BitDepthThe flagellation of TSTT

The flagellation of TSTT

Above: Fresco detail from Milan’s Certosa di Garegnano. Image by clodio/DepositPhotos

BitDepth#1433 for November 30, 2023

Now that the furore, at least in the media, about the TSTT hack has largely subsided, perhaps it’s time to think about why the incident loomed so large in the public consciousness.

It can’t be just the fact of the data breach. There were breaches before and breaches right after that didn’t raise that level of alarm.

Eighteen days after the story broke, TSTT CEO Lisa Agard was reported, in the words of a company press release to have “departed.”

Placed in an acting role is Kent Western, abruptly promoted from the post of General Manager, Customer Experience and Marketing, who must now make sense of the situation.

What went wrong, or was so dramatically different from previous data breaches?

The data went public

TSTT chose to downplay the significance of the breach by declaring the 6GB data haul to be insignificant compared to the terabytes of data it manages daily.

But the size of the data exfiltrated in the breach made accessing and working with it possible for even casual users.

Unfortunately, the stolen files were not encrypted. Encryption makes data unreadable without a password and protects with varying levels of complexity.

The size of some of the exfiltrated files and nature of the data encoding, designed to be read by an Oracle database, meant that it was impossible to review the largest files in their entirety using commonly available tools, but there was enough there to send ordinary citizens into a tizzic.

The small size of the files also allowed them to be widely distributed after they eventually were downloaded from the dark web and posted to open internet file sharing sites and that brought further inspection, some of it admittedly both hysterical and ill-advised.

The departed: TSTT’s former CEO, Lisa Agard.

The communication was a hot mess

Even in her final public communication in a full page press statement, TSTT’s CEO seemed to be blaming the poor messaging on everyone except herself.

It’s hard to imagine Agard, a lawyer, allowing any statement from the company to be sent if it did not have her unequivocal approval and what she approved was dense with legal caveats, evasiveness and misdirection.

The releases on October 30 and November 05 were not communication with anxious customers. They were a clumsy attempt to change the conversation, but nobody had time for that.

When news broke just seven days later that a 2021 data breach of Digicel Group data had been found by Jamaican cybersecurity investigators, two things stopped that news from commanding headlines.

Digicel could point to a press release disclosing what had happened days after the data went live and at 164.55GB, it was impenetrably encoded for distribution. The file was archived on the dark web in 337 segments, each 500MB in size.

All of the archive segments had to be downloaded and then reassembled for access. A daunting task at best.

Misunderstanding the stakeholders

TSTT’s communications during the heat of the incident first denied any impact for its customers, then sought to downplay potential exposure.

While the mass release of the personally identifiable information (PII) of hundreds of thousands of customers was troubling enough, the company appeared to forget that the 51 per cent share held by the government is actually being held on behalf of the 1.4 million citizens of Trinidad and Tobago.

Everyone had a stake in this.

Multinational companies like the Irish-owned Digicel and the US-owned Liberty Global (Flow, Columbus) have substantial outposts in the Caribbean, but TSTT’S navel string is buried here.

So customers were disappointed, citizens were uneasy and trust in the company was unnecessarily shaken.

It was worse than an own goal. The TSTT team just kept on firing shots at their nonplussed goalie. It couldn’t have been a good week to be Khamal Georges.

What is TSTT?

TSTT CEO (ag) Kent Western

The Public Utilities Minister declared himself pleased with Kent Western after they met last week, declaring that the ministry and the telecommunications company were now on “the same page.”

The minister seems to think TSTT is another state company over which he needs to exercise greater control. Given that the other state companies that he has dominion over generate staggering losses that doesn’t seem to be a positive development.

That’s probably not good news for anyone. TSTT is supposed to be a business, but nobody is interested in the dormant 49 per cent shareholding held by Liberty Global.

TSTT’s inability to explain itself over a fortnight of media scrutiny does not speak of a company operating with clear directives or oversight.

Implying that Lisa Agard’s departure heralds a new day is misleading and more state intervention is unlikely to improve that situation.

Samsung launches Solve for Tomorrow 2026

Samsung launches Solve for Tomorrow 2026

The programme has expanded its regional reach to 14 countries, welcoming Jamaica to the group of participating markets.
Read More
No more fire in these wires

No more fire in these wires

FireWire effectively died with MacOS 26 Tahoe, when Apple removed the drivers that enabled the OS-level connection to its operating system.
Read More
New theme, who dis?

New theme, who dis?

The site may look pretty much the same on the user side of things, but getting there has been different for every theme change
Read More
Site maintenance and upgrade in progress…

Site maintenance and upgrade in progress…

Making a UI change while a website is running is like changing a wheel on a car while it's moving.
Read More
Visa partners with OpenAI for the next generation of AI commerce

Visa partners with OpenAI for the next generation of AI commerce

Visa’s payment capabilities will be integrated into OpenAI experiences giving developers and merchants a streamlined way to accept Visa payments initiated by agents.
Read More
Privicy introduces Assura for DPO compliance

Privicy introduces Assura for DPO compliance

Build a complete record of processing activities using a structured 5-step wizard.
Read More
What the heck is chip binning?

What the heck is chip binning?

Instead of manufacturing multiple versions of a processor with different numbers of active cores, manufacturers create one master processor and then test the yields.
Read More
Two Hats, One Breach

Two Hats, One Breach

When an incident is discovered, retain a different provider to conduct the forensic investigation — one with no authorship of the compromised environment.
Read More
New MoF based phishing scheme in play

New MoF based phishing scheme in play

A new phishing scheme is masquerading as official communcation from the Ministry of Finance
Read More
Solving the region’s journalism problem

Solving the region’s journalism problem

There's formulaic approach to the content that we produce that sometimes totally denies or is ignorant of audience interest.
Read More
When “It wasn’t a breach” actually was

When “It wasn’t a breach” actually was

Breaches go unreported because IT says it is not a breach and no one in the room can push back with confidence.
Read More
Tambini to journalists: “Keep doing what you’re doing”

Tambini to journalists: “Keep doing what you’re doing”

There are lots of international standards to support that idea of the state supporting the media, but that support is often abused, so it has to be based on real...
Read More
How do we unfetter journalism from the shackles of business?

How do we unfetter journalism from the shackles of business?

Journalism must dissect information, deepen the understanding of it and bring clarity to the news consumer.
Read More
Samsung launches Solve for Tomorrow 2026 Samsung launches Solve for Tomorrow 2026
No more fire in these wires No more fire in these wires
New theme, who dis? New theme, who dis?
Site maintenance and upgrade in progress… Site maintenance and upgrade in progress…
Visa partners with OpenAI for the next generation of AI commerce Visa partners with OpenAI for the...
Privicy introduces Assura for DPO compliance Privicy introduces Assura for DPO compliance
What the heck is chip binning? What the heck is chip binning?
Two Hats, One Breach Two Hats, One Breach
New MoF based phishing scheme in play New MoF based phishing scheme in...
Solving the region’s journalism problem Solving the region’s journalism problem
When “It wasn’t a breach” actually was When “It wasn’t a breach” actually...
Tambini to journalists: “Keep doing what you’re doing” Tambini to journalists: “Keep doing what...
How do we unfetter journalism from the shackles of business? How do we unfetter journalism from...

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Possible UI Glitch. Click top right corner to dismiss 👉

Get Connected!

A once weekly email notification of new stories on TechNewsTT.

Just that. No spam.

RELATED POSTS