# Itaca Technologies > Itaca Technologies LLC is a technology and engineering firm working out of Florida and Port of Spain since 2011. It helps owners and directors understand, design, and build the infrastructure, cloud, security, and software their businesses run on. The site is published in English (https://itacatech.com/en/) and Spanish (https://itacatech.com/es/). ## English > Itaca helps owners and directors understand, design, and build infrastructure, cloud, security, and software their business runs on. Florida and Port of Spain. ### Key pages - [Home](https://itacatech.com/en/) - [Resources: articles, case studies and guides](https://itacatech.com/en/resources/) - [Contact](https://itacatech.com/en/contact/) - [Careers](https://itacatech.com/en/careers/) - [For AI assistants](https://itacatech.com/en/about-for-ai/) ### Services - [AI readiness and applied AI](https://itacatech.com/en/services/applied-ai/): Apply AI where process, data, access, and ownership are clear enough. - [Architecture roadmap](https://itacatech.com/en/services/architecture-roadmap/): Turn business needs into a technical sequence. - [Cloud and infrastructure](https://itacatech.com/en/services/cloud-infrastructure/): Cloud, servers, networks, backup, recovery, and the order in which a migration happens. - [Custom software](https://itacatech.com/en/services/custom-software/): Internal platforms, portals, and workflows when the market does not solve the problem. - [Cybersecurity and secure access](https://itacatech.com/en/services/cybersecurity/): Controls that make security operational, not just subscribed to. - [Identity and devices](https://itacatech.com/en/services/identity-devices/): IAM, SSO, MDM, password management, and access conditions. - [Long-term advisory](https://itacatech.com/en/services/long-term-advisory/): Keep providing technical judgment after delivery. - [Systems integration](https://itacatech.com/en/services/systems-integration/): Make the tools the business already pays for work together. - [Technology diagnostic](https://itacatech.com/en/technology-diagnostic/): Understand the current state before recommending a path. ### How the work runs - [Understand](https://itacatech.com/en/how-we-work/understand/): Every engagement starts here, because nothing else is safe to decide first. - [Design](https://itacatech.com/en/how-we-work/design/): The roadmap comes before the tool, because the order decides what the work costs. - [Implement](https://itacatech.com/en/how-we-work/implement/): We own the build, and the operation keeps running while the ground changes. - [Stay](https://itacatech.com/en/how-we-work/stay/): Delivery is where most technology relationships end. It is where the real life of a system begins. ### Industries - [Financial services & real estate](https://itacatech.com/en/industries/financial-services/): Closings, payments, and client records cross CRM, document management, e-signature, email, and wire instructions. - [Healthcare](https://itacatech.com/en/industries/healthcare/): EHR, labs, imaging, billing, portals, and devices mix clinical and business architecture. - [Aviation, aerospace & defense](https://itacatech.com/en/industries/aviation-aerospace-defense/): ERP/MRP, CAD, quality, and controlled technical data that must cross supplier boundaries without unlimited access. - [Logistics, ports & trade](https://itacatech.com/en/industries/logistics-ports-trade/): WMS, TMS, EDI, customs, inventory, and fleets synchronized across organizations on time-sensitive deliveries. - [Professional services](https://itacatech.com/en/industries/professional-services/): Email, document management, and case or tax systems holding privileged data, with nobody owning the architecture. - [Energy & industrial contractors](https://itacatech.com/en/industries/energy-industrial/): OT and plant systems, contractor access, maintenance records, and HSE evidence connecting operational and corporate risk. - [Manufacturing & distribution](https://itacatech.com/en/industries/manufacturing-distribution/): ERP/MRP, inventory, quality, purchasing, and customs held together by integrations and connectivity. ### Resources - [When the phone company goes down: continuity lessons from October 2023](https://itacatech.com/en/resources/blog/continuity-lessons-tstt/): The October 2023 ransomware attack on TSTT, the national telecommunications provider of Trinidad and Tobago, is usually filed as a cybersecurity story, but for most businesses on the islands it was a lesson about dependency rather than about being attacked: their own systems were fine, and what failed was the link between them and their customers, their bank, their cloud software and their card terminals. Continuity has two halves and most plans answer only one. The first half is your own recovery, which comes down to three questions almost nobody can answer (when did someone last restore from the backups, how long did that restore take measured with a clock, and is at least one copy somewhere an attacker cannot reach), plus a plan the people who would execute it at two in the morning have actually seen. The second half is a dependency map that fits on one page: for each thing you do not control, what stops when it is gone, how long that can be tolerated, and what the fallback is and whether anyone knows how to run it. Most of continuity is decisions, and decisions are cheap; the rehearsal that surfaces them fits in an afternoon. - [“Not yet” is a legitimate answer: an honest AI readiness check for small business](https://itacatech.com/en/resources/blog/is-your-business-ready-for-ai/): AI readiness in a small business has nothing to do with ambition and everything to do with whether its data is in order, which comes down to three questions asked before any model, vendor or licence is discussed: where does your data live, who owns it, and can you trust it. If a meaningful share of what the business knows sits in inboxes and in people's heads, a model will learn from the part that was easy to reach and be confidently wrong about the rest; if three systems disagree about the same customer, a tool trained on all three will take a side at random; and if the honest answer to “would you change prices today based on this report” is “let me look at it first”, that is the data quality problem described in the owner's own words. When any answer is shaky the right response is “not yet”, which is a sequence rather than a refusal: name the system of record for each kind of data, give each kind an owner and a correction rule, close the two or three gaps that matter, and only then pick a first project that is small, measurable and reversible. - [Replacing a 35-year-old ERP without stopping the orders](https://itacatech.com/en/resources/case-studies/footwear-wholesale-legacy-erp-replacement/): A US footwear wholesaler ran its entire operation (orders, EDI, production, two warehouses, allocation, invoicing and factored collections) on a FoxPro ERP written around 1990, with more than 500 programs and over 600 tables per company. Rather than buy a replacement, we mapped 35 years of business rules out of the code and out of people's heads, then built a private multi-company operating layer for footwear wholesale with NetSuite underneath as the system of record. Before adding anything to the warehouse system a previous vendor had abandoned, we audited it and found returns modelled outside NetSuite's native transactions, batch scripts that broke at around 50 transactions, queries built by string concatenation, and integration roles with far more permission than they needed; we priced the rebuild as a versioned, event-driven SuiteApp and let the client decide with the numbers in front of them. The rollout ran brand by brand while the legacy system kept running, and the migration has not stopped an order. - [From paper task sheets to verified, billable work across seven distribution centers](https://itacatech.com/en/resources/case-studies/facility-services-paper-to-verified-work/): A cleaning and maintenance contractor won a national retailer's distribution centers and, within about a year, was running seven sites in four states with tasks recorded on paper, special projects invoiced from thin spreadsheets, and one person, the chief operating officer, supervising and billing everything personally. We followed a task from the floor to the invoice and found the eight answers every job needs before it can be billed with confidence, plus a hard constraint: whatever replaced the paper had to be usable by someone who has never used business software. We evaluated four existing platforms for time and attendance, field teams, accounting and ERP against the real process; two solved a piece well, none connected work, evidence, approval and invoice for a multi-site operation of this shape without adding a second set of manual steps. So we kept the accounting package and payroll where they were and built the missing control layer: a work order that carries the eight answers and cannot be billed until it is approved, four roles, reports by center and person, a service desk, and the devices, connectivity and corporate identity the sites lacked. - [Rates, sign-up and tracking without a phone call: a freight line between Florida and the Caribbean](https://itacatech.com/en/resources/case-studies/freight-platform-florida-caribbean/): A