Jamaica Gleaner

Cybersecur­ity threat level raised to high

-

THE CYBER Incident Response Team in the national security ministry yesterday raised the island’s cybersecur­ity threat level in relation to government systems to high.

The heightened threat level comes on the heels of a number of weaknesses discovered within the JAMCOVID app and website, which was being used to store critical data regarding travellers and COVID-19 patients in the island.

The website for the Child Protection and Family Services Agency also appeared to have been breached this week and concerns were heightened as the Passport, Immigratio­n and Citizenshi­p Agency’s (PICA) went offline.

“Many GOJ applicatio­ns process data and store results on back-end database servers, where sensitive data may sit, and thus, there is cause for concern. There are many potential attacks that entities may encounter which may threaten to disrupt business but can also lead to unauthoris­ed access to data,” the Cyber Incident Response Team disclosed.

The digital security system used by PICA, which processes some of the most sensitive personal informatio­n on Jamaican citizens, has been strongly defended by National Security Minister Dr Horace Chang.

At a recent Gleaner Editors’ Forum Chang said that “none of the critical associated government points were affected, for example PICA”.

Marsha Grant, PICA business developmen­t director, told The Gleaner that that the site was taken offline by PICA, but did not disclose whether other recent cybersecur­ity events triggered the move. She, however, said that the PICA website was not breached.

Further questions sent to her were not answered up to press time on Friday.

The latest in breach uncovered in the

JAMCOVID system involves quarantine orders, including personal details such as addresses, issued to residents being publicly accessible on the Internet.

Under the law, most recently amended on February 1, data gathered for electronic monitoring “shall be deleted upon the expiration of the [14-day] quarantine”. That provision in the Disaster Risk Management Act would have been in place from as early as June 15, 2020, well after the roll-out of the applicatio­n. The vulnerabil­ity of the servers is believed to have stretched back to this time.

The Major Organised Crime and AntiCorrup­tion Agency yesterday said that its investigat­ors have observed persistent attempts to gain unauthoris­ed access to government systems, adding that measures were being taken to bolster their cyber defence.

Newspapers in English

Newspapers from Jamaica