Cybercrime nearly doubles as BoU calls for stronger national resilience
KAMPALA, August 12, 2026 — Uganda must treat cybersecurity as a national economic and resilience priority as cybercrime continues to rise alongside the country’s rapid digital transformation, the Bank of Uganda [BoU] top official has said.
Speaking during the inaugural National Cybersecurity Conference at Sheraton Kampala Hotel on Tuesday, Michael Atingi-Ego, the BoU Governor said cybersecurity could no longer be regarded as the responsibility of ICT departments or individual institutions, but as a national capability requiring collaboration across government, financial institutions, telecommunications companies, technology firms and other sectors.
Delivering his speech as Keynote Speaker during Day One of the conference, Atingi-Ego said Uganda’s growing digital footprint had brought significant economic opportunities but had also increased the country’s exposure to cyber threats.
An estimated 23 million Ugandans, nearly half the population, are now online, driving commerce, financial inclusion, education and access to government services, according to the BoU top executive.
However, he said, reported cybercrime cases nearly doubled from 245 in 2023 to 474 in 2024, representing an increase of more than 93 per cent, before falling slightly to 412 cases in 2025.
He said the financial losses associated with cybercrime were running into billions of shillings every year.
The growing threat comes as Uganda pursues an ambitious digital transformation agenda, with the Digital Transformation Roadmap 2023/24–2027/28 targeting 90 per cent broadband coverage and 90 per cent of citizens accessing e-services online by 2040.
Cybersecurity as an economic issue
Atingi-Ego argued that cybersecurity should be viewed not merely as a technical or ICT matter but as a macroeconomic issue because confidence in digital systems is essential to investment, financial inclusion and economic activity.
“Trust is not a soft virtue added on top of sound economics; it is infrastructure,” he said, stressing that citizens, businesses and investors must have confidence in the systems on which they increasingly depend.
The address cited a national assessment by National Information Technology Authority of Uganda [NITA-U] indicating that roughly four in every ten Ugandan small and medium-sized enterprises have experienced some form of cyberattack.
Globally, the annual cost of cybercrime is estimated at about US$10.5 trillion, highlighting the scale of the threat facing increasingly interconnected economies.
Atingi-Ego also warned that emerging technologies, particularly artificial intelligence, were rapidly changing the cybersecurity landscape, giving both attackers and defenders increasingly sophisticated tools.
Financial sector faces growing risks
Atingi-Ego said the financial sector was particularly exposed because digital financial services depend on interconnected systems involving banks, telecommunications operators, merchants, consumers and technology providers.
A vulnerability in one part of the ecosystem, he noted, could quickly spread to other sectors, potentially disrupting payments, undermining confidence and creating financial-stability risks.
The Bank of Uganda has responded by strengthening its regulatory framework. “Effective December 2024, the central bank issued Cyber and Technology Risk Management Guidelines requiring supervised financial institutions to establish robust governance, data-protection and cybersecurity controls, backed by supervisory enforcement,” Atingi-Ego said.
He said BoU itself has aligned its information-security programme with international standards, including ISO/IEC 27001, while maintaining executive and board oversight.
The central bank’s latest Financial Stability Review has identified cyber threats and system vulnerabilities as continuing operational risks to Uganda’s financial sector.
From compliance to resilience
The Governor called for a shift from simply complying with cybersecurity requirements to building practical resilience that enables institutions to withstand, respond to and recover from attacks.
“Cyber resilience deserves the same rigour” as the capital buffers and stress tests used by financial institutions to prepare for economic shocks, the Governor said.
Atingi-Ego identified three key shifts needed to strengthen Uganda’s cybersecurity posture: collaboration, resilience and trust.
Under collaboration, institutions should strengthen threat-intelligence sharing, coordinated incident response and joint cross-sector exercises.
The BoU Governor challenged sectors beyond banking to adopt stronger cybersecurity practices, arguing that telecommunications companies, government agencies and utility providers should be able to operate with a common understanding of security across Uganda’s critical digital ecosystem.
On resilience, institutions were urged to test their preparedness before crises occur, including determining what would happen if critical systems or technology providers became unavailable or if several institutions were attacked simultaneously.
He warned that an untested continuity plan or backup system should not be mistaken for genuine preparedness.
Trust must be built into digital systems
The third priority is trust, which the BoU official described as the ultimate measure of whether Uganda’s digital transformation is succeeding.
He said citizens and businesses must believe that the digital systems they use are safe, reliable and accountable.
Trust, the address noted, has direct economic value because it influences whether citizens adopt digital public services, whether businesses invest in digital platforms and whether investors have confidence in Uganda’s markets.
He also rejected the idea that cybersecurity and innovation are competing priorities.
“Security, properly understood, is not the tax we pay for innovation,” Atingi-Ego said, arguing instead that security is one of the conditions necessary for sustainable innovation.