freight consolidator shipping from Miami to Trinidad, Tobago and Barbados had a 2018 website that described the service but did not run it, while customers on three islands increasingly expected to quote, open an account, pay and track without calling. We rebuilt the site around the questions customers actually ask at each step of a package's journey (received in Miami, consolidated, flown or shipped to Port of Spain, Tobago or Barbados, cleared, handed over), with one rate table feeding the marketing pages, the calculator and customer notices, and with hosting, DNS and certificates under the client's own accounts and documented. The platform relaunched in 2024 and has been in production since. In November 2024 it went down, and restoring from backup did not bring it back, because the fault was in how the application had been built and shipped rather than in the data; we found it, fixed it, and changed the deployment so the same failure cannot recur. Eight years on, the client talks to the same people who built the first site. - [Identity, devices and departures: putting a tax firm's security in writing and in practice](https://itacatech.com/en/resources/case-studies/tax-firm-identity-devices-departures/): A bilingual tax and accounting practice in South Florida had grown into a team with laptops, cloud accounts and client files spread across a Microsoft tenant, Google Drive and shared passwords, with an IT relationship that answered the phone but did not own the picture. Nobody could say in a day which devices held client data, which accounts were still active for people who had left, or which security settings were actually applied rather than intended. We started with the deliverable most firms skip, an inventory of every user, device and application that touches client data, plus both offices and their networks drawn as diagrams the partners can read, and then wrote down what should be true: one identity per person across Microsoft 365 with licences by role and multi-factor authentication where client records move, a catalogue of twenty device policies of which seven were selected, and arrivals and departures as a single procedure. The seven policies were tested on a virtual machine, piloted on a small group and applied to the whole fleet, each documented with its purpose and configuration. The firm can now produce, on request, the devices and who holds them, the accounts and their status, the policies in force and the evidence that they are applied. - [One directory for a European operation spread across countries](https://itacatech.com/en/resources/case-studies/energy-group-hybrid-identity-europe/): The European arm of an international energy and infrastructure group had grown quickly into offices in several countries, with teams organised by country and department and people who travel between them, running on an on-premises directory synchronised to the cloud plus Microsoft 365, VPN, endpoint protection, backup and a digital business-card service. Each piece was fine; together they were the problem, because a single arrival or departure crossed all of them in an order that existed only in whoever happened to do it. We did not start with a tool: we wrote down how the organisation is actually structured, then designed how that structure should appear in the directory, with organisational units for countries, cities and departments, groups that grant access, a readable naming convention, the rule that every user belongs at minimum to a country, a department and a VPN group, and group policy inheritance, filtering and explicit exceptions. One lifecycle procedure now covers people and devices in nine steps from directory to cloud to backup to endpoint, each with a check. We also built an asset and service inventory in the service desk's own asset module and ran four workstreams under one team, so the operation kept working while it changed underneath. - [The evidence file: what a Trinidad and Tobago business should be able to show](https://itacatech.com/en/resources/guides/evidence-file-tt/): Most summaries say Trinidad and Tobago's Data Protection Act 2011 is “not yet in force”, and that imprecision is expensive: the Act is partially proclaimed, with Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 in force since 6 January 2012 under Legal Notice No. 2 of 2012, and section 42(a) and (b) since 23 August 2021 under Legal Notice No. 220 of 2021. What is already in force includes the general privacy principles and the framework of the Information Commissioner's office. For a business handling personal data (client files, patient records, employee data) the defensible