Back to all insights

Building Resilient Digital Infrastructure in an Era of Rising Cyber Risk

Smiling man in a navy suit, white shirt, red tie, and pocket square posing for a formal headshot against a light background.

Resilience is now a boardroom issue. It is no longer enough for infrastructure to be available most of the time or for security to operate as a separate control layer. Organisations are increasingly judged by whether essential services can continue during disruption and how quickly they can recover when cyberattacks, system failures, human error or severe weather interrupt normal operations (World Economic Forum [WEF], 2024; Centres for Medicare & Medicaid Services [CMS], n.d.). 

This is especially relevant across Jamaica and the wider Caribbean, where organisations are modernising while managing rising cyber risk, data-protection obligations and the realities of lean internal IT teams. For many local organisations, the issue is not only whether the technology exists, but whether teams with limited capacity can govern, support, secure, and recover it. Resilience therefore extends beyond uptime to continuity, trust and the ability to restore service without avoidable damage to reputation or customer confidence (World Bank, 2024a; Office of the Information Commissioner, Jamaica [OIC], n.d.).

Downtime now carries consequences well beyond the IT department. An outage can affect revenue, customer experience, regulatory exposure and create reputational risks. As a global benchmark, IBM reported that the average cost of a data breach reached US$4.88 million in 2024, with 70% of studied organisations reporting significant or very significant disruption (IBM, 2024). The practical question for leaders is therefore not whether disruption is possible, but whether their environment is designed to absorb it, contain its impact, and recover within an acceptable timeframe. 

A Regional Threat Landscape That Demands Better Design

The regional trend is concerning. Disclosed cyber incidents in Latin America and the Caribbean have increased at an average rate of 25% annually over the last decade (World Bank, 2024a; European External Action Service [EEAS], 2025). This measure is distinct from threat-telemetry counts. Fortinet data reported by the Jamaica Observer recorded 43 million attempted cyberattacks against Jamaica in 2023, and more than 200 billion attempted attacks across the wider region (Jamaica Observer, 2024). Neither figure represents confirmed breaches, but both indicate sustained hostile activity against regional organisations.

Digital adoption is also accelerating. Internet use in the Latin American and Caribbean region rose from 68% to 81% between 2019 and 2023, while regional cybersecurity capacity has not advanced at the same pace (World Bank, 2024a; World Bank, 2024b). The OAS and IDB have also identified continuing gaps in resources, skills development and cross-sector coordination (Organisation of American States [OAS], 2025). CARICOM IMPACS has consequently positioned the updated CARICOM Cyber Security and Cybercrime Action Plan as a regional framework for protecting critical infrastructure and strengthening trust in digital services (CARICOM IMPACS, 2025). 

These conditions make one point unavoidable: isolated security products do not create resilience. Resilience must be designed into the infrastructure and reinforced through clear governance, ownership and testing.

Why Traditional Infrastructure Models Break Under Pressure

Many organisations treat infrastructure, security, backup and recovery as separate workstreams. That fragmentation creates risk, particularly in hybrid and multi-cloud environments where visibility, identity controls, compliance and secure data flows must be managed across platforms (National Security Agency [NSA], 2024; Fortinet, 2024). In practice, this weakness may show up as backups that are never restored, cloud services with unclear ownership, inconsistent access controls, or recovery plans that have not been tested under realistic conditions. 

Technology alone cannot close these gaps. A business may own capable security tools but lack governance; maintain backups but have no evidence that critical systems can be restored; or consume cloud services without a clear continuity architecture. Effective cyber resilience therefore depends on leadership, accountable ownership, monitoring and a coordinated response across the organisation and its technology partners (WEF, 2024; CARICOM IMPACS, 2024). 

From Backup to Business Continuity

One of the most persistent misconceptions is that backup alone equals resilience. It does not. A backup is a recoverable copy of data or systems; disaster recovery defines how technology will be restored after a major interruption; and business continuity addresses how essential operations will continue during and after that interruption (National Institute of Standards and Technology [NIST], n.d.-a). A backup that has never been successfully restored is evidence of data duplication, not evidence of recoverability.

The distinction matters because recovery is measured in business outcomes, not merely in files restored. Leaders need to know which services must remain available, what dependencies support them, how much data loss is tolerable and how long the organisation can operate before restoration becomes critical. The 2022 ransomware attack in Costa Rica, which affected approximately 26 government entities and was estimated to have caused losses equivalent to about 2.4% of GDP, illustrates the scale of disruption that can follow when essential services are compromised (World Bank, 2024a; World Bank, 2024b).

