In the fourth instalment of our Expert Insights series on cyber threats and security for 2026, and to commemorate Cybersecurity Awareness Month in October, we are joined once again by Cybersecurity Consultant David Gittens after a three-year break. During this conversation, David shares his thoughts on, among other things: where Caribbean organisations stand in terms of actual posture versus perceived readiness; how resource-constrained security teams can use AI to level the playing field; the biggest friction points governments face when translating policy into operational defence; and some high-impact security measures Caribbean MSMEs should prioritise today.

 

This episode is also available on SoundCloud, Apple Podcasts, Spotify and Amazon Music.

As organisations across the Caribbean region accelerate their digital transformation initiatives, they face an increasingly complex and aggressive cyber threat landscape. Recent intelligence reveals that regional organisations face an average of over 2,500 cyberattacks per week—roughly 40% higher than the global average—as threat actors increasingly view Small Island Developing States (SIDS) as high-value, vulnerable targets (Source: Symptai Consulting Limited). Moreover, Caribbean entities are navigating a surge in sophisticated ransomware campaigns, social engineering, and supply-chain vulnerabilities that are targeting critical infrastructure, government services and vital sectors, such as tourism and financial services.

In addition to traditional vulnerabilities, the rapid integration of artificial intelligence (AI) into everyday operations is compounding the situation. Although AI offers immense potential for automating workflows and improving efficiency, it also provides malicious actors with tools to execute hyper-targeted phishing campaigns and evade legacy defences. At the same time, regional organisations deploying Large Language Models and automated systems often lack the necessary governance and data security guardrails, resulting in a precarious position where sensitive data is exposed to unseen risks.

In this episode of the ICT Pulse Podcast, and in the fourth instalment of our Expert Insights series for 2026, we examine how Caribbean organisations can navigate this shifting digital reality.

 

Introducing our guest

David Gittens

David Gittens is an independent, Barbados-based cybersecurity consultant and a seasoned cybersecurity professional. He has spent a number of years providing cybersecurity services to global and regional banks and governmental organisations, including several years working in the area of cybersecurity risk. In 2021, he was voted one of the top ten security and resilience professionals in the entire Caribbean region by Information Security Journal. In 2024, he became a Commonwealth Caribbean Cyber Security Fellow, a new Commonwealth initiative intended to help promote cybersecurity within the Caribbean region.

For about four years, David sat on a national cybersecurity working group which provided advisory services to government. He also worked with the Organisation of American States and other cybersecurity experts to create Barbados’ first National Cybersecurity Strategy. Other national roles included him heading up the Anti-fraud Committee of the Barbados Bankers Association, as well as being the founding president of the Information Systems Security Association Barbados chapter, which was the first such chapter in this part of the world.

David’s professional focus is on making the Caribbean and the wider world more cyber secure, and as a result, he has invested a lot of time in developing skills needed to use cloud environments and AI systems safely. For the past two years, he has been part of the Cerebellum Project, an international initiative to provide effective guardrails for safe, secure, responsible, and trustworthy AI. He has worked on another international project by the Cloud Security Alliance to produce a trusted AI safety knowledge certification programme.

David attained a BSc (Honours) in Electronic & Electrical Engineering from Loughborough University of Technology in the United Kingdom (UK). He received his Master’s in Information Systems Management from the University of Liverpool in the UK.  Security certifications currently held include the CISSP, CRISC, CISA, CISM, CCSP, CCSK, AC|CISO, CSX-P, HISP, Security+, eCPPT, CHFI, and CDPSE.

 

Insights into our conversation

Discussions on cyberthreats and security are often sobering, and it is no different with David. The landscape has evolved considerably in recent years, and it has become increasingly difficult – even nearly impossible – for security experts to stay ahead of vulnerabilities and attacks. Moreover, in the realm of cybersecurity, it appears that AI is not levelling that playing field, as, according to David, the fixes current models produce are still not up to scratch.

 At the same time, we all need to fight the good fight. We need to do the best that we can – even if our governments have not implemented any AI guardrails and/or cybersecurity standards that we need to follow. Guidelines and frameworks are widely available that we can adopt within our own organisations (or homes) to improve our security posture.

Below are questions posed to David during our conversation.

  1. Can you give us a sense of the current state of the cyber threat landscape in Barbados and/or the wider Caribbean region and how it has changed since we spoke last year, in 2023?
  2. Looking at the current landscape, where do Caribbean organisations stand in terms of actual posture versus perceived readiness?
  3. What specific attack vectors or threat actors have emerged over the past year as the biggest risks for Caribbean infrastructure?
  4. How are credit unions and regional banks faring against increasingly sophisticated financial fraud and cyber-enabled crime?
  5. How are threat actors leveraging generative AI to target Caribbean organisations, and conversely, how can resource-constrained security teams use AI to level the playing field?
  6. What critical cloud misconfigurations or security gaps are you seeing most frequently in Caribbean deployments?
  7. As businesses in the region race to adopt Large Language Models (LLMs) and automated workflows, what are the most critical data privacy and security guardrails they tend to overlook?
  8. Having helped shape national policy initiatives like Barbados’s first National Cybersecurity Strategy, what are the biggest friction points governments face when translating policy into operational defence?
  9. As someone deeply involved in professional credentials and associations like ISSA, what realistic strategies can regional firms adopt to cultivate and retain local cybersecurity talent?
  10. How can CISOs and security managers communicate cyber risk effectively to boards and executive leadership without resorting to pure fear, uncertainty, and doubt?
  11. End-users and IT teams often experience “security fatigue” from constant alerts, mandatory policy updates, and training. How can security leaders build a culture of vigilance without burning out employees?
  12. For small-to-medium enterprises (SMEs) across the Caribbean with limited security budgets, what are 2 or 3 high-impact security measures they should prioritise today?

 

We would love to hear your thoughts!

Do leave us a comment either here beneath this article, or on our Facebook or LinkedIn pages, or via Twitter, @ICTPulse.

Also, if you or a member of your network is interested in joining us for an episode, do get in touch.

Let’s make it happen!

 

Select links

Below are links to some of the organisations and resources that were mentioned during the episode, or otherwise, might be useful:

 

 

Images credit:  D Gittens;  Magnific (Magnific); Zulfugar Karimov (Unsplash); Rafael Minguet Delgado (Pexels)

Music credit: The Last Word (Oui Ma Chérie), by Andy Narrell

Podcast editing support: Mayra Bonilla Lopez