I'll research this topic thoroughly before writing the blog post.

I now have comprehensive research to write an authoritative, well-cited, SEO-optimised blog post. Here it is:


There's a quiet crisis unfolding in boardrooms and security operations centres around the world. The professionals hired to protect your organisation's most sensitive data are, in alarming numbers, being told to stay silent about the very threats they were brought on to confront. It's not a conspiracy — it's a culture problem. And it's putting companies, customers, and careers at serious risk.

A recent Checkmarx report, The Future of Application Security in the Era of AI, found that 95% of CISOs "feel pressured to suppress or delay compliance-related security findings."

Read that again. Nearly every Chief Information Security Officer surveyed has felt the squeeze to bury bad news rather than escalate it. If that statistic doesn't make you stop and audit the health of your security culture, nothing will.

This blog post explores why that pressure exists, what happens when it goes unchecked, and — most importantly — what you can do about it right now.


The Scale of the Problem Is Bigger Than You Think

To understand the silence, you first need to understand the stakes.

The average cost of a data breach reached a record high of $4.88 million USD in 2024, according to IBM's Cost of a Data Breach Report 2024.

Meanwhile,

security breaches in 2024 were up 75% year-over-year, with organisations facing an average of 1,876 attacks per quarter.

Against this backdrop, you'd expect organisations to be doubling down on honest reporting and rapid escalation. Instead, the opposite is happening.

More than two-thirds (69%) of CISOs have been told to keep breaches confidential, according to a survey by Bitdefender — significantly up from the 42% recorded in an equivalent study two years prior.

This isn't a fringe trend. It's a systemic pattern, and it's accelerating.


Why CISOs Are Afraid to Speak Up

Fear for Their Jobs Is Real — and Rational

Nearly all CISOs (99%) are worried about losing their positions if a breach occurs, with a striking 77% being very or extremely concerned.

That kind of career anxiety doesn't stay compartmentalised. It bleeds into every reporting decision a CISO makes.

17% of CISOs say they always feel personally blamed for security incidents regardless of root cause, and 39% say they often feel blamed — even when incidents fall outside their direct control. If a breach were to occur, 90% say their role may be at risk to some degree.

When the messenger gets shot, people stop sending messages.

Pressure Comes From Inside the Building

Here's what's particularly troubling: the biggest source of stress for CISOs isn't the hackers outside — it's the executives inside.

44% of CISOs surveyed ranked board or executive expectations as their top stressor, more than external threats, which were cited by 33%.

The pressure may be palpable, but it's rarely communicated directly. Most CISOs actually experience competing business priorities and expectations to accomplish more with fewer resources. Business leaders focus on finances and keeping operations running smoothly. Security investments are often viewed as a cost, while the risks they prevent are difficult to quantify until an incident occurs.

This creates a structural silence: CISOs who lack the authority or political capital to push back simply comply.

The Role Itself Is Becoming Unsustainable

87% of CISOs say pressure in their role has increased over the past year. Two-thirds report feeling burned out weekly or daily, and 40% have considered leaving their role altogether.

99% of CISOs work extra hours every week, with one in five working an additional 25 hours. This pressure results in high executive churn, with average tenure hovering between 18 months and 26 months.

When CISOs rotate out this quickly, institutional knowledge evaporates — and with it, any hope of building a culture of open, honest security communication.


The Real-World Consequences of Burying Bad News

Organisations Get Blindsided

When security findings are suppressed, organisations lose their most powerful tool against cyberattacks: early warning.

Despite global information security spending projected to reach $215 billion in 2024, 44% of CISOs reported they were unable to detect a data breach in the last 12 months using existing security tools. CISOs identified blind spots as a key issue, with 70% stating their existing security tools are not as effective as they could be due to limited visibility.

If your CISO is already battling detection gaps — and then feels compelled to sit on what little intelligence they do surface — your organisation is flying blind.

The findings of a recent CISO survey reveal a concerning gap between perceived preparedness and actual readiness among cybersecurity leaders. A majority of CISOs do not feel confident in their ability to handle a cyberattack if it were to strike their organisation in the immediate future.

Suppressed reporting makes this gap even wider.

Perhaps the starkest illustration of what's at stake came from the SolarWinds case.

The SEC announced charges against SolarWinds Corporation and its CISO, Timothy Brown, for allegedly making material misstatements regarding its cybersecurity practices, for not having reasonable internal controls to safeguard the company's crown jewel assets, and for not having reasonable disclosure controls.

The SEC alleged that SolarWinds and its CISO knowingly or recklessly made materially false public statements to mislead investors.

The case sent shockwaves through the CISO community — because for the first time, a security leader was named individually in a federal enforcement action.

The regulatory environment has since hardened considerably.

