August 2025 · InnovAKT intelligence assessment

In July 2025, six jurisdictions found out at the same time.

A coordinated ransomware campaign ran through government systems across Aruba, Curaçao and Sint Maarten. Tax collection, judicial operations and legislative communications were disrupted. We published a full assessment of it — the timeline below is from that work.

6

jurisdictions

affected by the single attack on the Joint Court of Justice

3+

government entities

compromised across multiple islands in ten days

55%

of OT environments

run four or more remote access tools — the path the campaign used

  1. 22 July

    The warning

    The Dutch Public Prosecution Service disconnects from the internet over NCSC warnings about Citrix NetScaler.

  2. 24 July

    Double extortion

    The Curaçao Tax Office is encrypted while its public filing portal is deliberately kept running.

  3. 24–25 July

    All six at once

    The Joint Court of Justice is compromised across all six Dutch Caribbean jurisdictions.

  4. Late July

    The shift

    Aruba's Parliament email systems are targeted — intelligence gathering rather than disruption.

Our assessment's conclusion was that this was not an isolated incident but a strategic probe: it gave threat actors a working map of regional dependencies, shared providers and remote-access infrastructure. The systems hit were administrative. The access paths they exposed run to operational technology.

Get the new Island Operator’s Guide →

Caribbean Ransomware Attacks — Advanced Intelligence Assessment and OT Security Implications. InnovAKT OT Cybersecurity Intelligence Team, August 2025. Remote-access figure: Claroty Team82.

The new field guide · 24 pages · English edition

Turn the lessons into your next move.

The Island Operator’s Guide to Cyber Resilience connects the July 2025 ransomware campaign with the decisions that matter for Caribbean utilities, ports and facilities.

  • Twelve questions to start a useful conversation with your operations team.
  • Two investment sequences to help put priorities in the right order.
  • A first-year roadmap to move from exposure to practical action.

Your island’s resilience deserves more than a checklist. Start with a guide built around the realities of your operation.

Your copy. Straight to your inbox.

Enter your name and business email. Mohammed Saad at InnovAKT will send you an automated email with the download link.

By requesting the guide, you ask InnovAKT to email you its download link. We’ll use your details to fulfil this request and arrange a conversation if you choose that option. Privacy Policy.

Form not loading? Open the secure request form.

Why an island is different

One grid, one consequence

There is no interconnection to import from. A control-system event at a power station, a substation or a fuel terminal is an island-wide event, and black start is the recovery plan. Cyber risk has to be stated in those terms before anyone can price it.

Everything depends on everything

Desalination is an electrical load. The port's cranes and the airport's lighting are electrical loads. The hotel runs its own plant until the grid comes back. One dependency chain runs through the whole island, and usually one short list of vendors runs through it too.

The network grew flat, and the vendors never left

Control estates built project by project end up as one segment where everything can reach everything, with remote access opened for a commissioning that finished years ago. It is not negligence. It is what happens when each project is delivered on its own and nobody owns the whole.

IT and OT are the same few people

On most island operators the same small team already carries both. That is not convergence — convergence is a model. What is missing is decision rights: who approves a change on a control system, who owns cyber risk to production, who can grant a vendor access, and who declares an incident.

The money goes to the wrong place

A platform is easy to buy, easy to approve and easy to show a board. The exposure that would actually stop the island is more often an access path nobody has listed, an inventory nobody has, or a restore nobody has tested — and those cost a fraction of what gets spent instead.

Boards, regulators and lenders now ask

Insurers, regulators and the development lenders behind new generation, water and port capacity increasingly want demonstrable resilience rather than a policy document. A program that can be measured is far easier to defend than one that cannot.

The estate, as it is

The network as it grew. The network as it should be.

Two drawings of the same island operator. The first is what twenty years of project-by-project delivery produces. The second is the same equipment with zones, an industrial DMZ and one governed way in — which is a sequence of changes, not a rebuild.

The island control network in two states First state: a single flat segment carrying operator stations, control servers, controllers, cameras, office computers and the enterprise link, with three vendor remote-access tunnels arriving directly onto it. Second state: three zones — enterprise, an industrial demilitarised zone and process control — with the same three vendors arriving through one brokered access gateway, then a single controlled hop down to the process. One segment · everything reachable from everything OEM support Integrator Contractor laptop Operator HMI Control server PLC / RTU Historian CCTV / access Office PCs Enterprise link Three standing routes to the process, none of them logged Enterprise Industrial DMZ Process control OEM support Integrator Contractor laptop Enterprise link Office PCs Brokered accessidentity · approval · record Jump host Historian Operator HMI Control server PLC / RTU CCTV / access Safety system One way in, and it is watched

Every vendor tunnel lands on the same segment as the controllers, so any one of them reaches the process directly. Nothing here is unusual and nothing here was a mistake at the time — it is what a flat estate looks like once you draw it.

Where the budget goes

The same six line items, in two different orders.

On the left, roughly the order these get bought — easiest to approve first. On the right, the order in which they would stop the island. The two are close to inverted, and that inversion is what over-investing in the wrong direction actually looks like on a budget.

    Nothing on this list is a bad thing to own. The question is only what gets funded first, and a platform is far easier to put in front of a board than an access review.

    What we deliver

    Eight capabilities, delivered as one program or entered one at a time.

