Barbados’ Data Protection Watchdog Has Real Teeth on Paper. Why Hasn’t It Bitten?

Introduction

Barbados demonstrated a level of progressiveness compared to its Caribbean neighbours when it gazetted the Data Protection Act, 2019 (the “DPA”), a GDPR-inspired law with registration requirements, mandatory breach notification, data subject rights, and penalties of up to BBD $500,000 or three years’ imprisonment for serious violations. The Act became enforceable in March 2021, and Lisa Greaves was appointed as the island’s first Data Protection Commissioner (“DPC”) in July the same year.

Four years on, the legal architecture remains solid, but the performance of the Office that’s supposed to enforce it is a different story. From a national voters list exposed on the open Internet to a children’s survey investigation that appears to have simply gone quiet, a pattern emerges of a privacy regulator that reacts late, if at all, and rarely tells the public what happened next. In this blog post, I will explore where the Office of the Data Protection Commissioner (“ODPC”) appears to be falling short, case-by-case, and what needs to change.

No visible enforcement record

The DPA gives the Commissioner real enforcement powers in the form of audits, enforcement notices, warrants to investigate suspected breaches, and fines that scale up to half a million Barbadian dollars. Four years into an active mandate, there is no public register of enforcement notices issued, no published list of completed investigations, and no visible history of fines levied against non-compliant organizations in the public or private sectors.

A regulator that never visibly uses its enforcement powers sends an unintended signal to data controllers that the risk of actually being penalised is low. Regulatory deterrence depends on organisations believing that non-compliance carries consequences, and that belief has to be built on evidence, not the text of a statute.

The government’s own breaches expose the gap between law and practice

The clearest test of any data protection regime is how it performs when something goes wrong, and 2022 through 2024 presented Barbados with three major tests.

A December 2022 cybersecurity attack on the Queen Elizabeth Hospital (QEH) severely disrupted the country’s healthcare infrastructure, forcing a total network shutdown and reversion to manual, paper-based operations for an extended period. The outage caused the postponement of surgeries, delayed appointments in the Radiology Department, and temporarily shut down outpatient pharmacies. Despite the scale of the breach and the highly sensitive nature of patient data at risk, the incident was characterized by a distinct lack of public transparency. In the aftermath of the hack, there was no public record of a formal, published investigation or conclusive regulatory action by the DPC. This administrative silence, coupled with a failure to provide the public with clear reassurances regarding the containment of personal health information is a major concern in terms of lack of accountability and enforcement within the island’s data privacy regulations.

In September 2024, the Barbados Revenue Authority (BRA) suffered what may be the largest data breach in the country’s history, where roughly 230GB of data, including driver’s licenses, passports, vehicle registration records, tax information, and other sensitive documents, was exfiltrated by a threat actor and offered for sale online. I publicly challenged the government’s characterization of the incident, arguing the breach was more serious than officials were letting on and that international supervisory authorities and data subjects in the EU, UK, and Canada should have been notified given foreign nationals’ data was involved. The government’s own account, weeks later, sought to downplay the risk, describing much of the exposed material as “reasonably low risk” administrative documentation; a characterization at odds with the sensitive data confirmed in the leak.

A second breach hit the Barbados Statistical Service in October 2024, involving a ransomware group. To its credit, the Statistical Service notified the Commissioner and issued public updates, but the fact that two significant government bodies were breached within weeks of each other, with the public first learning of the scale from independent researchers and journalists rather than proactive disclosure, does not reflect well on the state of data governance the Data Protection Commissioner is meant to be driving across government.

In neither case is there public evidence that the DPC conducted a visible, independent post-incident audit, issued findings, or required corrective measures with any public accountability attached.

The 2021 election roll: a foreseeable exposure met with near-silence

If the BRA and BSS incidents show how the DPC handles a crisis after the fact, the 2021 voters list exposure shows something arguably worse – a foreseeable privacy failure the ODPC appears to have done little to prevent or answer for, even though it happened on its own watch.

On 29 December 2021, days after a snap election was called, the Barbados Government Information Service published a full preliminary voters list online with 5,520 pages containing the full name, national registration number (NRN), date of birth, gender, residential status, constituency, and address of more than 264,000 people. It was freely downloadable by anyone in the world, not just Barbadians, and was quickly mirrored on social media, the Dark Web, and other platforms once attention turned to it. Commissioner Greaves had already been in post for roughly five months at that point, and the DPA had been enforceable since March of that year.

The Electoral and Boundaries Commission (EBC) defended the release as a legal obligation under the Representation of the People Act, and its Chairman (now the Chief Justice of the Supreme Court) publicly maintained that identifiers like the NRN were “not really anything that is private.” I pushed back against his contention arguing that publishing the full NRN and date of birth of every voter violated the basic data minimisation principle the DPA itself is built on, and pointed out that safer alternatives existed, including a searchable lookup tool, or controlled distribution to election officials and campaign managers, that would have satisfied the legal publication requirement without exposing sensitive identifiers to the open Internet. My assessment at the time was blunt: the Office of the DPC was too under-resourced or politically captured to make enforcement of the DPA against this kind of exposure realistic.

What’s conspicuously absent from the public record is any comment from the DPC herself. She never visibly weighed in on whether the EBC’s actions were consistent with the DPA, no public guidance issued to the EBC on safer methods of publication, and no indication the office pushed for the promised legislative harmonisation between the Representation of the People Act and the newer DPA, despite commentators flagging that exact conflict in real time. By March 2023, I again raised the alarm, saying there was evidence the leaked list was already being used to commit identity fraud against Barbadians internationally, and that the EBC had ignored my warnings. Once again, there was no public record of the DPC’s Office weighing in.

This case is arguably the most damaging of the three discussed here, because it wasn’t a hack, a rogue vendor, or a third-party contractor’s mistake; it was the government’s own statutory election process, running headlong into the DPA’s core principles, in the regulator’s first year of operation. If the DPC couldn’t or wouldn’t intervene on this one, in public, it raises a hard question about how much it can be relied on to check the rest of the government.

The IDB school survey: an investigation opened, never closed

The clearest example of the Office starting strong and then going quiet involves children’s data, the category the DPA should be most protective of.

In September 2022, more than 700 first-form students across five secondary schools were given a roughly 300-question survey administered as part of an Inter-American Development Bank (IDB)-funded project. The questionnaire asked children as young as 11 or 12 about their sexuality, gender identity, self-harm and suicidal ideation, and drug use, along with details about their families, and all without parental consent. Parents only learned about it after the fact, when local media broke the story following complaints.

To its credit, the Ministry of Education referred the matter to the Data Protection Commissioner, and the Office opened a formal investigation, with a spokesperson for Commissioner Greaves confirming publicly that it was examining whether the DPA had been breached and would advise the Ministry accordingly.

That’s where the public trail ends. There are no published findings from that investigation, no statement on whether the DPA was in fact breached, no enforcement notice, no public accounting of what the IDB, the Ministry, or the schools involved were required to change. What followed instead was driven by everyone but the regulator. Parents organised protests calling for resignations and a class-action lawsuit, the IDB and Ministry apologised on their own initiative, and the Ministry quietly tightened its internal approval process for any research conducted in schools. As recently as early 2026, officials cited that internal Ministry protocol, not any DPC ruling, as the safeguard now governing school-based research, framing it as something developed in “consultation with” the Commissioner rather than the product of a completed DPC investigation.

This is a hard case to explain away as “still ongoing.” The underlying facts were never seriously disputed. Both the IDB and the Ministry admitted the survey happened and apologised for its content, so there was little for a regulator to adjudicate that wasn’t already conceded. What was missing was the one thing only the DPC’s Office could provide, which was an authoritative, public determination of whether Barbadian children’s sensitive data had been unlawfully collected, and what accountability followed. Four years on, parents still don’t have that answer from the body legally responsible for giving it to them.

Other notable data breaches

There’s been a recurring wave of cyber incidents in Barbados between 2024 and 2026, most notably the viral February 2026 Digicel data breach and systemic ransomware attacks targeting local law firms. These too have been met with notable silence from the DPC, despite detailed customer records, highly sensitive corporate legal files, land titles, and other private client data been exposed. Moreover, the dataset from the Digicel breach appeared to have been highly targeted by political campaigns with subscribers found on the list reportedly receiving highly personalized, unsolicited campaign calls from political canvassers who matched their names to the leaked database. Local cybersecurity experts also note that several corporate cyber incidents go completely unrecorded because companies choose not to report data breaches to protect their reputation (this is a clear violation of the DPA’s mandatory breach notification requirement). Despite legal mandates for swift oversight, the DPC’s failure to issue timely public statements, definitive enforcement actions, or transparent status updates has left the public in the dark. While corporate victims quietly manage reputation damage and thousands of exposed citizens fall prey to targeted political spam and phishing risks, the Commissioner’s lack of visible intervention severely undermines national trust in Barbados’ privacy framework.

Reactive, not proactive, engagement

Where the Office has visibly acted, it has largely been in response to complaints or media pressure rather than through its own initiative (e.g., investigating a school survey after the Ministry of Education flagged it, or responding to a political party’s e-voting system after journalists reported member concerns). These interventions show the Office can act, but a regulator whose only visible activity is complaint-driven reaction, rather than proactive audits of high-risk data controllers (government ministries, financial institutions, telecoms, credit bureaus), is not fulfilling the supervisory role the DPA envisions. Barbados only rolled out a national cybersecurity and data-protection public awareness campaign after the BRA breach forced the issue. A competent regulator builds public and institutional awareness ahead of a crisis, not in response to one.

No registry of data controllers and data processors

Under the text of the DPA, every data controller and processor operating in or targeting Barbados is required to register with the Commissioner. However, this requirement is not currently active because sections 55 through 57 (which cover processor registration) were explicitly excluded from proclamation by the government. There is no publicly accessible register showing how many organizations are engaged in personal data processing, and no announced deadline was ever set for when these provisions will become active; a fact the DPC only publicly acknowledged years after the law took effect. The absence of an active, centralized registry for data controllers and data processors creates significant regulatory and operational friction. Without a registry, the ODPC lacks a definitive, up-to-date master list of every entity handling citizen data. The regulator cannot easily audit who exists, what data they possess, or whether they have appointed a mandatory Data Protection Officer (DPO). This makes proactive compliance enforcement incredibly difficult, forcing the Commission to operate responsively only after a breach occurs. Without the verified emergency contacts for an organization’s data team that would be recorded in a pre-vetted registry, communication lines during a high-stakes data breach can also be slowed down by bureaucratic lag. As Barbados has heavily modeled its legislation after the GDPR to attract international investment and secure “adequacy status” for seamless cross-border data flows, a law that is partially unproclaimed or missing its enforcement registry can raise flags for foreign companies questioning if the local privacy framework is truly robust and active.

Limited transparency and reporting

The DPA requires the Commissioner to submit annual reports to Parliament. Whether or not this is technically happening, there is little to no public visibility into these reports, complaint statistics, breach notification numbers, or the Office’s own resourcing and staffing levels. A regulator’s credibility rests substantially on transparency about its own performance (e.g., publishing how many complaints it receives, how long they take to resolve, and what outcomes result). That data isn’t publicly available in Barbados today. 

Furthermore, the DPC’s Office does not even have a dedicated website with key resources. As a model, an effective website should feature public advisories, data subject rights explanations, organizational toolkits, reporting channels, and public enforcement logs at a bare minimum. This state of affairs cannot and should not be acceptable for a function that is nearly 5 years old.

Resourcing and capacity questions

The Office sits within the Ministry of Industry, Innovation, Science and Technology (MIST) rather than as a fully independent statutory body with its own budget line, staffing complement, and governance mechanisms. Regional commentary has repeatedly noted Caribbean regulators, including Barbados’, are still looking to more established regulators in the UK and EU for guidance on how to function effectively. This is a sign that institutional capacity, not just legal authority, remains a work in progress. Whether the Office currently has the technical (cybersecurity), legal, and investigative staff to audit large government agencies and private-sector data controllers is not publicly documented, but the scale and apparent surprise of the 2024 breaches suggests the answer is “not at all.”

Recommendations

  1. Publish an enforcement track record. Even a simple public log of enforcement notices, audits, and (where appropriate, anonymised) outcomes would materially improve deterrence and public trust.
  2. Conduct and publish independent post-breach reviews. After incidents like the BRA and BSS breaches, the Commissioner’s Office should issue its own public findings — separate from the breached agency’s political messaging — including root cause, scope, and remediation timelines.
  3. Set and enforce a compliance deadline. Give data controllers and processors a hard registration and compliance deadline, publish aggregate compliance statistics, and follow through with enforcement against those who miss it.
  4. Move to proactive supervision. Shift resources toward scheduled audits of high-risk sectors such as government ministries and statutory bodies holding ID, tax, and health data; financial institutions; telecoms; credit bureaus rather than relying primarily on complaints and media coverage to trigger action.
  5. Report to the public, not just Parliament. Publish an accessible annual report with complaint volumes, resolution times, breach notifications received, and enforcement actions taken, in the way the UK’s ICO or similar regional regulators do.
  6. Strengthen institutional independence and resourcing. Give the Office a clearer statutory footing, independent budget, and dedicated technical staff (IT, cybersecurity, audit, digital forensics) so it isn’t reliant on other ministries’ capacity when a major incident hits.
  7. Build cross-border notification protocols now, not during a crisis. Given tourism and the size of Barbados’s foreign customer/visitor base, the Office should have clear, pre-agreed procedures for notifying overseas supervisory authorities when non-Barbadian data subjects are affected rather than that becoming a point of public dispute after the fact.
  8. Harmonise conflicting legislation proactively. The 2021 election roll exposure happened because the Representation of the People Act’s publication requirements were never reconciled with the DPA’s data minimisation principle. The Office should maintain and publish a running review of older statutes that conflict with DPA principles, rather than waiting for a public controversy to expose the gap, and should be willing to publicly and specifically weigh in when another public body’s statutory obligations collide with data protection principles, as it did not do in the 2021 case.
  9. Set a time-bound duty to publish investigation outcomes, especially involving children. The IDB survey investigation shows what happens without one: an inquiry opened under public pressure, then never publicly concluded. A statutory deadline, even a lengthy one, for the Office to publish at least a summary finding on completed investigations would prevent cases from quietly disappearing, and should apply with particular urgency to cases involving minors or other vulnerable groups.
  10. Invest in proactive public education. Continue and expand the post-BRA cybersecurity awareness push, but as an ongoing programme rather than a reactive one.

The Bottom Line

Barbados did the hard part in passing a modern, GDPR-aligned law and standing up a regulator years before most of its regional peers. What’s missing now is the visible, consistent exercise of that authority. A voters list containing the identifiers of a quarter-million people sat exposed on the open Internet with no public intervention from the regulator responsible for preventing exactly that. Children were surveyed about their sexuality and mental health without consent, and the investigation into it appears to have quietly died. Two major government agencies were breached within weeks of each other in 2024, and the public learned the real scale from independent researchers, not proactive disclosure. Each case follows the same modus operandi of an initial acknowledgement, then silence where a public finding should be.

Until that changes, and until the ODPC consistently shows its work, in public, on the cases that matter most, the Data Protection Act risks being a well-drafted law without a regulator willing, or resourced, to enforce it.

The Facade of Progress: Why GovTech Barbados is Stalling Digital Transformation

In the humid corridors of Barbados’ public service, there is a new buzzword circulating with the frequency of a tropical breeze: “GovTech.” Established in late 2023 with the high-octane promise of dragging a paper-clogged bureaucracy into the 21st century, GovTech Barbados Ltd. was heralded as the “silver bullet” for the nation’s digital woes.

However, as we move through 2026, the initial honeymoon period has ended. While the PR machinery hums with talk of “AI-powered prototypes” and “digital champions,” the average Barbadian citizen is still standing in physical lines, clutching paper forms, and wondering when the promised “sweeping transformation” will actually increase the ease of doing business.

The reality is that GovTech Barbados, despite its modern branding and high-profile leadership, is currently a victim of institutional inertia, misplaced priorities, and a “startup” culture that is fundamentally incompatible with the weight of government bureaucracy.

The Prototyping Trap: Appearance vs. Reality

The most visible “achievement” of GovTech Barbados so far has been the rollout of rapid “prototyping.” Using AI to turn a paper form into a digital interface in “minutes” sounds like a revolution. It makes for excellent LinkedIn posts and impressive demos for the Ministry of Industry, Innovation, Science and Technology (MIST).

But a prototype is not a service.

The “Prototyping Trap” occurs when an organization prioritizes the UI (User Interface) over the UX (User Experience) and the underlying backend processes. Turning a paper form into a digital PDF or a web form is the easiest 5% of digital transformation. The difficult 95% involves:

  • Integrating with the national identity system.
  • Automating backend approvals so a human doesn’t have to print the digital form to file it.
  • Introducing workflow management tooling to handoff tasks between different government departments or control points.
  • Updating the 40-year-old legislation that still requires a physical signature.

By focusing on what they believe to be “tangible outputs” to win public confidence, GovTech is essentially painting the windows of a house that has no plumbing. Citizens may fill out a form online, but if the “transformation” stops there, the inefficiency is simply moved from the front counter to a back-office inbox. Instead of focusing on throughput (how many forms can we digitize?), GovTech Barbados needs to focus on outcomes (how much time and money can we save the citizen?). It’s also quite telling that the GovTech team has neither the deep expertise nor a visible focus on ICT law and business process reengineering.

The CEO Dilemma: A Startup Mindset in a “Legacy” Environment

Mark Boyce, hired in July 2024, has brought a seemingly more tech savvy energy to the role. His background, marked by a vocal critique of the “safe” career paths of doctors and lawyers in Barbados, suggested he was the disruptor the island needed. However, in reality, Mr. Boyce does not have the qualifications or experience to lead a major national digital transformation initiative like GovTech Barbados. He has never led complex enterprise or government implementations which include cloud computing, interoperability layers, cybersecurity, e-commerce, digital identity, and big data. Unfortunately, neither has the majority of his key hires.

Digital transformation in a government setting is less like a tech startup and more like an organ transplant. The “host body” (the existing Civil Service) often rejects the “new organ” (GovTech) if the cultural and legislative prep work isn’t done.

I can’t help but to think that GovTech is operating as an isolated island of innovation. While Boyce and his team speak the language of “The Radical How” and “agile execution,” the rest of the government still speaks the language of “The General Orders” and “Financial Rules.” This cultural mismatch has led to a bottleneck where GovTech builds prototypes that sit in limbo for months because the “human review process” in traditional ministries remains unchanged.

The Sovereign Cloud and the “Hardware Hubris”

One of GovTech’s early and most controversial claims was that Barbados was “on the brink” of a sweeping transformation fueled by a Tier 3 data center and a “sovereign cloud.”

As I noted in a previous blog post, this often feels like “déjà vu.” Barbados has a history of announcing expensive infrastructure projects that fail to deliver service-level improvements. It’s important to note that:

  • Costs are astronomical: A greenfield Tier 3 data center can cost upwards of $20 million in capital expenditure, with millions more in annual operating costs.
  • Infrastructure vs. Service: A data center is just a room with servers. If the software running on those servers is poorly designed or the data remains siloed in different ministries, the “Sovereign Cloud” is just a very expensive local hard drive.

Furthermore, the focus on building local infrastructure ignores the global trend toward public cloud utilization (AWS, Azure, Google Cloud), which offers better security, scalability, and disaster recovery than a small island nation can typically manage on its own. The obsession with “sovereign hardware” often masks a lack of “sovereign software” capability.

A better approach would be a hybrid cloud model with a smaller footprint sovereign data center hosting “mission critical” and “secret” data (e.g., Digital ID, Electronic Patient Records, BimPay, etc.) and leveraging the public cloud for non-sensitive, high-scale applications (e.g., public-facing websites, information portals).

Missing the “Human” in the Human Firewall

For a “GovTech” agency, there has been a glaring lack of focus on the digital literacy of the civil service. Digital transformation is 10% technology and 90% people.

While GovTech talks about “Digital Champions” within ministries, these individuals are often overstretched civil servants with no formal technical training and no authority to change the processes they are “championing.” Without a massive, nationwide upskilling program for the thousands of government workers who actually process the forms, GovTech’s tools will remain shiny toys that no one knows how to play with.

The Transparency Deficit

Meaningful digital transformation requires trust. Yet, GovTech Barbados must be questioned for its approach to:

  • Cybersecurity: Barbados continues to score poorly on the ITU Global Cybersecurity Index. Announcing “AI-powered” government services without a robust, transparent cybersecurity framework or government-wide AI governance standard is a recipe for a national data disaster.
  • Data Protection: As GovTech moves to “release public datasets” to spur local tech growth, there are unanswered questions about how citizen privacy is being protected under the Data Protection Act. Where is the Open Data Policy? What about Freedom of Information (FOI) legislation? What will be the overarching data governance framework? Is the Data Protection Commissioner being continuously engaged?
  • Procurement: Is GovTech empowering local startups, or is it becoming a middleman for expensive foreign “turnkey” solutions that don’t fit the local context?
  • Digital Identification: Considering the existence of the Trident ID system, why haven’t centralized and federated digital ID been prioritized? GovTech should have already built a “Single Sign-On (SSO)” for all government portals. Instead of having separate logins for Taxes (TAMIS), NIS, and the Land Registry, a citizen uses one verified Trident identity. GovTech can also act as a “Trust Broker.” For example, local banks should be mandated to use the Trident ID API to verify a new customer’s identity instantly, rather than requiring them to visit a branch with a passport. Banking customers should also be able to login to their Internet and mobile banking applications with the Trident digital ID.

Notwithstanding a clear lack of transparency, GovTech Barbados has been granted a multi-million dollar budgetary increase in the 2026–2027 Estimates. The public must now ask: how is this agency being held accountable for its results – or the evident lack thereof?

The Verdict: Is it Transformation or Decoration?

As of early 2026, GovTech Barbados has achieved Digital Decoration. It has made the government look more modern, but it hasn’t made it work more efficiently.

For GovTech to move from a PR success to a systemic success, it needs to stop focusing on “tangible prototypes” and start doing the “unsexy” work of:

  1. Legislative Reform: Working with the Attorney General to kill the “physical signature” requirement once and for all.
  2. Interoperability: Forcing ministries to share data through a central API, so citizens don’t have to provide their birth certificate to five different departments.
  3. Radical Transparency: Publishing real-time KPIs on service delivery times, not just “how many forms we digitized.”

If GovTech continues down its current path, it risks becoming just another “State-Owned Enterprise (SOE)” – a well-funded agency that produces beautiful reports and prototypes while the people of Barbados continue to wait in the sun for a service that should have been a website click years ago.

Why CISOs Must Fight Back Against Scapegoating

  • CISO ignores red flags in recruitment where business leaders repeatedly mention their “unique developer culture”.
  • CISO joins a major company which claims to be committed to cybersecurity.
  • CISO publishes 30-60-90 day plan and immediately performs a maturity assessment upon joining.
  • CISO meets with over 50 organizational leaders to outline their strategic vision and build support. Not a single person provides any meaningful input. The organization has no Internal Audit or Risk functions.
  • After completing the maturity assessment, CISO develops and publishes a draft cybersecurity strategy and multi-year roadmap for feedback. Not a single member of the executive management board reads the documents or provides feedback (including the CTO and CIO).
  • When asked about weak asset management (less than 35% of devices have EDR or MDM installed), the CIO states that developers don’t like being monitored. The CIO also states that cloud security posture management isn’t a priority (the organization employs a ‘multi-cloud strategy’ with a large footprint across multiple public clouds).
  • The organization’s CI/CD pipeline is fragmented with limited security controls. The CTO refuses to commit to robust security in the CI/CD pipeline because the organization is focused on code velocity and bringing new products/features to the market. CTO cannot explain why the Security Champions program failed.
  • The organization’s ecosystem is filled with thousands of vulnerable apps because there has literally been zero investment in relevant security controls. CISO develops a detailed plan addressing the people, process, and technology required to enhance security in the marketplace. The CISO is pretty much ignored.
  • The organization is obsessed with its annual SOC 2 audit (security theater).
  • CISO makes first presentation to executive management, addressing the security vision in accessible language such as business resilience, competitive advantage, market differentiation, regulatory compliance, collaborative risk management, etc. CISO highlights the “poor security culture” and asks that executive management make a formal statement about their commitment to security, authority to the CISO, and need for business leaders to own security in their domains and cooperate with the CISO. The executive management team is angry and criticizes the CISO for asking them to do what they see as his job.
  • A few weeks later, management and the CISO decide to part ways because of a “poor cultural fit”.

This is unfortunately a widespread scenario highlighting why the average CISO tenure is 18-24 months: poor tone from the top, unrealistic expectations, inadequate resources, accountability without authority, regulatory & legal pressure, and poor organizational culture.

It’s time for CISOs to pushback against these toxic situations!

The Dangers of Relying on Security Theater

In 2026, phrases like “We take security seriously” or “Your security is important to us” have become the ultimate red flags.

When companies lead with these lines in their PR, it often signals the opposite: Security Theater 🎭

As a global digital trust and corporate governance professional, I see this daily. Theater is easy; resilience is hard. Theater is about “checking a box” for a board mandate, audit finding, or customer requirement; resilience is about an internal ethos that guides every business decision.

How do you spot the actors? Here are 6 signs of a “Theatrical” security posture:

  • Non-Existent or Weak “Tone at the Top”: The attitude and commitment of the Board and C-suite dictates the security culture that governs every employee’s daily actions. When the tone at the top is weak, the security program in most every case fails.
  • Compliance as a Destination: Treating a SOC 2 or ISO certification as the finish line rather than the baseline. Attackers don’t care if you passed an audit; they care about your unpatched edge devices and unsecured cloud assets.
  • “Shadow IT” Amnesia: Bragging about a new “AI Policy” while employees are quietly feeding sensitive intellectual property into unmanaged non-enterprise LLMs, leveraging third-party code with no security gates or approvals, and using unapproved plugins or add-ons in browsers / IDEs / issue-tracking platforms that are vastly insecure.
  • The “Culture” Conundrum: Forcing employees through 10 minutes of outdated, boring video slides once a year and calling it a “Security Culture.” Real culture is when people believe in security and live it each day in their actions and decisions. This also goes for the businesses whose “developer culture” requires security leadership to be ‘flexible’ and to ignore heinous security practices by software developers.
  • MFA Mirage: Having Multi-Factor Authentication (MFA) enabled, but allowing so many “exceptions” for executives or legacy systems that the front door is essentially unlocked.
  • Asset and Configuration Management: No accurate inventories exist for hardware / software / data assets, the majority of enterprise devices aren’t running unified endpoint management (UEM) or endpoint protection, cloud assets and their configuration status are unknown, an embarassingly low number of critical assets have logging enabled, and hardening templates don’t exist across virtual servers / microservices / network devices.

Digital Trust isn’t a marketing slogan. It is a measurable KPI. In 2026, the market must shift to rewarding candor and specificity over “vague invulnerability.”

The companies that thrive won’t be the ones that never get hit – they’ll be the ones that had the integrity to build real defenses before the curtain went up.

Stop the performance. Start the protection.

Why the UK Government’s Loan Guarantee for JLR Requires Deeper Analysis

A cyber-attack “severely disrupted” Jaguar Land Rover (JLR) vehicle production, particularly at its two main UK plants. JLR’s retail business was also significantly impacted for consumers ordering or taking delivery of new vehicles. To help the carmaker recover and protect jobs within its extensive supply chain, the UK government has decided to underwrite a £1.5 billion loan guarantee.

The government’s loan guarantee requires deeper analysis because it can be viewed as potentially socializing corporate risk, essentially creating a taxpayer-funded safety net for private sector cybersecurity failures. While the goal of protecting 100,000 supply chain jobs is understandable, this decision may undermine the core market incentive for all businesses to achieve robust security resilience.

1. Incentivizing Security Complacency

By being the first company to receive such significant government aid following a cyber-attack, JLR sets a challenging precedent. It may signal to other large, systemically important companies that serious investment in preemptive cyber-defenses is optional. If a major breach causes a costly production shutdown, the government may provide a financial parachute to protect the supply chain. This effectively lowers the cost of poor security planning for major corporations and shifts the financial burden of resilience onto the public purse.

2. Rewarding Inadequate Preparation

The scale of JLR’s shutdown (e.g., halting all production for weeks) suggests a critical failure in both cyber resilience and business continuity planning (BCP) at the company. Should a secure and resilient organization be able to isolate an attack and recover without weeks of total shutdown, minimizing impact on its supply chain? Do the loan guarantees reward the company for a recovery posture that was either slow, inadequate, or both? Is the public essentially paying for the gap between JLR’s security maturity and the highly disruptive level of the breach? Many questions arise and a deeper discourse is needed into whether or not the government should be bailing out private corporations for suboptimal cybersecurity posture.

3. Moral Hazard and Unintended Consequences

This action may create a moral hazard. The government is protecting the ultimate parent company, India’s Tata Motors, from the full financial consequences of the attack by backstopping a commercial loan via the Export Development Guarantee (EDG). Taxpayers assume the risk of JLR defaulting, possibly shielding the multinational owner from a major cyber-loss event. This is especially alarming given that JLR’s massive profits would normally imply responsibility for maintaining its own cyber insurance and resilience fund.

In short, while the loan guarantee offers necessary short-term relief to small suppliers facing collapse, there is the potential long-term cost of the erosion of market pressure on large corporations to treat cybersecurity as a non-negotiable, self-funded business continuity imperative.

Mismanagement of the BRA Breach: Lack of Cyber Preparednes is Expensive

In this year’s budget, the Ministry of Finance, Economic Affairs, and Investment is asking for $36.9 million to cover the costs associated with managing last year’s data breach at the Barbados Revenue Authority (BRA). Given that the average cost of responding to a data breach in 2024 was USD $4.88 million (BBD$9.94 million), this quoted figure is exceptionally high and warrants a detailed examination.

Here’s my breakdown of why such an amount is considered excessive:

1. Financial Strain:

  • Depletion of Public Funds: $36.9 million is a substantial amount that severely depletes the country’s financial resources at a time the nation is struggling with heavy debt obligations and underperformance in key sectors. It more than likely will require budget cuts in other critical areas, halt planned projects, or even threaten the country’s ability to service existing debts or meet its overall financial needs.
  • Opportunity Cost: The money spent on data breach response could be better used for investments in economic growth, innovation, social services, workforce development, or other strategic initiatives that contribute to Barbados’ long-term success.
  • Citizen Impact: This is at its core an erosion of trust in government’s effectiveness in managing cybersecurity and data protection, and can have a knock-on negative impact in terms of reduced quality and investment in citizen services (e.g., education, healthcare, transportation, sewage, housing, etc.), increased public debt, additional taxes, and hindered development.

2. Cost-Benefit Analysis:

  • Value of Data: It’s essential to compare the recovery cost with the actual value of the compromised data. I am certain no quantitative assessment was performed by the government to determine the cost of the data. In this case, the data might not be worth $36.9 million, making the recovery expenditure disproportionate.
  • Potential Losses: While data breaches can lead to financial losses, including regulatory fines, legal fees, and compensation to individuals harmed by their data being misused or abused, it’s crucial to estimate these potential losses accurately. A $36.9 million recovery cost in my opinion exceeds the estimated losses the government would have otherwise incurred.

3. Inefficiencies and Overcharging:

  • Vendor Pricing: Given my experience managing data breaches over the last 20+ years, unscrupulous vendors usually exploit the urgency and panic surrounding a breach to inflate their prices. This appears to be the case in this instance (given that the government has limited cybersecurity capabilities and little to no experience responding to breaches).
  • Scope Creep: Recovery efforts can sometimes expand beyond the initial scope, leading to unnecessary expenses. There’s no doubt in my mind that the government did not have defined security incident response procedures or objectives, which led to the recovery scope being too wide and unconstrained to avoid cost overruns.
  • Ineffective Strategies: The chosen security incident response strategies were poorly defined and inefficient, leading to prolonged recovery times and increased costs.

4. Failure of Prevention:

  • Security Gaps: As I have said numerous times, the government does not have the capabilities in place to secure the technologies that they have implemented, and this $36.9 million bill confirms these significant weaknesses in their cybersecurity infrastructure and practices. It raises questions about why they have failed to implement the numerous detailed security strategies provided to them over the last decade by the European Union (a project which I led), International Telecommunications Union (ITU), Organisation of American States (OAS), and others.
  • Missed Opportunities: Investing in robust cybersecurity measures, such as firewalls, intrusion detection systems, personnel training, and regular security audits, could have prevented the breach or minimized its impact, potentially saving millions of dollars in recovery costs. And while investments have been made in some of these areas, the implementation of the solutions have left a lot to be desired.

5. Reputation Damage:

  • Public Perception: While the financial cost is significant, the reputation damage from the BRA data breach doesn’t seem to be substantial. While the breach was severe, involved sensitive data, and came on the heels of the cyber-attacks against the Queen Elizabeth Hospital and many other government departments, there are many residents who still don’t seem to understand how dire the government’s cybersecurity situation really is.
  • Public Trust: The constant data breaches impacting public services and citizens’ data have a detrimental effect on public trust (which is already low). This will prevent the uptake of digital services being implemented by the government as well as reduce the confidence in e-commerce as a whole. Basically, it jeopardises the entire digital transformation agenda of this administration and the ability of Barbadians to reap the associated benefits.

In conclusion, while data breach recovery is a necessary expense, $36.9 million is an exorbitant amount that warrants careful scrutiny. It’s crucial that the Public Accounts Committee (PAC) and the Office of the Auditor General conduct a thorough investigation, evaluating vendor pricing, identifying inefficiencies, and addressing underlying security vulnerabilities to ensure that recovery efforts in the future are effective and cost-efficient.

New ISACA Research: 63 Percent of Privacy Professionals Find Their Jobs More Stressful Now Than Five Years Ago

The ISACA State of Privacy 2025 survey report, which gathered responses from over 1,600 privacy professionals globally, revealed that 63% of these professionals find their roles more stressful than they were five years ago, with 34% reporting a significant increase in stress levels. The primary sources of stress identified in the survey were the rapid pace of technological advancements (63%), difficulties with compliance (61%), and a lack of resources (59%).

“In an increasingly complex international regulatory environment, often with lacklustre resources, it is understandable that many privacy professionals are feeling strain from their efforts to stay compliant and keep their organizations’ data safe. Addressing these challenges and getting practitioners the support they need will be vital to not only ensure a healthy privacy workforce, but also to maintain data integrity and security, and avoid potential harm to data subjects.” I made these comments via BusinessWire on the report to emphasize not only the challenges associated with implementing privacy programs, but also the importance of organizations demonstrating their commitment to data governance, data ethics, privacy rights, and overall digital trust.

With AI, the privacy landscape has changed dramatically, including the regulatory burdens for companies. Continued leadership in the boardroom, at the executive level, as well as embedding privacy principles in organizational values is integral to nurturing the trust relationship between enterprises, their customers, and society at large.

Dispelling the Myths of Defense-Grade Cybersecurity

Defense-grade cybersecurity solutions are specifically designed to provide advanced protection against sophisticated threats but there are many misunderstandings about this level of protection. 

Sectors like finance, healthcare and critical infrastructure can use battle hardened defense-grade cybersecurity to tackle today’s cyber threats.  

In this webinar hosted by Infosecurity Magazine, I joined an expert group of panelists to uncover the truth behind common misconceptions about defense-grade cybersecurity, demonstrating its relevance, affordability, adaptability and effectiveness for organizations beyond the military or government.

We tackled myths such as, “defense-grade cybersecurity can’t stop APTs”, “it’s only for the government” and “it’s too complex and difficult to deploy”, providing insights into how modern defense-grade measures are accessible, scalable and essential for critical sectors.

We also discussed real-world applications of defense-grade principles, explaining how these solutions address today’s advanced threats.

Register to watch the on-demand recording at this link.

Barbados’ Digital Aspirations: A Reality Check

In a recent Barbados Today article, the CEO of the newly minted GovTech Barbados stated with confidence that the country is “on the brink of a sweeping digital transformation, with a particular focus on enhancing its cybersecurity infrastructure.” While the ambition is commendable, it’s crucial to examine these claims with a critical eye. As someone deeply involved in the tech sector for almost 30 years, I find several elements of this grand vision questionable at best, and potentially misleading at worst.

The ‘Conundrum’ of the Tier 3 Data Center

The government’s plan to establish a Tier 3 National Data Center sounds impressive on paper. However, this claim ignores several fundamental realities of Barbados’ infrastructure, market conditions, and human capacity.

Costs

With a monopoly electric company serving the entire island, is it even possible to achieve the redundancy and reliability required for a Tier 3 facility in a cost effective manner? Tier 3 data centers demand multiple, independent power distribution paths. In the Uptime Institute tier model, onsite power is the only reliable source of power – it is completely within the span of control of the organization, with no conflicting external entity’s profitability goals. Given the high costs of commercial power in Barbados ($0.33 per KWh – one of the highest in the world), and the even higher costs associated with operations and maintenance for onsite generated power, has the government properly assessed the overall costs of delivering the power requirements for a Tier 3 data center?

In addition, a Tier 3 data center requires the installation of redundant systems in terms of uninterrupted power (UPS), direct current battery plants, diesel-based power generators, and HVAC systems, including heating (H), ventilation (V) and precision air conditioning (AC). Below is an overview from Kio (a global data center company) in US dollars of the costs of building out such facilities.

With regards to network connectivity, a Tier 3 data center must have multiple Internet service provider connections and dedicated fiber optic cabling. This is particularly challenging as telecoms costs in Barbados are phenomenally high when compared to the global average. Furthermore, a mile of fiber optics can cost upwards of $250,000 USD. Then there are the incremental costs for perimeter control/fencing, access control systems, metal detectors, video monitoring, fuel tanks, telecoms grounding and lightning protection, fire suppression, racking hardware, networking equipment, server infrastructure, tier certification, etc. I will address the costs for staffing in greater detail in the next section.

The capital expenditure (CapEx) and operational expenditure (OpEx) can quickly skyrocket. My conservative estimation is CapEx of approximately USD$20 million for the greenfield build-out of the Tier 3 facility and USD$5-10 million in annual OpEx to successfully run it.

Taking into consideration that Tier 3 data centers usually have a commercial model, it would be good if the government can explain to the general public how the build-out is being funded, whether taxpayers will be expected to cover the costs, will more loans and increased debt be involved, how will the return on investment (ROI) be achieved, what does the total cost of ownership (TCO) look like over a 5-10 year period, and other related financing and cost recovery details.

Talent

Another area worth a deeper dive is the talent associated with the operations and maintenance of a Tier 3 data center. For operational sustainability, staffing must be divided into three (3) categories.

  • Headcount: The number of personnel needed to meet the workload requirements for specific maintenance activities and shift presence. Assuming a 24x7x365 operation, headcount will be needed to cover daily administration, preventative maintenance, corrective maintenance, vendor support, project support, and tenant work orders.
  • Qualifications: The degrees, certifications, technical training, and experience required to properly maintain and operate the wide array of installed infrastructure.
  • Organization: The reporting structure for escalating issues or concerns, with roles and responsibilities defined for each group.

Most of the persons on-island that meet these requirements are employed by Digicel, Flow, or commercial banks. The remaining talent would have to be sourced from overseas. What is the government’s strategy for attracting and retaining this level of talent? How will they do so in a fiscally responsible manner? Has a skills gap analysis been performed for the public sector? Is there a talent management and professional development plan to ensure that this digital initiative is adequately resourced from the human capital perspective? 

Environmental Impact

Data centers are responsible for an enormous negative environmental impact: their gluttonous annual consumption of electricity, greenhouse gas emissions, heavy water consumption, generation of toxic electronic waste, and other types of direct and indirect ecological harms are of a major concern. In conformity with the United Nations Sustainable Development Goals (UN SDGs), the potential environmental impact of data centers should be numerically assessed to compare to the environmental capacity and chart a plan towards sustainability.

Has the government completed an environment impact assessment (EIA) for the data center facility? Have they engaged surrounding residents to discuss the known issues with data centers, including noise pollution and drought risks? Given the government’s commitment to climate change, what are their plans for the Tier 3 facility vis-a-vis carbon-neutrality, carbon offsetting, and investment in renewable energy systems like wind and solar? What is the government’s broader toxic electronic waste disposal strategy? 

The “Sovereign Cloud” Misnomer

The term “sovereign cloud” has been tossed around, but it appears to be more buzzword than substance. In the tech world, a sovereign cloud typically refers to public cloud services that treat workloads as if they’re in the client’s home country, even when physically hosted elsewhere.  Sovereignty requirements mandate that customers’ usage of what’s typically understood as public cloud must be immune from the impact of foreign laws and mandates; sovereignty overall is then a key requirement for consideration alongside other controls requirements such as security, resilience, data residency, and privacy. These factors generally apply when a government or international organization is purchasing services from an overseas-based cloud provider.

What GovTech Barbados is proposing is simply a government-owned data center located on Bajan soil. It’s inherently sovereign, but a “sovereign cloud” it isn’t – it’s just a standard approach to local data hosting. By misusing this term, are they trying to make a normal infrastructure upgrade sound more innovative than it really is?

The vast majority of the government’s public sector computing environment is based on traditional client-server architecture and on-premise data processing. There’s nothing specifically “cloud-centric” about it. Bearing that in mind, it would be good to better understand the government’s future state cloud architecture. How will cloud-related skills be obtained in the public sector where they currently don’t exist? What’s the overall enterprise architecture model? How will they transform deeply antiquated, siloed and fragmented government systems into a cohesive architecture premised upon modern cloud technologies? What cloud solutions will be used for orchestration, observability, infrastructure, databases, etc.? How will existing infrastructure and applications be refactored to be cloud native? Is their approach based on private cloud, public cloud, or multi-cloud? Have disaster recovery needs been considered? Has the partner/vendor ecosystem been defined? What about third-party risk management (TPRM)? These questions and more need to be answered.

The last 2 questions are especially pertinent given the announced partnerships with Promotech and Fortinet – The former (Promotech) is a consumer electronics retailer with zero credentials in deploying complex, secure, enterprise-scale technologies and the latter (Fortinet), while a solid cybersecurity solutions vendor, requires advanced expertise to properly deploy and manage their equipment. Fortinet is also known to be quite expensive in terms of professional services and they have had a number of security issues in recent times.

Cybersecurity: Promises vs. Reality

The government’s emphasis on cybersecurity is not new. In fact, it’s a tune we’ve been hearing from as far back as 2012. Over the last 10 years, the Government of Barbados has received substantial funding from various international bodies to enhance its cybersecurity posture. Yet, where is our national cybersecurity unit? Why is our cybersecurity maturity so low compared to other developing countries such as Botswana, Cuba, Ethiopia, Ghana, Guyana, Jamaica, and Kenya, among others?

And despite numerous cybersecurity assessments, strategies, and roadmaps conducted by international organizations (e.g., ITU, OAS, European Commission, etc.), we seem no closer to establishing a robust cybersecurity framework than we were a decade ago. 

In the International Telecommunications Union’s (ITU’s) recently released 2024 Global Cybersecurity Index, Barbados scored quite poorly against the Americas regional average (see below).

With this ITU ranking as a backdrop, it has to be said that the GovTech Barbados announcement feels like déjà vu. What’s different this time? How can we trust that these plans will materialize when similar promises have fallen flat repeatedly? Amidst the talk of setting up a national cybersecurity unit, is Mr. Boyce aware that the responsibility for national cybersecurity lies with the Barbados Defence Force (BDF) Cyber Unit? Has he consulted with anyone on what was the mandate, scope, and lessons learned from the government’s failed Cyber Security Working Group (CSWG)? Has someone told him that in recent years, a Barbados Computer Emergency Response Team (BCERT) was funded by international donors, an office location and equipment was setup, but the CERT was never staffed or actually operational? To be frank, he seems quite unaware of what has transpired in the nation’s cybersecurity landscape over the past 5-7 years.

The Spectre of Abuse, Censorship, and Exclusion

While the government touts the benefits of centralized digital infrastructure, we must also consider its darker implications. A nationally controlled data center, pervasive e-government systems, and fully integrated identity-based platforms can easily become powerful tools for abuse of authority, mass surveillance, and oppression. These risks are even more pronounced with GovTech’s proposed use of artificial intelligence (with no regulatory safeguards) and the government’s insistence on implementing poorly drafted and potentially rights-violating cybercrime laws.

Myself and others have raised serious concerns, including worries about how new citizen-centered digital services are developed and managed; social exclusion and discrimination; privacy and data protection; cybersecurity; and major risks for human rights. In the context of human rights, the risks are related to the right to privacy, freedom of movement, freedom of expression, and other protected rights. For example, GovTech has stated that they plan on “releasing certain public datasets” in order “to spur the development of new products and services from local tech companies.” Government must be transparent on whether or not personal data will be involved and how these decisions align with the Data Protection Act, including what risk assessments and security countermeasures will be put into place to prevent material harm to individuals.

With all government data and services funneled through a single point, the temptation for overreach becomes significant. Who will oversee this system? What checks and balances will be in place to prevent abuse? The ability to control information flow and access to digital services could be weaponized against dissenting voices or used to manipulate public opinion.

We must demand clear, legally robust safeguards against such misuse. Without them, our journey towards digital transformation may well become a path to digital authoritarianism.

The Bigger Picture

While digital transformation is undoubtedly crucial for Barbados’ future, we must approach these grand declarations with healthy skepticism. Are we genuinely prepared for the scale of change being proposed? Do we have the necessary infrastructure, expertise, and, most importantly, the political will to see these projects through?

Moreover, in our rush to digitize, are we addressing more fundamental issues? Can we talk about advanced data centers when parts of our island still struggle with basic Internet connectivity? Are affordable Internet and telecoms services even attainable when the regulating functions within the Ministry of Industry, Information, Science and Technology (MIST) and the Fair Trading Commission (FTC) are incapable of delivering core consumer benefits (e.g., consumer protection, service quality, diverse product and services offerings, affordable prices, etc.)? Can we really talk about cybersecurity when breaches of government IT systems are the norm as opposed to the exception? Why are the bulk of e-government services still lacking in accessibility features for the differently abled?

Mr. Boyce emphasized that, “The National Data Centre will allow the government to take a more data-driven approach to governance.” Data centers and data governance are both important for the country’s data-driven future, but they have very different focuses, and the links between the two are tenuous. A data center is a physical facility that is used to house IT infrastructure, applications, and related data. Data centers are designed based on technology components: networks, computing, and storage resources that enable the delivery of shared applications and data. Data governance involves the management of data quality, security, usability, and availability. It is oriented towards people and processes – policies, procedures, roles, and metrics which ensure data is leveraged efficiently and effectively. Data governance can help the government and private corporations make better decisions, reduce costs, and comply with regulations such as the Data Protection Act (DPA), General Data Protection Regulation (GDPR), and others. However, one can have a data center and still have poor data governance or you can have no data center and have strong data governance. There are literally no dependencies of either element on the other.

“A key aspect of the digital transformation plan is to integrate digital services, allowing ministries and departments to collaborate seamlessly. Initiatives such as digital identifiers and signatures will enable citizens to access multiple services through a centralized portal, gov.bb, reducing fragmentation in the current system.” This statement from the CEO of GovTech is quite worrisome. Does he know that over the last 4 years there was an IDB-funded e-Services Project with these same objectives that failed spectacularly? Does he realize that the National Digital ID project – another public sector IT project that was poorly executed – was designed to provide centralized identity-based services to citizens, including digital identifiers and signatures?

The fact remains that IT projects for the Government of Barbados seldom fail due to technology-related issues. The technologies are generally sound and fit for purpose. Leadership-related issues are at the core of these repeated failures. A lack of skills in managing complex, large scale IT projects is also a major factor, which leads to a corresponding inclination to rely instead on outsourcing to consulting firms or a heavy dependence on the professional services arms of vendors. The problem here is that government employees lack the capabilities to manage these third-parties, are unable to meet government-owned deliverables, or impose unrealistic / infeasible requirements on experts that actually know what they’re doing. In addition to the absence of skills for managing large IT efforts in general, there are also huge deficiencies in change management skills in particular.

A Call for Transparency and Realism

As citizens, we deserve more than lofty promises and tech jargon. We need a clear, realistic roadmap for digital transformation that acknowledges our current limitations and outlines concrete steps to overcome them.

Instead of grand visions, let’s start with achievable goals. Develop a strategic roadmap that has a long-term arch and practicality that survives biased political motivations and changes in government administrations. Improve our basic digital infrastructure and access to it for all. Invest in education to build a tech-savvy workforce. Ensure that our legal and regulatory framework supports open, accessible, secure, rights upholding, and citizen-centric digital services. Create governance, risk, and oversight mechanisms which guarantee that projects deliver tangible value, not just headlines.

Barbados has the potential to become a digital leader in the Caribbean, but not through wishful thinking. We need honest assessments, pragmatic planning, and, above all, a commitment to turning words into action. Until then, these digital aspirations will remain just that – unfulfilled aspirations.

Essential skills for today’s threat analysts

“Skilled threat hunters can play a dual role for organizations, hunting for threat actors as well as ensuring budget is directed at tools and technology that will bolster the hunting capabilities, according to the SANS 2023 Threat Hunting survey. However, a lack of skilled staff is hampering the success of threat hunting efforts, according to the global survey of 564 respondents drawn from SOC analysts, security managers and administrators.

Adding to the task, threat hunters themselves are seeking more training, education, and support from management, the survey has found. As CISOs look ahead to 2024 and the cybersecurity challenges it will bring, what do they need from threat hunting teams and how should threat hunters themselves look to strengthen their skill set?”

Threat analysts play crucial roles in cybersecurity. Without them, it is near impossible to obtain actionable intelligence on potential threats, and other security professionals like security architects and security engineers have no way to effectively focus their efforts.

Demand for threat analysts is also growing and many enterprises have decidedly made threat analysis one of their top security priorities.

It was great speaking to Rosalyn Page about the critical skills that threat analysts need to be successful. She asks the most probing questions and has brought together the insights of several professionals into a solid article.

Check out Rosalyn’s article here.