position is to operate as if the remaining sections were coming, which in practice means mapping where personal data lives and controlling who reaches it, and being able to show both; those two records are the first pages of the evidence file. For financial institutions the pressure is more immediate, because the Miscellaneous Provisions (FATF Compliance) Act 2025 has been in full force since 17 November 2025 and institutions are being asked for evidence rather than intentions. - [The first 24 hours: an incident checklist for Florida businesses](https://itacatech.com/en/resources/guides/first-24-hours/): When a Florida business discovers a compromised inbox, a diverted payment or encrypted files, two clocks may already be running: Florida's data protection statute gives 30 days from determining a breach to notify affected residents, and a non-bank financial institution (a mortgage broker, a title company, an advisory firm) has been required since May 2024 to report certain incidents to the FTC under the Safeguards Rule. The first day decides most of what follows, and it asks four things in order: cut access without destroying evidence by changing credentials, closing sessions and preserving the logs; notify your insurer before changing anything they might later call material, and bring in counsel early, because both clocks are legal questions rather than technical ones; preserve before anyone restores anything; and name one person, out loud, who leads, meaning they decide hour by hour what is cut, what is kept and who is told, writing each decision down with the time. The most expensive mistake is restoring before preserving: it feels like recovery and destroys the record that decides what you know, what you must notify, and what the insurer covers. ## Español > Itaca ayuda a dueños y directores a entender, diseñar y construir la infraestructura, nube, seguridad y software de su empresa. Florida y Puerto España. ### Páginas clave - [Inicio](https://itacatech.com/es/) - [Recursos: artículos, casos de cliente y guías](https://itacatech.com/es/resources/) - [Contacto](https://itacatech.com/es/contact/) - [Carreras](https://itacatech.com/es/careers/) - [Para asistentes de IA](https://itacatech.com/es/about-for-ai/) ### Servicios - [Asesoría a largo plazo](https://itacatech.com/es/services/long-term-advisory/): Seguir aportando criterio técnico después de la entrega. - [Ciberseguridad y acceso seguro](https://itacatech.com/es/services/cybersecurity/): Controles que convierten la seguridad en una práctica operativa, no en una suscripción más. - [Diagnóstico tecnológico](https://itacatech.com/es/technology-diagnostic/): Entender el estado actual antes de recomendar un camino. - [Hoja de ruta de arquitectura](https://itacatech.com/es/services/architecture-roadmap/): Convertir las necesidades del negocio en una secuencia técnica. - [Identidad y dispositivos](https://itacatech.com/es/services/identity-devices/): IAM, SSO, MDM, gestión de contraseñas y condiciones de acceso. - [Integración de sistemas](https://itacatech.com/es/services/systems-integration/): Hacer que las herramientas que la empresa ya paga trabajen juntas. - [Nube e infraestructura](https://itacatech.com/es/services/cloud-infrastructure/): Nube, servidores, redes, copias de seguridad, recuperación y el orden en que ocurre una migración. - [Preparación para IA e IA aplicada](https://itacatech.com/es/services/applied-ai/): Aplicar IA cuando los procesos, los datos, los accesos y las responsabilidades están suficientemente claros. - [Software a medida](https://itacatech.com/es/services/custom-software/): Plataformas internas, portales y flujos de trabajo cuando el mercado no resuelve el problema. ### Cómo se hace el trabajo - [Entender](https://itacatech.com/es/how-we-work/understand/): Todo proyecto empieza aquí, porque nada más es seguro decidir antes. - [Diseñar](https://itacatech.com/es/how-we-work/design/): La hoja de ruta va antes que la herramienta, porque el orden decide lo que cuesta el trabajo. - [Implementar](https://itacatech.com/es/how-we-work/implement/): Asumimos la construcción, y la operación sigue funcionando mientras el suelo cambia. - [Seguir](https://itacatech.com/es/how-we-work/stay/): La entrega es donde terminan la mayoría de las relaciones tecnológicas. Es donde empieza la vida real de un sistema. ### Sectores - [Servicios financieros e inmobiliario](https://itacatech.com/es/industries/financial-services/): Cierres, pagos y expedientes de clientes cruzan CRM, gestión documental, firma electrónica, correo e instrucciones de transferencia. - [Salud](https://itacatech.com/es/industries/healthcare/): EHR, laboratorios, imagen, facturación, portales