    Named the way a buyer looks for them. Each is delivered through the InnovAKT engagements behind it, and each can be scoped on its own.

    NIS2 and the Kingdom's plan

    NIS2 does not apply here yet. The comparison is still coming.

    The NCSC's construction plan for a Kingdom-wide Cyber Resilience Network states plainly that the Caribbean Netherlands has no cyber legislation and that NIS2 does not apply, so no operator is legally designated critical today. It then sets out four phases running to 2029 — and the third is a gap analysis comparing Caribbean capability against Netherlands standards.

    Why this is an argument for acting now, not later

    An operator who waits for an obligation will meet the comparison in phase three with whatever it happens to have. An operator who builds to NIS2-equivalent practice voluntarily meets it with evidence, and is in a position to shape what the pillars look like rather than receive them.

    The plan also says something InnovAKT agrees with: what the islands need is technical assistance, personnel capacity, training and exercises — capability, not procurement. That is the same argument we make on this page, and it is how we scope an engagement.

    Four reviews that get you there

    SLA technical and security reviewThe service levels you already hold — with integrators, OEMs, managed service providers and connectivity suppliers — read against what they actually oblige anyone to do when something goes wrong in the plant.
    GRC against recognised standardsIEC 62443, the NIST Cybersecurity Framework and ISO 27001, expressed as a management system your team can operate.
    NIS2 and Cyber Resilience Network readinessA readiness view against NIS2-equivalent practice and the direction the Kingdom's plan is taking, with the gap stated plainly and the sequence to close it.
    Security control effectivenessEvidence that the controls already paid for do what was specified — segmentation that holds, detection that sees, backups that restore a controller, access that expires.

    InnovAKT's role in all four is to review, evidence and advise. The obligation under any standard, regulation or contract stays with you, and nothing in an engagement moves it.

    Source: Building plan for a Cyber Resilience Network, Caribbean annex — NCSC, Netherlands

    IT and OT

    On a small operator, convergence is not the problem. Accountability is.

    The usual convergence conversation assumes two organizations that need to be brought together. On most island operators there are not two organizations. There is one small team, already carrying the enterprise network, the control network and everything attached to both, and already talking to each other every day.

    What is missing is not integration. It is the set of decisions nobody has written down — and each one of them surfaces at the worst possible moment, when a vendor needs access at midnight or an engineer has to decide whether to keep running.

    Settling these five is usually a matter of weeks, costs almost nothing, and changes how every later investment gets prioritized. It is the part of an engagement clients tell us afterwards they should have done first.

    High-voltage substation equipment — the kind of estate an island operator runs
    The decisionWhere it usually sitsWhat a working model looks like
    Approving a change on a control systemWith whoever is doing the workEngineering owns it, security reviews it, and the record survives the person who made it
    Owning cyber risk to productionNobody, or IT by defaultThe operations leader who owns the production target, advised by security
    Granting a vendor remote accessWhoever holds the credentialsRequested by engineering, approved per session, granted through one gateway, logged
    Declaring a cyber incidentUnclear until it happensA named duty role with the authority to declare, and a defined path to the plant manager
    Deciding to stop or continue productionContested in the momentAlways the plant. Security advises on exposure; it never makes a production call

    How we work in the Caribbean

    We have worked with operators in the Dutch Caribbean and understand the operating reality: a handful of people responsible for everything, OEMs six time zones away, and outage windows the whole island notices.

    Our goal is not for you to depend on us. It is to augment your team and leave more capability on the island than we found — so the next cycle is run by your own people, with us available rather than in the middle of it. Building that local skill is part of the engagement, not an afterthought at the end of it.

    Engagements combine on-site work in the islands with remote support from Atlanta, within an hour of local time. The relationship is between InnovAKT and you: we work to an agreed service level, we report security maturity against a baseline you can watch move, and we write for two audiences at once — the engineers who run the plant and the board or ministry that funds it.

    This page is available in English, Dutch and Papiamentu. Engagements are conducted in English, and written material can be prepared in other languages on request.

    Innovate the Future. AKT Today.

    Talk with InnovAKT about your island's operations.

    A senior consultant, your environment, and an honest view of what the first step should be.

    Questions from the islands

    Working in Aruba, Curaçao and Bonaire.

    Does InnovAKT work in Aruba, Curaçao and Bonaire?

    Yes. InnovAKT supports utilities, water producers, fuel terminals, refineries, ports, airports and hotel infrastructure across Aruba, Curaçao, Bonaire and Sint Maarten, working on site in the islands and remotely from its base in Atlanta. Engagements are conducted in English.

    What makes island critical infrastructure different to secure?

    Isolation. There is no neighbouring grid to import from, no second desalination plant down the road, and a spare part is a flight away rather than a drive. An event that would be an inconvenience on a large interconnected system becomes a national one on an island. That changes what resilience has to mean and how recovery has to be designed.

    Which regulations apply to Caribbean operators?

    Operators in the Dutch Caribbean generally work to international practice — IEC 62443 for industrial systems, the NIST Cybersecurity Framework for the program, ISO 27001 where a management system is required — alongside local regulatory and utility obligations and, for organizations connected to Dutch or EU parents, the expectations flowing from NIS2. InnovAKT builds to the operational outcome and maps it to whichever framework the organization must evidence.