
Executive Summary
Ask any Caribbean board what cyber scenario it fears most and the answer arrives without hesitation: ransomware. The fear is rational. A successful ransomware event is not an IT incident; it is a full business interruption with a criminal counterparty attached — systems encrypted, operations halted, data stolen for a second round of extortion, and a countdown clock imposed by someone who has studied exactly how much pain the organisation can bear. For a distributor, it is trucks that do not move. For a credit union, it is members locked out of their own money. For a hotel, it is a front desk working on paper in high season. For a government agency, it is citizens unserved and headlines writing themselves.
Here is the truth this article is built on: the outcome of a ransomware event is decided almost entirely before it begins. Organisations that survive well and organisations that suffer catastrophically face broadly the same attackers using broadly the same methods; what differs is preparation — six specific disciplines, each testable in advance, none exotic, all routinely neglected. This article walks through how these events actually unfold, the six disciplines that determine the outcome, what “we have backups” must genuinely mean, and the decision framework every board should agree before it is ever needed — including the ransom question nobody wants to discuss and everybody must. It closes with ten questions whose honest answers predict your organisation’s outcome more reliably than any security budget.
Why Ransomware Is the Caribbean’s Flagship Loss Scenario

Ransomware dominates the regional threat picture for reasons of economics, not malice toward the Caribbean specifically. The modern ransomware operation is a business: access is obtained or purchased, victims are researched, and the ransom is priced to the victim’s revenues, insurance and desperation. Mid-sized organisations — the backbone of Caribbean economies — sit in the profitable middle of that market: large enough to pay meaningful sums, small enough to lack the layered defences and around-the-clock monitoring of global enterprises. The double-extortion model has made the calculus worse: even an organisation that can restore its systems faces a second demand over stolen data, with regulators, customers and data-protection statutes waiting on the other side of any disclosure.
The regional pattern is consistent enough to state plainly, without naming victims: organisations across the Caribbean — financial institutions, distributors, utilities, healthcare providers, government bodies — have experienced events in recent years that halted operations for days or weeks, and the difference between a difficult fortnight and an existential crisis has tracked, almost perfectly, the presence or absence of the disciplines this article describes. Insurers have noticed the same pattern, which is why ransomware-specific questions now dominate cyber underwriting — and why the readiness this article describes is increasingly the price of coverage itself.
How a Ransomware Event Actually Unfolds

The popular image — a bolt from the blue that encrypts everything in an instant — misleads in a way that matters, because it hides where defence is possible. Real events unfold in stages. First comes entry, typically through the routine weaknesses this series has discussed: a convincing phishing message, exposed remote access, an unpatched internet-facing system, or a compromised supplier. Then comes the quiet phase: the intruder explores, escalates privileges and maps the environment — often over days or weeks — identifying what matters most and, critically, locating the backups, because modern operators disable or encrypt backup systems first, knowing that recoverable victims do not pay. Only then, frequently timed for a weekend or holiday when response will be slowest, does encryption detonate and the demand appear — accompanied, in the double-extortion model, by proof that data has already left the building.
Every stage of that sequence is an opportunity. Entry can be hardened against. The quiet phase is detectable — by monitoring that watches for the movement and escalation this series’ technical articles described. Backups can be architected so the intruder cannot reach them. And response can be rehearsed so the worst morning is a bad day executed well rather than an improvisation. The stages are the defence map; the six disciplines below simply follow it.
| THE DEFINING FACT
Modern ransomware operators locate and destroy backups before they encrypt anything else — because recoverable victims do not pay. Whether your backups survive that hunt is decided by architecture, not by luck. |
The Six Disciplines That Decide the Outcome

