Log In

Reset Password

Don’t let the audit trail go cold

Businessmen protecting personal data on laptop

Dear Sir,

The long-awaited, 42-page joint select committee report on the September 2023 government systems cyberattack was finally released to the public on Friday. Three years worth of reviews, discussions, fact finding, revelations and recommendations and yes, you guessed it, a conclusion that further investigations are required.

What did we learn from this report? Here is my brief synopsis but I recommend that you read the report for yourself:

During the period 2015-2022 there was increasing reliance by the Government on information technology and as a result, mitigating the associated increased risk of system disruptions became a priority.

In August, 2022, the Government entered into an untendered contract with a Canadian cybersecurity consultant — Cyberdine. This 16-month (total) contract ended in January 2023, four months after the cyber incident. The company was paid approximately $420,000 during the period.

We now know that in May 2023, four months before the actual data systems “hack”, Cyberdine’s assessment of the Government's cyber-risk was “critical”.

We know that between May and September 2023, while the consultant’s recommendations to reinforce data systems security were under way, the upgrades were not being given the urgency/support which the already identified critical risk demanded.

We know that the cyberattacker had infiltrated the government data systems at least ten days before actually being detected, during which time access to the system back-ups was removed, enabling the criminals to demand the ransom.

We know verified sources have confirmed that our personal data was compromised.

While the Government has never confirmed or denied that a ransom took place, we know from this report that all available indicators suggest that a ransom demand was made and that a ransom or ransom-related payment may have been “effected”.

We know that there were two expenditure amounts totalling approximately $4.415 million in the Budget book covering this period: $3.092 million was listed under line item “Head 10, Ministry of Finance HQ” and $1.323 million for “Head 43, Information and Digital Technologies/Cabinet Office”, both of which were allocated to this 2023 cyber incident. The JSC neither confirms nor denies that this expenditure was in connection with a ransom demand, but stated that a detailed financial audit/trail on this (now almost three years old) expenditure should be conducted by the bipartisan Public Accounts Committee or another competent oversight body.

If we look at the government financials for the Consolidated Fund for the year ending March 2024, (covering the cyberattack period), the expenditure numbers for the whole Ministry of Finance has some quite surprising fluctuations. That ministry’s total annual budget was estimated at $236,372,000. The actual spending number was $362,626,546. That’s 53 per cent over budget. If we look at the specific line item “Head 10”, which is just the Ministry of Finance HQ: Spending Estimate = $6,790,000. Actual spending = $15,108,692. That’s 122 per cent over budget. I wonder what the “paper trail” shows for that expense. Maybe the PAC needs to examine that in some detail.

It is disappointing to me that during the research period, the committee did not delve further into the reasons for $4.4 million expenditure linked to the 2023 cyber incident because it is well known that the longer an unidentified monetary transaction sits without clarification, the colder an audit trail will get.

Our auditor-general tells us this every year and has repeatedly warned that extensive backlogs in financial reporting and chronic difficulties in reconciling public expenditures, severely heighten the risk of fraud.

When transactions are inadequately documented and verified in a timely manner, opportunities for forgery, collusion and the misappropriation of government assets are significantly increased.

Now we wait for the PAC — or other oversight body — to do a forensic audit and report back to us. Given how long it has taken for the just-released report on the 2023 Covid travel authorisation data, you can be sure that it may be years before we get this new audit report. I hope I am proved wrong.

This JSC report has a very long list of valuable recommendations going forward to reduce the risk/ramifications of future cyber incidents; too many to list here. There is one item, however, which stands out to me: the committee emphasised that the Government must treat cybersecurity as critical national infrastructure. There is that tired and worn-out word again — “infrastructure” — which of course includes our pothole-riddled roads, our bridges held together by rust, our sputtering waste facility on borrowed time, an acute-care hospital with ER patients “boarding” in hallways, our public education system in shambles and rising social issues, just to name a few.

So, yes, cybersecurity needs to be added to the list of our essential infrastructure with a dedicated, forward-evolving “maintenance” plan, which is mandatory, just like our debt interest payments, which are non-negotiable.

Furthermore, the Government needs to start cutting all fluffy, discretionary spending, some of which is clearly a government want rather than a people’s need. Ministerial global jaunts, Southlands Park commercialisation and Caricom full membership immediately come to mind.

Government policymaking priorities must be re-evaluated and shrunk down to those which are critical to the lives of everyday Bermudians, who are barely getting by and who continue to wait for the Government to fulfil what are now nine-year-old promises. Judging by our now almost zero unemployment figure, it is obvious that some Bermudians just gave up and left the island.

BEVERLEY CONNELL

Pembroke

Royal Gazette has implemented platform upgrades, requiring users to utilize their Royal Gazette Account Login to comment on Disqus for enhanced security. To create an account, click here.

You must be Registered or to post comment or to vote.

Published July 22, 2026 at 7:22 am (Updated July 22, 2026 at 8:05 am)

Don’t let the audit trail go cold

Users agree to adhere to our Online User Conduct for commenting and user who violate the Terms of Service will be banned.