
Naivety about data security was once forgivable. It is not anymore. The tools that watch us are no longer hidden in spy films. We wear them on our wrists, our faces and in our ears, and we carry them into the rooms where decisions are made.
During the DLP rule the Chinese donated some laptops to the members of parliament, and they were warmly accepted. When I made an enquiry, the assurance from the IT person was that these computers would be wiped, that response caused me to laugh, for that was a taught text book learnt response and not the real truth. Smoke signals and carrier pigeons are safer than messages via the internet, who thinks or advices otherwise is deeply uninformed.
What a treasure trove and jackpot for the Chinese as all that was needed was one laptop logging on to the internet or parliament’s network…Perhaps, intrusion to capture the payroll to ascertain the member of parliament with the lowest net pay to target for a bribe or the voting pattern, may not be concerning to persons conditioned to accept what is presented.
Four Cautionary Cases
The wrist that tells. In 2018, the fitness app Strava published a global heatmap of its users’ runs. Analysts quickly noticed bright outlines in remote parts of Afghanistan, Syria and Djibouti. These were soldiers jogging around military bases whose locations were meant to be secret. No hacker broke in. The data was given away, one morning run at a time. A smartwatch worn by an official records where they sleep, where they work, when their heart races, and which routes they repeat. Patterns are intelligence.
The glasses that remember. In 2024, two Harvard students paired camera-equipped smart glasses with facial recognition and public databases. Within seconds of glancing at strangers, they could pull up names, addresses and relatives. They built it as a warning, and the warning stands. A pair of glasses in a boardroom, a courtroom or a ministry meeting is a camera that nobody thinks to switch off.
The earpiece that listens. Bluetooth earbuds feel harmless, yet researchers keep finding flaws in the chips inside popular headphones. Some of these flaws could let a nearby attacker take over the connection, listen through the microphone, or reach the paired phone. An always-on wireless device near confidential talk is an open door with a polite face.
The code that is no longer enough. Two-factor authentication is still essential, but it is no longer a wall. Phishing kits now sit invisibly between victim and website, capturing both the password and the one-time code as they are typed. Voices and faces can also be forged. In 2024, an employee at the engineering firm Arup in Hong Kong joined a video call with what looked like the company’s CFO and colleagues. Every one of them was a deepfake. About US$25 million was transferred before anyone realised.
Barbados Is Not Exempt
The Queen Elizabeth Hospital has been the target of one of the most concerning attacks on the island. On October 31, 2024, the government’s statistical department suffered a cyber-attack. A regional security summit reports that the entire voters’ list, 5,250 pages, was published on the open internet on December 29, 2021.
A regional report found that in 2023, successful ransomware breaches hit Antigua and Barbuda, The Bahamas, Barbados, Belize, Dominica, Grenada, Guyana, Haiti, Jamaica and Trinidad and Tobago. Its authors concluded that no one in the Caribbean was safe that year. A decade ago, a headline warned that Barbados was not ready for a cyber attack. The question now is whether we have caught up.
What Situational Awareness Demands
- Leave devices at the door. Smartwatches, smart glasses and earbuds should stay outside sensitive meetings.
- Use phishing-resistant sign-in. Hardware security keys or passkeys should protect anyone with access to state, financial or health data.
- Verify money and secrets out of band. Confirm any request by calling back on a known number, however familiar the face or voice.
- Turn off what you don’t use. That means location history, fitness sharing and Bluetooth.
- Train, test and report. Staff should rehearse phishing and deepfake drills. Institutions should disclose breaches rather than bury them.
Knowledge and data are now currencies, and like any currency they can be stolen. Power is not patient, and it rarely announces itself. Opportunities, reputations and national advantage are most often lost in silence, through a device no one questioned. Caution is not paranoia. It is the price of living in a connected world.







The blogmaster invites you to join the discussion.