- Entry hardening. The unglamorous hygiene that closes the common doors: multi-factor authentication everywhere that matters, disciplined patching of internet-facing systems, hardened remote access, and staff who have been trained — and tested — against the phishing that starts most events.
- Privileged access control. Ransomware’s blast radius is a function of the credentials it captures. Tightly held administrative rights, separated admin accounts and removal of standing privilege turn a compromised workstation into a contained problem rather than a company-wide one.
- Detection during the quiet phase. Monitoring capable of noticing an intruder’s movement and escalation in the days before detonation — the single highest-value window in the entire event — whether delivered in-house or through a managed service that is actually watched.
- Networks divided so that compromise of one zone does not grant the whole estate: the difference between losing a department and losing the organisation.
- Backup architecture built for a hostile hunt. Copies that the intruder cannot reach or alter — offline or immutable, separated from production credentials — with restoration actually proven, a discipline important enough to have the next section to itself.
- Rehearsed response. An incident plan with named decision-makers, pre-positioned technical and legal support, communication templates, and — per Article 3 — executives and directors who have practised in a tabletop exercise before the real morning arrives.
What “We Have Backups” Must Actually Mean

No sentence in Caribbean boardrooms carries more unexamined comfort than “we have backups.” The claim that matters is different and has three parts. First, survivability: would the backups survive the attack itself? Copies permanently connected to the production network, accessible with the same administrative credentials the intruder now holds, are not backups in any meaningful sense — they are additional victims. Survivable architecture keeps copies offline or immutable, on separate credentials, with retention deep enough to reach behind an intrusion that may have begun weeks earlier.
Second, restorability at business speed. The question is never “do backups exist” but “how many days until the organisation operates again, and how much data do we lose?” — recovery time and recovery point, expressed in business terms and agreed with the board as part of the risk appetite this series has urged throughout. An organisation that needs three weeks to rebuild from clean copies has backups and does not have resilience. Third — and this is where comfort goes to die — demonstration. A restoration that has never been rehearsed at meaningful scale is a theory; the middle of a crisis is the wrong moment to discover the missing dependency, the corrupted archive or the undocumented sequence. The test, per this series’ standing rule, is not what management asserts but what has been demonstrated — and independently verified.
The Decision Nobody Wants: Preparing the Ransom Question in Advance

Whether to pay a ransom is among the hardest decisions a board can face, and organisations that first confront it at 2 a.m., mid-crisis, decide it badly. The framework belongs in the drawer before the event. It should record the considerations the board will weigh: that payment funds criminal enterprises and marks the payer as a proven customer; that payment guarantees nothing — decryption tools fail, and stolen data is not returned by promise; that legal exposure is real, since payments touching sanctioned entities can themselves be unlawful, and counsel must be in the room; that insurers, where cover exists, have contractual rights in the decision and access to experienced negotiators; and that the genuine alternative to payment is not defiance but recovery — which returns the question, as everything in this scenario does, to whether the backups survived and restoration was proven.
This is precisely why Article 3 insisted on an escalation protocol agreed in advance: who convenes the board, within what hours, with what external support already on retainer. A board that has rehearsed this decision in a tabletop exercise — with its lawyers, its insurers’ requirements and its own values on the table — will make it in the real event with speed and coherence. A board that has not will make it under duress, in public, and live with it.
The Ransomware Readiness Review: Five Actions This Quarter

- Assess against the six disciplines. An honest, evidence-based review of entry hardening, privileged access, detection, segmentation, backup architecture and response readiness — scored against the loss scenario, not against a generic checklist.
- Prove one restoration. Select the systems the business can least live without and rehearse their recovery from survivable copies — timed, documented, and repeated until the number is one the board can accept.
- Run the executive tabletop. Half a day, the realistic scenario, decision-makers present — including the ransom framework, the communications drill and the escalation protocol, exercised before they are needed.
- Pre-position the response. Incident support, legal counsel and insurer notification paths arranged now; the first hours of a real event are too expensive to spend finding phone numbers.
- Verify with testing. Per Article 6: have the disciplines validated by people attempting what an attacker would attempt — including whether the quiet phase is detected and whether the backups can be reached.
The Dawgen Global Perspective

