Digital Negligence Is No Longer an Option
Cybercrime is also present in the Caribbean region. After a hack at a government agency, we need to wake up and change.
During the recent Caribbean ICT Summit in the Bahamas, Curaçao was praised as a digital frontrunner in the region. An honorable mention, and a clear call to action. Because digital progress isn't an endpoint — it's a responsibility.
That responsibility came under pressure almost immediately. Shortly after the summit, several sources reported that the Curaçao Tax Authority (Belastingdienst) had fallen victim to a ransomware attack. The incident underscores a harsh truth: a modern image without digital resilience is a facade. Curaçao has the ambition and the resources. But digital security must be a structural part of that ambition — not an afterthought, but a starting point.
Cyber incidents shouldn't come as a surprise
Yet the incident at the tax authority shouldn't come as a surprise. Cybercrime is on the rise everywhere in the world. The digital world has no borders. That creates opportunities for Caribbean islands, but it also opens the door to attacks from far beyond our own borders. All over the world, businesses, institutions and governments are taking measures to improve cyber resilience, and here too, we need to commit to that.
The question is: how far along are we in the Caribbean region? This is extremely difficult to determine, since it can vary enormously between businesses or institutions. What we do know is that more entities are vulnerable to attacks from outside. Research by ethical hackers at Tozetta, a cyber security company based in Curaçao, shows that critical vulnerabilities are still regularly found in the systems of organizations with an important societal function.
Concerns about Curaçao's digital resilience
What's concerning is that signals about this are sometimes picked up slowly, or not at all, by the organizations involved. That doesn't only affect those organizations — it affects all of us. Citizens should be able to count on systems that protect their privacy and safeguard the continuity of essential services.
Because what happens if a banking app stops working, a hospital loses access to patient data, or a government portal is down for days on end? Cyber security isn't just about data — it's also about the availability and reliability of digital services that keep daily life running.
Improving Curaçao's cyber resilience
This calls for a proactive attitude from Curaçao, and especially from the businesses and executives who play a key role in our society. Vulnerabilities in people, software and systems need to be taken seriously. That means not only investing in technology, but also in awareness and behavior. Employees need to be trained regularly to recognize digital threats. Executives need to include cyber security in their strategic policy, rather than leaving it solely to the IT department. Systems need to be tested periodically by independent specialists, so that risks don't only become visible after an incident. And where vulnerabilities are found, there needs to be room to respond quickly and transparently — not to point fingers, but to take shared responsibility and protect the continuity of our society.
Breaking the taboo
At the same time, the taboo needs to be broken. A hack can happen to any business or institution, no matter how large, professional, or well-secured they believe themselves to be. By covering up incidents or dismissing them as one-offs, structural weaknesses stay hidden beneath the surface. Only through openness and collaboration can we, as a society, learn, improve, and become more resilient. Taking responsibility also means daring to acknowledge where things go wrong, so that together we can build a digital infrastructure that not only looks modern, but can also take a hit.
Curaçao has everything it needs: talent, technology and ambition. But only through the joint efforts of government, businesses and experts can we build a future where digital security is just as much a given as digital growth.