The SEC implemented new rules, effective December 18, 2023, requiring public companies to disclose material cybersecurity incidents on Form 8-K within four business days.

21% of CISOs report being pressured to not disclose compliance issues, even as personal liability for breaches increases under SEC and GDPR regulations.

That combination — mounting legal obligation and mounting internal pressure to stay quiet — is a powder keg.

Corporate Cover-Ups Erode Customer Trust

In some cases, CISOs have been told not to report incidents involving customer data because it was deemed "not their problem" or to preserve a business relationship with a third party. These situations highlight the impossible position in which CISOs are often placed: legally accountable for security but pressured to ignore standards when disclosure conflicts with corporate interests.

When breaches eventually surface — and they almost always do — the cover-up typically causes more reputational damage than the incident itself.


The Silence Has a Business Cost Beyond the Breach

Burnout doesn't just hurt the CISO. It becomes an organisational liability.

The personal cost of CISO pressure is beginning to affect business readiness. Nearly half say burnout has already hurt their ability to prepare for breaches.

High CISO turnover leads to security programs stalling and institutional knowledge disappearing. As one industry leader noted, "burnout doesn't just hurt individuals, but becomes a business risk in itself, weakening the organisation's entire security posture."

There's also a paradox in the data that boards need to hear:

while 67% of CISOs say their cybersecurity culture is strong, a striking 76% believe their organisation is at risk of a material cyberattack in the next 12 months.

If your CISO is saying everything is fine publicly while privately believing a major incident is coming, that gap is not a technology problem. It's a culture problem.


How to Build a Culture Where CISOs Can Tell the Truth

The solution isn't simply telling CISOs to speak up — it's creating the structural conditions where honesty is safe, expected, and rewarded. Here's what that looks like in practice.

Practical Tips to Act On Immediately

1. Establish formal protections for escalating bad news.

Boards and executives should reinforce that transparency is valued, and that escalation of problems will not be punished but used constructively. Questions should focus on what is not being reported and how near-misses are used to improve processes.

2. Create regular, non-crisis communication channels.

Establish regular, non-crisis communication channels between the board and the CISO. Support a culture of open dialogue so that issues are escalated early rather than hidden.

Don't wait for an incident to have a frank conversation about security posture.

3. Reframe security as a business conversation.

Transparency in cybersecurity is not merely about sharing information but about creating a framework of accountability that resonates across an organisation. Modern CISOs must balance technical expertise with executive communication skills, translating complex threats into actionable business insights.

Boards that only hear technical jargon will tune out — help CISOs frame risk in financial and operational terms.

4. Understand your legal disclosure obligations now — not after an incident.

When a material cybersecurity incident occurs, it is paramount to make full and timely disclosures. Making incomplete or misleading disclosures carries the potential to erode investor trust and could trigger a significant enforcement action.

Build a disclosure decision tree before you need it.

5. Give CISOs a genuine seat at the strategic table.

"CISOs are hired to protect an organisation's digital assets, yet they often lack the authority, influence, or resources needed to fully manage risk."

Without board-level access and genuine decision-making authority, CISOs will continue to be filtered messengers rather than strategic partners.

6. Audit the gap between stated culture and actual behaviour.

A 2024 survey of 200 CISOs revealed that 20% of boards don't ask about application security, and only 51% of boards have reviewed their process for identifying and disclosing a cybersecurity incident.

If your board isn't asking, your CISO may not be telling. Close that loop immediately.

7. Address CISO burnout as a strategic risk, not an HR issue.

There is growing recognition that the cybersecurity industry needs a shift away from blaming CISOs and security organisations for breaches, and a rebuttal of the shame-based culture that has plagued cybersecurity.

That shift starts at the top.


Conclusion: Transparency Is Your Best Security Strategy

The pressure on CISOs to hide bad security news isn't just a human resources problem or a leadership failure. It is an existential risk to your organisation. In an era of sophisticated, relentless cyber threats, your most valuable security asset is the truth — delivered clearly, early, and without fear of consequence.

Those tasked with the CISO role often bear the brunt of data breaches and cyberattacks, a reality that frequently results in burnout, dismissal, and even legal consequences.

That can't continue if organisations want to build genuine resilience.

The organisations that will weather the next wave of cyberattacks aren't necessarily the ones with the largest security budgets. They're the ones where the CISO can walk into the boardroom, share the unvarnished truth, and trust that the response will be: "Thank you. Now let's fix it."

Is your organisation one of them? If you're not certain, it's time to find out. Start by scheduling an honest, structured conversation between your board and your CISO — one with no agenda other than the truth. Download our CISO–Board Communication Framework, or contact our team today to assess the health of your security transparency culture before the next incident forces the conversation.