y dispositivos mezclan arquitectura clínica y de negocio. - [Aviación, aeroespacial y defensa](https://itacatech.com/es/industries/aviation-aerospace-defense/): ERP/MRP, CAD, calidad e información técnica controlada que debe cruzar fronteras de proveedores sin acceso ilimitado. - [Logística, puertos y comercio exterior](https://itacatech.com/es/industries/logistics-ports-trade/): WMS, TMS, EDI, aduanas, inventario y flotas sincronizados entre organizaciones con entregas sensibles al tiempo. - [Servicios profesionales regulados](https://itacatech.com/es/industries/professional-services/): Correo, gestión documental y sistemas de expedientes o fiscales con datos privilegiados, sin que nadie sea dueño de la arquitectura. - [Energía y contratistas industriales](https://itacatech.com/es/industries/energy-industrial/): Sistemas OT y de planta, acceso de contratistas, registros de mantenimiento y evidencia HSE que conectan riesgo operativo y corporativo. - [Manufactura y distribución](https://itacatech.com/es/industries/manufacturing-distribution/): ERP/MRP, inventario, calidad, compras y aduanas sostenidos por integraciones y conectividad. ### Recursos - [Cuando cae la compañía telefónica: lecciones de continuidad de octubre de 2023](https://itacatech.com/es/resources/blog/continuity-lessons-tstt/): El ataque de ransomware a TSTT, la compañía nacional de telecomunicaciones de Trinidad y Tobago, en octubre de 2023 suele archivarse como una historia de ciberseguridad, pero para la mayoría de las empresas del país fue una lección sobre dependencia y no sobre ser atacado: sus propios sistemas estaban bien, y lo que falló fue el enlace entre ellas y sus clientes, su banco, su software en la nube y sus terminales de tarjeta. La continuidad tiene dos mitades y la mayoría de los planes responde solo a una. La primera es la recuperación propia, que se reduce a tres preguntas que casi nadie sabe responder (cuándo restauró alguien por última vez a partir de las copias, cuánto tardó esa restauración medida con reloj y si hay al menos una copia donde un atacante no pueda llegar), más un plan que las personas que tendrían que ejecutarlo a las dos de la mañana hayan visto de verdad. La segunda es un mapa de dependencias que cabe en una página: para cada cosa que no controlas, qué se para cuando falta, cuánto tiempo se aguanta, y cuál es la alternativa y si alguien sabe ponerla en marcha. La continuidad es sobre todo decisiones, y las decisiones son baratas; el ensayo que las saca a la luz cabe en una tarde. - [«Todavía no» es una respuesta legítima: un chequeo honesto de preparación para la IA](https://itacatech.com/es/resources/blog/is-your-business-ready-for-ai/): Que una pequeña empresa esté preparada para la IA no tiene que ver con la ambición y sí con que sus datos estén en orden, lo que se reduce a tres preguntas que se hacen antes de hablar de ningún modelo, proveedor o licencia: dónde viven tus datos, quién es su dueño y si son de fiar. Si una parte significativa de lo que sabe la empresa está en bandejas de entrada y en cabezas, el modelo aprenderá de la parte fácil de alcanzar y se equivocará con total seguridad en el resto; si tres sistemas discrepan sobre el mismo cliente, una herramienta entrenada con los tres tomará partido al azar; y si la respuesta honesta a «¿cambiarías hoy los precios basándote en este informe?» es «déjame mirarlo antes», ese es el problema de calidad de datos descrito con las palabras del propio dueño. Cuando alguna respuesta tiembla, la respuesta correcta es «todavía no», que es una secuencia y no una negativa: nombrar el sistema de registro de cada tipo de dato, dar a cada tipo un dueño y una regla de corrección, cerrar los dos o tres huecos que importan y solo entonces elegir un primer proyecto pequeño, medible y reversible. - [Sustituir un ERP de 35 años sin parar los pedidos](https://itacatech.com/es/resources/case-studies/footwear-wholesale-legacy-erp-replacement/): Un mayorista de calzado estadounidense llevaba toda su operación (pedidos, EDI, producción, dos almacenes, asignación, facturación y cobros a través de un factor) sobre un ERP en FoxPro escrito hacia 1990, con más de 500 programas y más de 600 tablas por compañía. En lugar de comprar un sustituto, extrajimos 35 años de reglas de negocio del código y de la cabeza de la gente y construimos después una capa operativa privada y multiempresa para el mayorista de calzado, con NetSuite debajo como sistema de registro. Antes de añadir nada al sistema de almacén que un proveedor anterior había abandonado, lo auditamos y encontramos devoluciones modeladas fuera de las transacciones nativas de NetSuite, scripts