Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»Declaring data breaches: why self-reporting is on the increase (Page 12)
Cyber resilience

Declaring data breaches: why self-reporting is on the increase

December 17, 20256 Mins Read
A series of hexagons on a dark background, each with a blue locked padlock. A single unlocked padlock is raised up and has a red unlocked padlock.

By Jon Fielding

Coming clean about a cybersecurity incident is now a priority for businesses that are looking to deal with breaches more effectively. There has been a sharp rise in the number that are reporting themselves to the UK Information Commissioner’s Office (ICO) post-breach in order to limit regulatory penalties and reputational damage. Self-disclosure rose from 53% in 2024 to 69% in 2025, according to a recent annual survey of IT security decision-makers by Apricorn. And there was a corresponding decline in the number being reported by a third party, from 14% to just 8%.

This newfound zeal coincides with a raft of recent legislation, making businesses much more compliance-conscious. We have seen the introduction of the Digital Operational Resilience Act (DORA), the EU AI Act, and the EU Cybersecurity Act, as well as the overhaul of UK GDPR following Brexit. Plus, NIS2 is capturing more organizations in scope and holding senior management responsible for overseeing risk management. The upcoming UK counterpart, the Cyber Security and Resilience Bill (CSRB), is likely to do the same. That means people are now personally invested in the security of the business.

But regulators have also sought to make requirements less rigid. There has been a shift away from the tick box approach for some time now towards more outcome-based frameworks, but it is only in the latest iterations of some standards that we have seen true flexibility. If you look at the Payment Card Industry Data Security Standard (PCI DSS) version 4.01, for instance, it adopts a risk-based approach that allows for customised security controls as opposed to a one-size-fits-all approach.

All of these changes have seen compliance become much more embedded in the day-to-day operations of the business. This, in turn, has led to stronger internal reporting processes and ownership of breach response. However, the disclosure trend is also likely to be influenced by a desire to appease the regulator. Following disclosure, the ICO will usually issue a reprimand or enforcement notice and only affix a penalty if that enforcement is not observed. Therefore, businesses that are cooperative and seek to remediate are much less likely to be fined.

In its 2025 annual report, the ICO notes that it only took formal action in response to 33% of the total cases it received spanning data protection complaints, FOI requests, and personal data breach reports. There were 204 GDPR incidents, of which only 43 resulted in investigations, nine of which warranted reprimands, and only two penalty notices were handed out. Of these, just one related to a company in the private sector – Advanced Computer Software Group Ltd, which was fined £3,076,320.

With respect to cybersecurity, out of 1,746 reports of an incident, 61 incidents were ‘managed’, and there were 15 investigations. Of these, three resulted in reprimands concerning failures to implement appropriate technical and organizational measures. Nine monetary penalties were issued totalling £890,000, and nine under the marketing regulations, the Privacy and Electronic Communications Regulations (PECR). The regulator’s criminal investigations resulted in four prosecutions and three cautions.

Facing the music

It is important to point out, however, that the ICO has not and will not be adopting a more lenient approach towards the commercial sector. Its decision following a breach is driven by risk, i.e. how widespread the breach is and the risk it represents to personal data. Its preferred method of sanctions is a reprimand, as it revised its guidance on reprimand procedures in 2024.

However, an ICO reprimand is no slap on the wrist. There will be remedial recommendations and requirements that must be met within a given timeframe, evidence of compliance must be demonstrated, and the ICO may well publish those details on its website even if no fine is issued, potentially resulting in bad press and reputational damage. Plus, the ICO can revisit the business in the future to continue to ensure it is observing those requirements.

Greater transparency is, of course, to be welcomed, as is the pragmatic guidance of the ICO which equates to more carrot and less stick. But is more self-reporting and remediation having the desired impact? It may be too early to tell, but results from the Apricorn survey indicate otherwise. It found that the number of organizations suffering a data breach remains worryingly high, with only 7% of those questioned claiming they had not suffered a breach.

Of those that were breached, 37% said this was due to phishing attacks, 33% employee error, 26% misconfigured software, and 25% ransomware. This suggests that while ransomware may hog the headlines, it is not the main culprit. Rather, the less glamorous causes, such as human error and susceptibility to scams such as phishing emails, are far more likely to result in data loss.

Interestingly, there was also a rise in the number of insider breaches due to malicious employees from 15% to 20%, perhaps due to worsening economic conditions which make employees more susceptible to offers from adversaries. Insiders are being recruited by threat actors who quite blatantly advertise for willing accomplices. Another rising risk is that of AI-based attacks, which were included in the Apricorn survey options for the first time. These were found to be the cause of a fifth of breaches due to data leakage. There have been numerous examples of AI leakage, from ‘shadow AI’, whereby employees are using Large Language Models (LLMs) without authorisation, to issues with the LLM itself.

Redrawing the boundaries

Given that AI is here to stay and we are now seeing the emergence of agentic AI, which can act autonomously without the need for human prompting, this begs the question: what can businesses do to reduce these risks and protect their data? Governance has a big part to play here, but so too does how we build AI deployments. Many of the APIs these LLMs are connecting to, for instance, do not have basic controls in place, such as access and authentication. So, it is a matter of getting back to basics and looking at the architecture itself.

At the end of the day, each and every one of these attack types, no matter how new, all come back to the data which must be safeguarded and protected. The Apricorn survey further revealed that 58% thought their employees lacked the technology or skills to secure that data, putting the onus firmly back on the business to secure its most precious resource.

It is this swing of the pendulum that we are seeing in regulatory spheres, and the reason why we are seeing self-reporting rise, because the buck stops with those overseeing that risk. Management must step up and address the existing and emerging threats to its data, not only to fulfil compliance obligations, but to protect their employees, customers, and their livelihood.

The author

Jon Fielding is Managing Director, EMEA, Apricorn

UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleRisk appetite and risk operations – are you transparent enough with the board?
Next Article Why most IT environments aren’t ready for agentic AI – and what CIOs can do about it

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
A batch of Euro notes, some which are showing signs of being burned. Image © De Nederlandsche Bank - used under media permissions.

Identifying scenarios of interest under deep uncertainty

April 21, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?