Uganda's digital transformation is accelerating, and so is its exposure to cybercrime. That was the central message at "Uganda's Threat Landscape: State of Digital Exposure," a high-level session held on 26th June 2026 at the Ministry of ICT & National Guidance and convened by the CIO–CXO Digital Leadership Forum.
The gathering drew C-suite Executives, cybersecurity practitioners, and representatives from government, financial institutions, academia, and the private sector, all grappling with a single premise: cybersecurity is no longer a matter of if an organization will be targeted, but when, and how prepared it will be.
Opening the session, George Ouma, Co-chair of Round Tables at the Forum, framed the discussion as a collective responsibility rather than a technical briefing. "The strength of our cybersecurity ecosystem lies not only in technology, but in the conversations, collaborations, and actions we take together," he told participants, encouraging them to treat the session as a two-way exchange.
A widening attack surface
Emmanuel K. Kasule, Manager Cyber Security at Stanbic Bank Uganda, opened with an overview of how digital transformation is reshaping the threat environment. Cloud platforms, APIs, mobile money, IoT devices, and remote work technologies are all expanding the country's attack surface even as they drive efficiency and financial inclusion. "Every digital convenience introduces a new digital responsibility," Kasule said.
He cautioned that Uganda's cybercrime statistics drawn from police reports and the Uganda Communications Commission's cybersecurity posture data likely understate the true scale of the problem, since many organizations still avoid disclosing breaches for fear of reputational or legal fallout. Existing figures, he argued, should be read as a floor, not a ceiling.
Government and financial institutions, he said, carry the heaviest exposure. National identity systems, tax administration, health records, and energy and water utilities all present risks that go beyond financial loss into national security and public trust. In banking, legacy infrastructure, mobile money platforms, third-party vendors, insider threats, business email compromise, and AI-assisted fraud were flagged as recurring weak points.
Kasule's warnings to any institution tempted to think itself too small to matter was blunt: "The greatest cyber risk today is not technology, it is assuming your organization is too small or too prepared to be attacked."
AI rewrites the rules
Much of the discussion turned on how artificial intelligence (AI) is reshaping both attack and defence. Kasule noted that AI-generated phishing has grown sophisticated enough to defeat the old advice of watching for poor grammar. "We can no longer teach employees to look for broken English. The attackers have upgraded," he said, pointing also to deepfake voice technology and AI-driven impersonation as threats that exploit trust rather than technical flaws.
His broader argument was that cybersecurity is a business risk rather than an IT problem. Organizations with stronger resilience, he said, share certain traits: active board oversight, executive ownership, independent security leadership, and continuous risk assessment.
"Cybersecurity should be discussed in the boardroom before it becomes a crisis in the server room," he said.
Participants then completed a self-assessment of their own organizations' maturity across governance, authentication, incident response, and awareness.
Consistency over complexity
Andrew Omoding, Senior Manager IT Security at NSSF Uganda, shifted the conversation from diagnosis to action. Drawing on his experience securing one of Uganda's largest public institutions, he argued that most successful attacks exploit neglected fundamentals rather than sophisticated techniques.
"Cybersecurity is built on consistency, not complexity," Omoding said, urging organizations to patch legacy systems, routinely verify suspicious requests, and treat security as part of daily operations rather than a periodic campaign.
Like Kasule, he pointed to AI as having made phishing more convincing, and called for a shift from one-off awareness training toward a sustained culture of vigilance backed by technical controls.
On leadership, Omoding was direct: "Technology alone will never secure an organization. Leadership decisions will." He observed that many organizations only invest seriously in cybersecurity after an incident, an approach that proves costlier than acting proactively, and argued that security leaders need direct access to executives and boards to make the case before a breach forces the issue.
He also made the case for cross-institutional collaboration, noting that lessons from one organization's incident can protect many others if shared openly. "Your neighbour's cyber incident could become your greatest lesson, if information is shared," he said, calling for stronger partnerships between government, regulators, financial institutions, and private organizations.
The session closed with a set of practical recommendations. Immediate priorities included deploying multi-factor authentication, conducting vulnerability assessments, strengthening incident response, and putting cybersecurity on the board's agenda. Medium and long term priorities focused on building national cybersecurity talent, improving legislative frameworks, strengthening information sharing, and embedding executive accountability across sectors.
Closing the session, Gideon Nkurunungi, Executive Secretary of the CIO–CXO Digital Leadership Forum, challenged the C-suite Executives, policymakers, and technology leaders in attendance to transform discussions into measurable action.
The session's own framing captured the shift it was calling for: cybersecurity in Uganda, it noted, has moved beyond a technical conversation confined to server rooms and become a leadership conversation that belongs in boardrooms. As cloud adoption, mobile money, and AI-driven services continue to expand the country's digital footprint, the message from both presenters, Emmanuel K. Kasule and Andrew Omoding, converged on one point: resilience will depend less on any single technology and more on sustained governance, executive accountability, and collaboration across government, industry, and academia.
