Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Keeper Security study shows cultural changes imperative to improve cyber incident reporting

Cybersecurity Disasters Survey: Incident Reporting & Disclosure finds 40% of organisations have experienced a cybersecurity incident, yet almost half did not disclose to appropriate authorities 

by Guru Writer
September 27, 2023
in Featured
Keeper Security study shows cultural changes imperative to improve cyber incident reporting
Share on FacebookShare on Twitter

Keeper Security, a provider of cloud-based zero-trust and zero-knowledge cybersecurity software protecting passwords, passkeys, secrets, connections and privileged access, has released findings of its Cybersecurity Disasters Survey: Incident Reporting & Disclosure. They reveal widespread shortcomings in reporting cybersecurity attacks and breaches, both to internal leadership and external authorities.

 

Cybersecurity incident reporting falls short 

Keeper’s survey shows a lack of policies for cyber incident reporting, despite the growing risk of cyberthreats. Nearly three-in-four respondents (74%) said they were concerned about a cybersecurity disaster impacting their organisation and 40% of respondents said their organisation has experienced some type of cyber disaster.

 

Despite these concerns, the study confirmed that reporting breaches to a company’s leadership team and to proper authorities is often avoided.

 

When it comes to external reporting, 48% of respondents were aware of a cybersecurity attack that their organisation did not report to the appropriate external authorities.

 

And internally, 41% of cyberattacks were not disclosed to internal leadership.

 

Incident reporting is low; guilt is high

Of those who admit they’ve failed to report an attack or breach to leadership, 75% said they felt “guilty” for not doing so. Fear, forgetfulness, misunderstanding and poor corporate cyber-culture all contribute to widespread under-reporting of security breaches.

 

The top three reasons why an attack or breach was not reported to leadership:

  • Fear of repercussion (43%)
  • Thinking reporting was unnecessary (36%)
  • Forgetting to report the incident (32%)

 

Organisational cultures do not prioritise cybersecurity

Despite the potential for long-term financial and reputational consequences, poor disclosure and transparency practices prevailed. Failure to report was largely based on the fear of short-term harm to the organisation’s reputation (43%) and potential for financial impacts (40%).

 

Respondents also cited a strong need for senior leadership to demonstrate a vested interest in the organisation’s cyber posture and stand beside their IT and security teams, providing the resources and support they need to report and respond to attacks.

 

A combined 48% of respondents did not think leadership would care about a cyberattack (25%) nor would respond (23%).

 

Nearly one-fourth of all respondents (22%) said their organisations had “no system in place” to report breaches to leadership.

 

“The numbers point to a need for organisations to make significant cultural changes around cybersecurity, which is a shared responsibility,” said Darren Guccione, CEO and co-founder of Keeper Security. “Accountability starts at the top, and leadership must create a corporate culture that prioritises cybersecurity incident reporting, otherwise they will open themselves up to legal liabilities and costly financial penalties, and place employees, customers, stakeholders and partners at risk.”

 

Best practices 

In the current high-risk security climate it’s critical for enterprises to encourage transparency and honesty in cyber disaster reporting, and to adopt best practices, policies and procedures to safeguard against ongoing threats. Some of the most effective ways to prevent cyber disasters, including password and privileged access management, are the simplest, yet most critical to protecting organisations.

 

*Methodology

Keeper commissioned an independent research firm to survey 400 IT and security leaders in North America and Europe to gain their insights on cyber disaster incidents, reporting and recovery. An independent research firm conducted the survey in 2023. Keeper characterises ‘cybersecurity disasters’ as any event that severely impacts the confidentiality, integrity or availability of an information system.

 

ShareTweet
Previous Post

CREST and IASME announce partnership with the NCSC to deliver Cyber Incident Exercising scheme

Next Post

ICS Reconnaissance Attacks – Introduction to Exploiting Modbus

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol