
Executive Summary
For most of the past two decades, cybersecurity in the Caribbean has lived in the IT department: a budget line for firewalls and antivirus software, a technical specialist’s responsibility, a subject the board touched once a year, if at all. That arrangement no longer matches reality. Cyber risk has become one of the fastest-growing enterprise risks facing Caribbean organisations, capable of interrupting operations, draining cash, breaching data-protection law, destroying customer trust and, in regulated sectors, attracting supervisory action against directors themselves.
The consequences of a cyber event are not technical. They are financial, operational, legal and reputational — which is precisely why the oversight of cyber risk belongs where every other enterprise risk belongs: with the board. Directors are not expected to configure firewalls, but they are expected to govern the risk, set the organisation’s appetite for it, assign accountability for managing it, and obtain independent evidence that the controls management describes actually work.
This article — the first in Dawgen Global’s Cyber Assurance Advantage™ series — explains why cyber risk must now sit on the enterprise-risk agenda of every Caribbean board, why the conventional approaches many organisations rely on fall short, and the practical steps directors and executives should take within the next ninety days.
Why Is Cyber Risk Now a Boardroom Issue in the Caribbean?

The Caribbean is digitising at a remarkable pace. Banks and credit unions have moved members onto online and mobile channels. Governments are digitising citizen services, tax administration and procurement. Distributors and manufacturers run their operations on integrated ERP platforms connected to suppliers and logistics providers. Hotels take the majority of their bookings through digital channels holding guest identity and payment data. Payments themselves are modernising across the region, with instant transfers and digital wallets replacing cash and cheques.
Every one of these advances creates value — and every one of them expands the attack surface. The uncomfortable regional truth is that exposure has grown faster than governance. Many Caribbean organisations run lean IT teams, depend heavily on a small number of outsourced providers and cloud platforms, and have limited access to specialist cyber talent. Regional assessments of cybersecurity maturity across Latin America and the Caribbean continue to identify significant gaps in governance, incident-response capability and skills, even as national frameworks improve. CARICOM’s updated cyber security and cybercrime agenda points in the same direction: toward greater resilience, coordination and — critically — accountability.
The legal environment has also changed. Jamaica’s Data Protection Act is fully in force, and comparable statutes now operate or are advancing in Barbados, Trinidad and Tobago, Guyana and elsewhere in the region. Financial regulators increasingly expect boards of licensed institutions to demonstrate oversight of technology and cyber risk. Cyber insurers have sharpened their underwriting questions, and a growing number of international customers, lenders and franchise partners now demand evidence of cyber controls before they will do business. A Caribbean board that treats cybersecurity as a delegated technical matter is not merely behind best practice; it is increasingly out of step with law, regulation and the market.
What Makes Cyber Risk an Enterprise Risk Rather Than a Technical Problem?

The distinction is best seen by following a single vulnerability to its destination. An unpatched server or a compromised email account is a technical condition. But when ransomware encrypts the systems of a distributor, the enterprise consequence is that trucks do not leave the depot, customers are not invoiced, and revenue stops. When a finance officer is deceived by a fraudulent payment instruction sent from a compromised supplier mailbox, the consequence is an unrecoverable cash loss. When a credit union’s member records are exfiltrated, the consequences are statutory breach-notification obligations, potential regulatory penalties, and an erosion of the member trust on which the institution was built.
In every case, the event begins in technology and ends on the income statement, in the legal department, and in the organisation’s reputation. That trajectory is the defining characteristic of an enterprise risk. It is also why cyber risk cannot be “owned” by the IT function. IT can manage technical controls, but it cannot own business interruption, fraud losses, regulatory relationships or brand damage. Ownership of those consequences — and of the decisions about how much risk to accept and how much to spend reducing it — belongs to executive management, under the oversight of the board.
| THE GOVERNANCE PRINCIPLE
Management owns and manages cyber risk. The board governs it: setting appetite, assigning accountability, ensuring resources, and obtaining independent assurance that controls are designed and operating effectively. Neither role can be delegated to the IT department. |
Why Do Conventional Approaches Fall Short?

Most Caribbean organisations are not doing nothing about cybersecurity. The problem is that the things many are doing create comfort without creating evidence. Five patterns appear repeatedly:
- Spending is mistaken for security. Licences for security tools prove that money was spent, not that the tools are configured, monitored and effective. Unwatched alerts protect no one.
- Policies are mistaken for controls. A well-written information-security policy describes intent. It says nothing about whether multi-factor authentication is actually enforced, whether backups actually restore, or whether leavers’ access is actually removed.
- Compliance checklists are mistaken for resilience. A point-in-time attestation reflects one day in a threat environment that changes daily, and typically examines documentation more closely than operation.
- Delegation is mistaken for governance. When cyber is left entirely to IT, the people managing the risk are also the only people reporting on it — an arrangement no board would accept for financial reporting.
- Activity dashboards are mistaken for risk reporting. Counts of blocked emails and closed tickets describe activity. They do not answer the questions directors actually need answered: what could hurt us, how badly, and are we protected?
What is missing from each pattern is the same thing: independent verification. Boards do not accept management’s unaudited word on the financial statements, and there is no principled reason to accept it on a risk capable of stopping the business.
What Are the Governance and Internal Audit Implications?

Treating cyber as an enterprise risk has concrete governance consequences. Cyber risk should appear on the board or audit and risk committee agenda as a standing item, supported by reporting designed for directors rather than technicians. The organisation should articulate a cyber risk appetite — an explicit statement of the exposure it is and is not willing to accept — because without one, every security investment decision is made in the dark. Accountability should be assigned by name: who in executive management owns cyber risk, who operates the controls, and who provides independent assurance over both.
That last element has just acquired new force. The Institute of Internal Auditors’ Cybersecurity Topical Requirement, in force since February 2026, establishes a minimum baseline that internal audit functions must apply when providing assurance over cybersecurity governance, risk management and controls. For Caribbean organisations, the implication is direct: an internal audit plan that omits cyber, or treats it superficially, no longer conforms to global standards. Boards and audit committees should be asking their chief audit executives how the function will meet the requirement — and, where in-house cyber skills are limited, whether co-sourcing specialist support is the practical route to credible coverage.
The familiar three-lines model applies here as it does everywhere else in enterprise risk: management and IT operate the controls; risk and compliance functions oversee and challenge; internal audit — supported by technical specialists where necessary — provides independent assurance to the board. When those lines blur, so does accountability.
What Does Independent Technical Assurance Add?

Governance review alone cannot answer the question that matters most: do the controls actually withstand attack? That answer requires technical evidence — vulnerability assessment to identify weaknesses across the environment, penetration testing to establish whether those weaknesses can genuinely be exploited, configuration review of the systems and cloud platforms the business depends on, and validation that backups restore and recovery plans work under pressure. These are different exercises with different purposes; a vulnerability scan, for instance, is not a penetration test, a distinction a later article in this series examines in detail.
Equally important is translation. A technical finding expressed as a severity score means little in a boardroom. The same finding expressed as “an attacker who compromises this system can generate fraudulent payment instructions” or “this exposure could halt production for days” is a business risk a board can weigh, prioritise and resource. And assurance does not end when the report is issued: findings must be assigned owners and dates, remediation must be evidenced, and fixes must be independently retested and validated as closed. An unremediated finding is not a completed audit; it is a documented, known exposure.
The strongest position a board can occupy is one coordinated risk narrative — from governance and policy, through control design and operation, to the technical attack surface and the verified closure of what was found. Fragmented providers each holding one piece of that narrative leave the board assembling the puzzle itself.
What Practical Actions Should Boards Take in the Next Ninety Days?

- Put cyber risk on the agenda — properly. Schedule a dedicated board or committee session on cyber exposure, with management presenting in business terms, not technical ones.
- Assign ownership by name. Confirm which executive owns cyber risk, and how the three lines — operation, oversight, independent assurance — are populated in your organisation.
- Commission an independent diagnostic. Obtain a rapid, fixed-scope assessment of governance, control and technical exposure, benchmarked against a recognised framework such as NIST CSF 2.0, to establish where you actually stand.
- Define your cyber risk appetite. Decide, explicitly, what exposure is unacceptable — to member data, to operational downtime, to payment fraud — and let that decision drive investment.
- Test your readiness to respond. Ask when the incident-response plan was last exercised with executives in the room, and when backup restoration was last proven, not assumed.
- Ask internal audit about the IIA requirement. Establish how the cybersecurity Topical Requirement will be met in the current audit plan, and whether specialist co-sourcing is needed.
- Demand remediation accountability. Require every cyber finding — from any source — to carry a named owner, a date, and independent validation of closure.
The Dawgen Global Perspective

Dawgen Global’s view is that the Caribbean market has been offered two incomplete answers. Conventional audit and advisory providers understand governance but often lack the technical depth to test whether controls survive contact with an attacker. Technical cybersecurity vendors can find vulnerabilities but rarely translate them into the governance, financial, compliance and board-level consequences on which decisions depend. The space between the two — integrated, independent cyber assurance that runs from board oversight to technical validation and verified remediation — is where Caribbean organisations are least served and most exposed.
Closing that gap is the purpose of Dawgen Global’s Cyber Risk Assurance & Resilience practice, which combines cyber governance review, risk-based internal audit, technical security testing, resilience assessment and remediation validation in a single methodology, calibrated to the realities of Caribbean scale, infrastructure, regulation and resourcing. The articles that follow in this series examine each element in turn — beginning with the difference between cybersecurity activity and cyber assurance, the subject of Article 2.
Ten Questions Every Caribbean Board Should Ask About Cyber Risk

- When did this board last receive a substantive report on cyber risk expressed in business terms?
- Which named executive owns cyber risk in this organisation — and does that person agree?
- What is our stated cyber risk appetite, and where is it documented?
- What would a serious cyber incident cost us in downtime, cash loss, regulatory exposure and reputation?
- When were our cyber controls last independently tested — not self-assessed — and what did the testing find?
- Has every finding from that testing been remediated, and has closure been independently verified?
- When did we last restore from backup and exercise our incident-response plan with executives participating?
- How dependent are we on third-party providers and cloud platforms, and what evidence of their security do we hold?
- How will our internal audit function meet the IIA Cybersecurity Topical Requirement this year?
- If a material incident occurred tonight, who would make decisions, and would this board learn of it within hours or days?
Frequently Asked Questions
Is cybersecurity the responsibility of the board or the IT department?
Both, in different roles. IT and management operate and manage the controls; the board governs the risk — setting appetite, assigning accountability and obtaining independent assurance. A board that has fully delegated cyber to IT has not discharged its oversight duty; it has abandoned it.
What is the difference between cybersecurity and cyber assurance?
Cybersecurity is the set of activities and controls an organisation implements to protect itself. Cyber assurance is independent evidence that those controls are well designed and actually operating — the difference between management saying “we are protected” and the board knowing it.
How often should a Caribbean board receive cyber risk reporting?
At minimum quarterly at board or committee level, with immediate escalation of material incidents, and an annual deep-dive that includes the results of independent assessment or testing. Frequency should rise with the organisation’s digital dependence and regulatory exposure.
Do smaller Caribbean organisations really need independent cyber assurance?
Yes — arguably more than large ones, because attackers deliberately target organisations too small to maintain specialist defences, and a single ransomware event or payment fraud can be existential for a mid-sized business. The scale of assurance should fit the organisation; the principle of independent evidence does not change.
Move From Cybersecurity Assumptions to Independent Cyber Assurance
Dawgen Global combines cyber governance, risk-based internal audit, penetration testing, resilience assessment and remediation validation to help Caribbean organisations determine whether their cybersecurity controls are properly designed and operating effectively. To take the first step, request a confidential Cyber Risk Diagnostic or an executive briefing for your board.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210

