Report by Bitdefender
Bitdefender Cybersecurity Assessment 2026
Key Findings
47.4% of IT and security professionals acknowledge only partial or no visibility into individual Shadow AI tools or personal accounts used for work.
57.8% of IT and security managers believe they have full visibility into AI tool usage compared to 45.9% of practitioners.
45% of IT and security professionals identify internal AI systems and large language models (LLMs) as their primary security concern.
44% of IT and security professionals identify cloud infrastructure and application environments as a primary security concern.
33.3% of IT and security professionals identify identity and access management (IAM) systems as a top security concern.
55.2% of IT and security professionals who experienced a security incident or breach in the past 12 months state they were told to keep it confidential despite believing it should have been reported.
The 55.2% of IT and security professionals told to keep breaches confidential is slightly down from 57.6% in 2025 and substantially higher than 42% in 2023.
68.6% of IT and security professionals in the U.S. who experienced a breach report being told to keep it confidential, the highest regional rate.
57.2% of IT and security professionals in both Germany and the U.K. who experienced a breach report being told to keep it confidential.
56.8% of IT and security managers and 53.5% of practitioners who experienced a breach report pressure to stay silent.
35.9% of IT and security professionals report experiencing business email compromise (BEC) resulting in financial or data loss in the past 12 months.
54.7% of IT and security professionals in the U.S. report experiencing BEC incidents, nearly 19 percentage points above the overall average.
59.2% of IT and security professionals confirm experiencing AI-driven social engineering attacks in the past 12 months.
The top barriers to reducing the attack surface reported by IT and security professionals are high overhead in maintaining hardening rules and exceptions (38%), fear of operational disruption (35.4%), and resource constraints (34.6%).
Difficulty securing legacy systems is reported by 34.5% of IT and security professionals and visibility gaps are reported by 33.8%.
87% of IT and security professionals in the U.S., 85% in the U.K., and 77% in Germany say they would likely switch cybersecurity vendors due to data sovereignty concerns.
0.5% of IT and security managers report zero visibility into AI tool usage versus 4.5% of practitioners.
51.8% of IT and security professionals report full visibility into sanctioned and unsanctioned AI tool usage.
IT and security professionals rate attackers using AI to generate self-mutating malware as a high or extreme risk at 55.9%, employees leaking sensitive data into public LLMs at 53.5%, AI-driven evasion techniques at 52.5%, and deepfakes or voice cloning used in fraud or BEC at 51.9%.
25.6% of IT and security professionals report experiencing ransomware in the past 12 months.
20.4% of IT and security professionals rate employees leaking sensitive data into public LLMs as a low or extremely low risk.
48.8% of IT and security professionals in the U.S. report marked gaps in visibility compared to the overall average of 33.8%.
64% of IT and security professionals in Singapore and 61.6% in the U.S. view agentic AI expanding the attack surface as a regional flashpoint.
79.4% of IT and security managers and 72.8% of practitioners say they would likely switch vendors due to data sovereignty concerns.
76.1% of IT and security professionals say they would likely switch cybersecurity vendors due to concerns about data sovereignty, jurisdiction, or foreign government access to their data.
41.8% of IT and security professionals report experiencing a cloud infrastructure or application breach in the past 12 months.