Dawgen Global treats ransomware readiness as the sharpest single test of everything this series has argued, because the scenario refuses to be managed by documents. Governance without tested recovery is a binder. A clean scan without detection capability is a false comfort. An incident plan no executive has rehearsed is a stage prop. The organisations that emerge from these events with their operations, finances and reputations intact are those in which the six disciplines were assessed honestly, tested genuinely and governed continuously — the integrated assurance model of this series, applied to its hardest case.
The firm’s resilience practice delivers that application end to end: ransomware readiness assessments against the six disciplines, restoration rehearsals and recovery-time validation, executive and board tabletop exercises including the ransom decision framework, and technical validation of detection and backup survivability under the safety controls earlier articles described. The next article in this series moves from the scenario to the sector that fears it most — the Caribbean’s financial institutions, and the specific assurance expectations now converging on banks, credit unions and insurers from regulators, correspondents and members alike.
Ten Questions That Predict Your Ransomware Outcome

- Is multi-factor authentication enforced on every remote access path and administrative account — without exceptions?
- How quickly are internet-facing systems patched — and who verifies it happened?
- If a staff workstation were compromised today, what could its credentials actually reach?
- Would anyone notice an intruder moving through our network during the quiet phase — nights and weekends included?
- Are our backup copies genuinely beyond the reach of production administrator credentials?
- When did we last restore our most critical systems from backup — timed, at meaningful scale?
- What is our honest recovery time, in days, and has the board accepted that number?
- Does a written ransom decision framework exist — with counsel and insurer requirements built in?
- Have executives and directors rehearsed this scenario in a tabletop exercise within the past year?
- Has any independent party tested whether the six disciplines actually hold — or is our confidence self-assessed?
Frequently Asked Questions
Should an organisation ever pay a ransom?
No answer fits every case, which is exactly why the framework must exist before the event. Payment is legally hazardous, funds criminal enterprise, guarantees neither decryption nor deletion of stolen data, and marks the payer for return visits. The organisations with genuine freedom to refuse are those whose backups survived and whose restoration was proven — resilience is what makes principle affordable.
Does cyber insurance cover ransomware?
Policies increasingly do, within limits and conditions — and those conditions are the point: insurers now require evidence of the very disciplines this article describes, participate in response decisions, and scrutinise representations hardest at claim time. Treat the policy as one layer of resilience, never a substitute for it.
We are a small organisation. Are we really a target?
Yes — arguably the preferred one. Modern operations are volume businesses that price ransoms to the victim: small and mid-sized organisations are attacked precisely because defences are thinner and a modest ransom is likelier to be paid quickly. Scale reduces the headline size of the demand, not the probability of the knock.
What single step most improves our position fastest?
Prove a restoration. Nothing changes an organisation’s real position — or its negotiating position — faster than demonstrated, timed recovery of critical systems from copies an attacker cannot reach. It converts the ransom from an existential question into a commercial one, and most organisations discover more in one rehearsal than in a year of policy work.
Move From Cybersecurity Assumptions to Independent Cyber Assurance
Dawgen Global combines cyber governance, risk-based internal audit, penetration testing, resilience assessment and remediation validation to help Caribbean organisations determine whether their cybersecurity controls are properly designed and operating effectively. To learn what your organisation’s ransomware outcome would actually be — before an attacker answers the question for you — request a confidential ransomware readiness review or an executive tabletop briefing.
About Dawgen Global
Dawgen Global is an independent, integrated multidisciplinary professional services firm headquartered at 47 Trinidad Terrace, New Kingston, Jamaica, serving more than 15 territories across the Caribbean. Founded and led by Dr. Dawkins Brown, Executive Chairman, the firm is independent and not affiliated with any international network. It delivers a full suite of professional services under one roof: audit and assurance; tax advisory; IT and digital transformation; risk management; cybersecurity; actuarial and insurance regulatory advisory; HR advisory; mergers and acquisitions; corporate recovery; business advisory and strategy; accounting BPO and virtual CFO services; and legal process outsourcing.
The proposition is simple: big-firm capability without the big-firm price. Dawgen Global’s integrated approach is built for the specific complexities and opportunities of the Caribbean market, helping organizations make sharper, better-informed decisions that drive measurable progress.
To explore a partnership, reach out:
- Website: dawgen.global
- Email: [email protected]
- WhatsApp (Global): +1 555-795-9071
- Caribbean offices: +1 876-665-5926 | +1 876-929-3670 | +1 876-926-5210

