Key Findings

  • Slightly more than half of cybersecurity professionals believe AI helps attackers more than defenders—a conclusion from security vendor Bitdefender's latest report.
  • Malware improvements, social engineering tactics, and attack behaviors such as lateral movement and automated vulnerability scanning top the list of AI-related threat vectors respondents worry about most.
  • The report also highlights shadow AI risks, security incident concealment issues, and the confidence gap between management and frontline employees.

Deep Dive

One of the most striking findings in Bitdefender's annual report is that 55% of practitioners say they have been asked to stay silent about security incidents. This figure rose from 42% in 2024 to 58% in 2025, and has now leveled off this year. Bitdefender analysts write, "This plateau may be as unsettling as the initial surge."

The security vendor speculates that while organizations are working to incorporate breach disclosure regulations in the US and Europe, "cultural change lags behind policy change." Analysts write, "Changing behavior may require making disclosure less punitive, or conversely—making concealment harder to justify."

Bitdefender's report is based on a survey of 1,200 IT and cybersecurity professionals from the US and five other countries, conducted between April and June 2025, including frontline employees, mid-level managers, and executives.

More than half of respondents reported experiencing a data breach or other cybersecurity incident in the 12 months prior to the survey, with 42% citing unauthorized cloud access, 36% citing business email compromise (BEC), and 26% citing ransomware. BEC was most common in the US, while unauthorized cloud access dominated in the other five surveyed countries (UK, France, Germany, Singapore, and Italy).

Shadow AI issues also show regional differences. US respondents were most likely to report full visibility into their organization's AI usage (63%), followed by the UK (58%) and Germany (52%).

This finding aligns with a broader confidence gap between organizations in the US and elsewhere. Bitdefender states, "US respondents are both the most anxious and the most confident across our entire dataset. They report higher rates of incident concealment, more AI-driven attacks, and greater tool complexity. Yet they also express higher confidence in their security posture, stronger vendor relationships, and greater willingness to invest."

Among the report's more concerning findings, management's confidence in their own cybersecurity practices is notably higher than that of frontline employees. The largest gap appears on the issue of full AI visibility, with a 12-percentage-point difference; gaps on other issues are smaller but still significant, including alignment between cybersecurity defenders and the broader business (a 7.4-percentage-point difference).