The address called for cybersecurity, privacy and responsible governance to be incorporated into digital systems from the design stage rather than being added after problems emerge.
Call for national cybersecurity compact
Atingi-Ego urged participants at the inaugural conference to work towards a shared national compact built around three commitments: preventing institutional boundaries from becoming gaps through which cyber risks can spread; measuring preparedness by the ability to withstand, recover from and learn from incidents; and ensuring that Uganda’s digital transformation earns the confidence of citizens.
He said Uganda’s digital future would not be secured by technology, regulation or investment alone, but through institutions, systems and people working together.
The call comes as Uganda continues to strengthen its national cybersecurity architecture. The National Cybersecurity Strategy 2022–2026 adopts a whole-of-nation approach, while the Government recently launched the Updated National Information Security Framework 2026 to provide public institutions with practical security tools and minimum controls.
The Governor said cybersecurity must ultimately become a leadership responsibility, firmly embedded in governance frameworks, investment decisions and organisational culture.
“Cybersecurity is no longer solely the responsibility of ICT departments; it is a boardroom issue, an executive leadership responsibility, and increasingly a matter of national policy,” the Governor said.
UCC Executive Director speaks of expanding digital connectivity
Meanwhile, Uganda Communications Commission [UCC] Executive Director Nyombi Thembo while opening the conference called for stronger cybersecurity measures alongside efforts to expand digital connectivity, warning that connectivity without trust and security cannot deliver meaningful digital transformation.
He emphasised the importance of expanding digital networks but cautioned that connectivity was only “half the journey.”
“If we succeed in connecting every citizen, business, and public service, yet those connections cannot be trusted, we have not truly succeeded,” he said.
He said cybersecurity must not be treated as an afterthought to digital transformation, but should instead be embedded in the country’s digital infrastructure from the outset.
“Our latest Communications Sector Cybersecurity Posture Report shows encouraging signs, including a decline in reported malware infections from 1.59 million to 1.41 million. However, our overall sector security rating remains in the basic category, while threats such as ransomware, AI-driven phishing, and mobile malware continue to evolve rapidly,” Thembo said.
He called for greater cooperation among stakeholders, noting that cybercriminals operate across institutional and national boundaries, requiring defenders to adopt a similarly coordinated approach.
“Because cybercriminals do not respect organisational boundaries or jurisdictions, our defences must be equally integrated across the public and private sectors,” he said.
Thembo identified five key priorities for strengthening Uganda’s cybersecurity posture: accelerating real-time threat intelligence sharing, streamlining national incident coordination before crises occur, embedding cyber risk governance at board level, investing in local cybersecurity talent and ensuring consumer protection remains central to digital development.
“Moving forward, our collective national focus must centre on five practical priorities: accelerating real-time threat intelligence sharing, streamlining national incident coordination before a crisis strikes, embedding cyber risk governance at board level, investing in local talent so Uganda builds its own security solutions, and keeping consumers protected at the heart of everything we build,” he said.
He said UCC’s mission of achieving “A Connected Uganda 2030” must be matched by strong and reliable cybersecurity measures.
“Our mission at UCC is ‘A Connected Uganda 2030’, but true connectivity must be paired with unwavering security,” Thembo said, thanking the Ministry of ICT and National Guidance, the UCC Board and other stakeholders for their efforts to strengthen Uganda’s collective cybersecurity capabilities.
Other stakeholders speak
Day One of the conference included a panel that brought together Kenneth Kwesiga, Director, Financial Technology Service Providers Association of Uganda [FITSPA] and Abudu-Sallam Waiswa, Head of Litigation, Prosecution & Legal Advisory, UCC, and Japhet Aritho, Managing Director, Airtel Mobile Commerce Uganda Limited among others.
The conversation explored how Uganda can strengthen the security of digital financial services while ensuring that cybersecurity and compliance measures remain practical and accessible, particularly for smaller and emerging innovators.
In his contribution, Kwesiga highlighted the realities faced by growing fintechs, including the cost of accessing secure infrastructure and the cybersecurity risks associated with shared USSD environments.
He emphasised that cybersecurity goes beyond technology, noting that people remain one of the biggest sources of risk. Staff awareness, data protection policies, access controls, and responsible handling of customer information are therefore critical to protecting both institutions and their customers.
He also highlighted the opportunity for fintechs to leverage affordable, pay-as-you-use solutions such as SIM swap, device swap, number recycling, and identity verification APIs, rather than having to build every security capability from scratch. “At FITSPA, we remain committed to supporting our members in strengthening their technology, people, and risk management capabilities, while contributing to a secure, resilient, innovative, and inclusive digital financial ecosystem.”
The Minister of State for Information, Communications and Technology Joyce Nabbosa Ssebugwawo was among other people who spoke at the conference.
uy your copy of thecooperator magazine from one of our country-wide vending points or an e-copy on emag.thecooperator.news