The MC Systems View: Resilience by Architecture, Not by Afterthought

At MC Systems, we believe stronger resilience does not come from adding more tools to a fragmented environment. It comes from designing infrastructure intentionally, embedding security, aligning recovery capabilities to business priorities and making ownership clear from the outset. Cloud, networking, identity, backup, disaster recovery and continuity planning should therefore be treated as parts of one operating model rather than as disconnected projects (WEF, 2024; NSA, 2024).

Our role is to help clients connect technical design to operational reality: what must remain available, what can tolerate interruption, how quickly services must recover, what level of data loss is acceptable and who is accountable when disruption occurs. For organisations with lean IT teams, this requires practical architecture, clear documentation, disciplined testing and coordinated delivery across internal teams, service providers and technology partners.

What Leaders Should Do Next

For CIOs and business leaders, the next steps are practical.

First, identify the services that are critical to customers and operations.

Second, map the applications, data, people, facilities, power and connectivity on which those services depend.

Third, define realistic recovery time and recovery point objectives.

Fourth, simplify and strengthen the architecture, including identity, security, backup and monitoring. Finally, test recovery under realistic conditions and assign ownership for keeping plans, documentation and controls current.  

That discipline is what turns resilience from an aspiration into an architectural outcome.

References

CARICOM Implementation Agency for Crime and Security. (2024, October 23). CARICOM IMPACS hosts CCSCAP consultations. https://www.caricomimpacs.org/articles/caricom-impacs-hosts-ccscap-consultations [ibm.com]

CARICOM Implementation Agency for Crime and Security. (2025, November 1). Updated CARICOM Cyber Security and Cybercrime Action Plan (CCSCAP) launched. https://www.caricomimpacs.org/articles/updated-caricom-cyber-security-and-cybercrime-action-plan-ccscap-launched [csrc.nist.gov]

Centers for Medicare & Medicaid Services. (n.d.). Disaster recovery key concepts & definitions. https://www.cms.gov/tra/Infrastructure_Services/IS_0390_DR_Key_Concepts_Definitions.htm [oas.org]

European External Action Service. (2025, November 6). A cyber wall for the Caribbean. https://www.eeas.europa.eu/eeas/cyber-wall-caribbean_en [fortinet.com]

Fortinet. (2024, April 23). Key findings from the 2024 cloud security report. https://www.fortinet.com/blog/industry-trends/key-findings-cloud-security-report-2024 [caricomimpacs.org]

IBM. (2024, July 30). IBM report: Escalating data breach disruption pushes costs to new highs. https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs [idbinvest.org]

Jamaica Observer. (2024, April 19). Cyberattacks continue to rise but security firms vigilant. https://www.jamaicaobserver.com/2024/04/19/cyberattacks-continue-rise-security-firms-vigilantfortinet-report-shows-200-billion-attempted-attacks-caribbean-2023-43-million-jamaica/ [fortinet.com]

MC Systems. (Internal GTM plan). MC Systems Cloud and Hybrid Infrastructure GTM Plan v1. [caricomimpacs.org]

National Institute of Standards and Technology. (n.d.-a). Backup. Computer Security Resource Center. https://csrc.nist.gov/glossary/term/backup [oas.org]

National Institute of Standards and Technology. (n.d.-b). Disaster recovery plan (DRP). Computer Security Resource Center. https://csrc.nist.gov/glossary/term/disaster_recovery_plan [oas.org]

National Security Agency. (2024, March 7). Account for complexities introduced by hybrid cloud and multi-cloud environments. https://media.defense.gov/2024/Mar/07/2003407865/-1/-1/0/CSI-CloudTop10-Hybrid-Multi-Cloud.PDF [caricomimpacs.org]

Organization of American States. (n.d.). Cybersecurity program. https://www.oas.org/ext/en/security/prog-cyber [practicegu…ambers.com]

Organization of American States. (2025, December 18). 2025 OAS–IDB cybersecurity report: Latin America and the Caribbean make progress in strengthening their capacities, but the region remains exposed to increasingly complex digital threats. https://www.oas.org/en/media_center/press_release.asp?sCodigo=E-092/25 [oic.gov.jm]

World Bank. (2024a). Cybersecurity economics for Latin America and the Caribbean [Preliminary version]. https://documents1.worldbank.org/curated/en/099011925184519084/pdf/P179481-5515e6c4-1d69-444d-a057-741edce07402.pdf [eeas.europa.eu]

World Bank. (2024b, November 28). From fiction to reality: How Latin America became the world’s most critical cyber battleground. https://blogs.worldbank.org/en/latinamerica/seguridad-cibernetica-en-america-latina-y-el-caribe [publicatio…s.iadb.org]

World Economic Forum. (2024). Global cybersecurity outlook 2024. https://www3.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2024.pdf [cdn-dynmed…rosoft.com]

MCSystems
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.