por lotes que se rompían con unas 50 transacciones, consultas construidas concatenando texto y roles de integración con muchos más permisos de los necesarios; pusimos precio a la reconstrucción como una SuiteApp versionada y orientada a eventos y dejamos que el cliente decidiera con los números delante. El despliegue fue marca a marca mientras el sistema heredado seguía funcionando, y la migración no ha parado un pedido. - [De partes en papel a trabajo verificado y facturable en siete centros de distribución](https://itacatech.com/es/resources/case-studies/facility-services-paper-to-verified-work/): Un contratista de limpieza y mantenimiento ganó los centros de distribución de una gran cadena minorista y, en cosa de un año, operaba siete centros en cuatro estados con las tareas anotadas en papel, los proyectos especiales facturados desde hojas de cálculo escuetas y una sola persona, la directora de operaciones, supervisando y facturando todo personalmente. Seguimos una tarea desde el suelo hasta la factura y encontramos las ocho respuestas que necesita cada trabajo antes de poder facturarse con seguridad, más una restricción dura: lo que sustituyera al papel tenía que poder usarlo alguien que nunca ha usado software de empresa. Evaluamos cuatro plataformas del mercado, de control horario, equipos de campo, contabilidad y ERP, frente al proceso real; dos resolvían bien una parte, ninguna conectaba trabajo, evidencia, aprobación y factura para una operación multisede de esta forma sin añadir una segunda capa de pasos manuales. Así que dejamos la contabilidad y la nómina donde estaban y construimos la capa de control que faltaba: una orden de trabajo que lleva las ocho respuestas y no se factura hasta que se aprueba, cuatro roles, informes por centro y persona, un service desk, y los equipos, la conectividad y la identidad corporativa que los centros no tenían. - [Tarifas, alta y seguimiento sin una llamada: una línea de carga entre Florida y el Caribe](https://itacatech.com/es/resources/case-studies/freight-platform-florida-caribbean/): Un consolidador de carga que envía desde Miami a Trinidad, Tobago y Barbados tenía una web de 2018 que describía el servicio pero no lo operaba, mientras los clientes de tres islas esperaban cada vez más cotizar, abrir una cuenta, pagar y seguir el envío sin llamar. Reconstruimos la web alrededor de las preguntas que los clientes hacen de verdad en cada paso del recorrido de un paquete (se recibe en Miami, se consolida, vuela o navega a Puerto España, Tobago o Barbados, pasa aduana, se entrega), con una sola tabla de tarifas que alimenta las páginas comerciales, la calculadora y los avisos a clientes, y con alojamiento, DNS y certificados en cuentas del propio cliente y documentados. La plataforma se relanzó en 2024 y está en producción desde entonces. En noviembre de 2024 se cayó, y restaurar la copia de seguridad no la devolvió, porque el fallo estaba en cómo se había construido y desplegado la aplicación y no en los datos; lo encontramos, lo corregimos y cambiamos el despliegue para que el mismo fallo no pueda repetirse. Ocho años después, el cliente habla con las mismas personas que hicieron la primera web. - [Identidad, dispositivos y salidas: la seguridad de una firma fiscal, por escrito y en la práctica](https://itacatech.com/es/resources/case-studies/tax-firm-identity-devices-departures/): Una firma bilingüe de impuestos y contabilidad del sur de Florida había crecido hasta tener un equipo con portátiles, cuentas en la nube y expedientes de clientes repartidos entre un tenant de Microsoft, Google Drive y contraseñas compartidas, y una relación de TI que atendía el teléfono pero no era dueña del conjunto. Nadie podía decir en un día qué equipos guardaban datos de clientes, qué cuentas seguían activas de personas que ya no estaban o qué ajustes de seguridad estaban aplicados de verdad y no solo previstos. Empezamos por el entregable que casi todas las firmas se saltan, un inventario de cada usuario, equipo y aplicación que toca datos de clientes, más las dos oficinas y sus redes dibujadas en diagramas que los socios pueden leer, y después escribimos qué debía ser cierto: una identidad por persona en Microsoft 365, con licencias por rol y autenticación en dos pasos donde se mueven expedientes de clientes, un catálogo de veinte políticas de dispositivo de las que se eligieron siete, y altas y bajas como un solo procedimiento. Las siete políticas se probaron en una máquina virtual, se pilotaron en un grupo reducido y se aplicaron a toda la flota, cada una documentada con su propósito y su configuración. La firma puede enseñar ahora, cuando se lo piden, los equipos y