Over 5.4 million cyber attacks recorded in first quarter—Wheatley
KINGSTON, Jamaica—Minister with responsibility for Science, Technology and Special Projects, Dr Andrew Wheatley, has reiterated his call for stronger cyber-security measures across the country, noting that over 5.4 million attempts to breach Jamaica’s digital systems were recorded in the first quarter of this year.
His call for greater awareness comes as his ministry launched its National Cybersecurity Awareness Month at a post- Cabinet media briefing at Jamaica House on Wednesday.
Wheatley noted that the number of attacks increased from 12 million in 2022 to 43 million in 2024 and over 49 million last year.
“The truth is that we cannot pretend the threat is small. We have to prepare ourselves as a real target. Government agencies have been hit by ransomware. Institutions have seen key systems go dark for days. A breach on a major government digital platform exposed the personal information of hundreds of thousands of Jamaicans. In fact, attackers now use artificial intelligence to find the weak door first,” Wheatley told the media briefing.
Wheatley argued that cyber attack on the country’s critical infrastructure deserves the same seriousness given to a natural disaster.
“What it does for the country is more or less the same. It creates havoc and confusion. It cripples infrastructure. It affects lives. Imagine when the grid goes down, the family in the dark cannot tell whether it is the wind or a code that did it because the impact, when the water pump stops and you are no longer able to access water in your pipes because the National Water Commission system was attacked. Imagine the hospital that is crippled by an attack and you are not able to access critical patient information,” he said.
According to Wheatley In 2020, Jamaica was rated at around 40 per cent in terms of its national cybersecurity maturity, against 70 per cent for the regional year.
“The gap is real, but we are closing that gap and we have a lot to speak about in terms of achievements to be able to close that gap. The Jamaica Cybersecurity Standards Framework is now complete and the National Cyber Incident Response Plan is ready. We have secured some US$10 million through the Strengthen Cybersecurity in Jamaica Project and work is now on the way for a new cybersecurity law,” he said.
Making his contribution to the Sectoral Debate in June, Wheatley disclosed that the proposed legislation will facilitate international cooperation in investigating cyber criminals operating abroad and will establish the National Cybersecurity Directorate in statute, giving Jamaica’s permanent cybersecurity authority a legal foundation.
Furthermore, he noted that it will create a formal framework for designating and protecting critical information infrastructure in sectors such as national life, energy, banking, telecommunications, health, and Government.
At the time, the technology minister said:“ It will mandate minimum cybersecurity standards across regulated sectors, with the authority to enforce compliance. It will create clear obligations for incident reporting, responsible disclosure of vulnerabilities, and the regulation of cybersecurity service providers operating in Jamaica.”
On Wednesday, Wheatley said a proposal to establish the National Cybersecurity Coordination Assurance Council (NCCAC) will be taken to Cabinet.
“As proposed in my Sectoral presentation, it will be a lean council in the Office of the Prime Minister set up for 24 months with members from Government, security forces, regulators, the private sector, academia and the Office of Information Commission,” he said, adding that The Office of Disaster Preparedness and Emergency Management will also be involved.
“The council’s full mandate and work will be set out once Cabinet has approved the proposal, but what I can tell you today is its purpose, and that is to turn the plans we have already into action and to prepare for a permanent National Cybersecurity Authority. But no council, ladies and gentlemen, and no law can do this alone. Because most attacks still begin with one person, one message and one key,” Wheatley stressed.