Key Findings

  • A survey by cybersecurity firm VikingCloud found that nearly half (48%) of cybersecurity leaders did not report "significant" cybersecurity incidents to senior management or the board of directors over the past year.
  • VikingCloud noted in a recent report that the main reasons include concerns that leadership and the board would respond punitively rather than constructively (40%), and fears of financial or reputational damage from public disclosure or regulatory consequences (44%).
  • "If you're in a leadership position, you need to find out if this is happening in your company," said Jon Marler, a cybersecurity evangelist at VikingCloud, in an interview. "I'm not saying 'go on a witch hunt,' but rather from the perspective of fostering a culture of accountability and establishing mechanisms where people don't fear losing their jobs for disclosing incidents—especially in today's tough job market in IT and tech."

Deeper Analysis

It remains unclear whether the surveyed companies violated any cybersecurity laws by failing to report breaches. The increasingly complex cybersecurity incident reporting requirements in the U.S. include rules from the Securities and Exchange Commission (SEC) requiring public companies to disclose "material" incidents within four days of making a materiality determination.

"While the survey is interesting, it's too broad to draw definitive conclusions," said Scott Kimpel, a partner at Hunton Andrews Kurth, in an email. "Many incident response plans only require reporting to the board or executive management in very limited circumstances." He noted that the study was limited to a few industries and did not define key terms such as "material cybersecurity incident." "We don't know whether the surveyed companies are publicly traded, nor their relative size as measured by total assets, revenue, or other metrics." Nevertheless, he believes the study reminds companies to develop incident response plans tailored to their own circumstances, "appropriately considering applicable legal standards, prevailing market practices, and stakeholders' information needs."

Andy Lunsford, CEO of cybersecurity firm BreachRx, said VikingCloud's findings align with results from his company's research on regulatory filings and administrative actions. "Choosing not to report a significant cyber incident may seem like it avoids scrutiny, but it actually backfires," he said in an emailed statement. "Even if there's short-term relief, the eventual consequences are more severe, and the company and entire executive team face greater liability, including personal liability."

The findings come as cyberattacks continue to surge, exposing businesses to financial, regulatory, and legal risks. "Strong cybersecurity defense requires building a corporate security culture that provides a safe space for reporting all incidents," VikingCloud said in the report. "Network and broader executive leadership have a responsibility to establish clear reporting protocols and foster a culture of continuous learning and improvement."

The FBI's Internet Crime Complaint Center received 859,532 complaints of suspected cybercrime in 2024, with reported losses exceeding $16 billion—a 33% increase from the prior year, according to a report released earlier this year. VikingCloud said cybersecurity incidents have escalated in both frequency and severity over the past year, with artificial intelligence being a primary driver.

More than half (51%) of respondents cited generative or agentic AI-driven phishing campaigns as their top concern among emerging cyberattack techniques, up from 22% last year. The study noted: "This indicates that more leadership teams recognize the dangers of AI-driven attack methods, especially as agentic AI becomes more prevalent, making malicious actors more dangerous, more efficient, and more persistent than with generative AI alone."

Additionally, nation-state hackers—cybercriminals backed or directed by foreign governments—now have a broader reach, with businesses of all sizes and industries potentially affected by "collateral damage through software supply chains." More than three-quarters of respondents believed that recent or proposed cuts to U.S. federal cybersecurity programs, such as the Cybersecurity and Infrastructure Security Agency and the National Security Agency, could increase cybersecurity risks for their organizations.

The study is based on a survey of 200 cybersecurity leaders (director level and above) from the U.S., UK, and Ireland. When asked whether any of the surveyed organizations were publicly traded companies subject to SEC requirements to report "material" cybersecurity incidents, a VikingCloud spokesperson said the company "did not drill down to that level of detail in the demographic questions." The spokesperson added: "We asked about industry (healthcare, retail, hospitality, food service, travel), location (US, UK, Ireland), whether they operate across multiple locations (86% do), and job level (43% at the executive level)."