quién los tiene, las cuentas y su estado, las políticas en vigor y la evidencia de que están aplicadas. - [Un solo directorio para una operación europea repartida entre países](https://itacatech.com/es/resources/case-studies/energy-group-hybrid-identity-europe/): La filial europea de un grupo internacional de energía e infraestructuras había crecido deprisa hasta tener oficinas en varios países, con equipos organizados por país y departamento y gente que viaja entre ellos, sobre un directorio local sincronizado con la nube más Microsoft 365, VPN, protección de equipos, copia de seguridad y un servicio de tarjetas de visita digitales. Cada pieza estaba bien; juntas eran el problema, porque una sola alta o baja las cruzaba todas en un orden que solo existía en la cabeza de quien la hacía. No empezamos por una herramienta: escribimos cómo está estructurada de verdad la organización y después diseñamos cómo debía verse esa estructura en el directorio, con unidades organizativas para países, ciudades y departamentos, grupos que dan acceso, una nomenclatura legible, la regla de que cada usuario pertenece como mínimo a un país, un departamento y un grupo de VPN, y políticas de grupo con herencia, filtrado y excepciones explícitas. Un solo procedimiento de ciclo de vida cubre ahora personas y equipos en nueve pasos, del directorio a la nube, la copia de seguridad y el equipo, cada uno con su comprobación. Montamos además un inventario de activos y servicios en el módulo de activos del propio service desk y llevamos cuatro líneas de trabajo bajo un mismo equipo, para que la operación siguiera funcionando mientras cambiaba por debajo. - [El expediente de evidencia: qué debería poder enseñar una empresa de Trinidad y Tobago](https://itacatech.com/es/resources/guides/evidence-file-tt/): La mayoría de los resúmenes dicen que la Data Protection Act 2011 de Trinidad y Tobago «aún no está en vigor», y esa imprecisión sale cara: la ley está parcialmente proclamada, con la Parte I y las secciones 7 a 18, 22, 23, 25(1), 26 y 28 en vigor desde el 6 de enero de 2012 por la Legal Notice No. 2 de 2012, y la sección 42(a) y (b) desde el 23 de agosto de 2021 por la Legal Notice No. 220 de 2021. Lo que ya está en vigor incluye los principios generales de privacidad y el marco de la oficina del Information Commissioner. Para un negocio que maneja datos personales (expedientes de clientes, historiales de pacientes, datos de empleados) la posición defendible es operar como si el resto de secciones fuera a llegar, lo que en la práctica significa mapear dónde viven los datos personales, controlar quién llega a ellos y poder demostrar ambas cosas; esos dos registros son las primeras páginas del expediente de evidencia. Para las instituciones financieras la presión es más inmediata, porque la Miscellaneous Provisions (FATF Compliance) Act 2025 está en vigor al completo desde el 17 de noviembre de 2025 y a las instituciones se les pide evidencia, no intenciones. - [Las primeras 24 horas: una lista de incidente para empresas de Florida](https://itacatech.com/es/resources/guides/first-24-hours/): Cuando una empresa de Florida descubre un correo comprometido, un pago desviado o archivos cifrados, puede que ya corran dos relojes: el estatuto de protección de datos de Florida da 30 días desde que se determina la brecha para notificar a los residentes afectados, y una institución financiera no bancaria (un broker hipotecario, una compañía de título, una asesoría) debe reportar desde mayo de 2024 ciertos incidentes a la FTC bajo la Safeguards Rule. El primer día decide casi todo lo que viene después, y pide cuatro cosas en orden: cortar el acceso sin destruir la evidencia, cambiando credenciales, cerrando sesiones y conservando los registros; avisar a la aseguradora antes de cambiar nada que después pueda considerar material, e incorporar pronto a un abogado, porque los dos relojes son cuestiones legales y no técnicas; conservar antes de que nadie restaure nada; y nombrar en voz alta a una persona que dirija, es decir, que decida hora a hora qué se corta, qué se conserva y a quién se avisa, anotando cada decisión con su hora. El error más caro es restaurar antes de conservar: parece recuperación y destruye el registro que decide qué sabes, qué debes notificar y qué cubre la aseguradora. ## Offices & contact - Itaca Technologies — Headquarters: 2387 W 68th St #604, Hialeah, FL 33016 (US) - Itaca Technologies — Fort Lauderdale: 501 E Las Olas Blvd, Suites 200 & 300, Fort Lauderdale, FL 33301 (US) - Itaca Technologies — Port of Spain: 5th Floor, Newtown Centre, 30-36 Maraval Road, Port of Spain (TT) - Phone: +17865688890 - Email: itaca@itacatech.com