it stops short of what happened afterward to the person who received the instruction [20]. Whether suppression pressure amounts to a personal legal exposure for the individual analyst is a separate argument, one this data set does not address. The study is vendor-run and self-reported, one of several annual waves Bitdefender has published [1].
Reporting obligations expanded from 2023 onward [6]. So did the share of practitioners told to keep it quiet [18].
What to watch
- Whether the next Bitdefender wave breaks out who issued the confidentiality request: executive, legal, client or attacker.
- Whether the 2027 reading leaves the 55 to 58 percent band it has held since 2025.
- Any enforcement action that names an individual practitioner rather than the employer, which would put a price on the request this survey only counts.