Blogs

Changing nature of cyber threats

An insecure ministry connected to the wider government network can become the entry point through which an attacker reaches other institutions.

Godfrey Mutabazi. (File)
By: Admin ., Journalist @New Vision

________________

OPINION

By Godfrey Mutabazi

Criminals are increasingly targeting people, passwords, mobile devices and digital identities rather than concentrating exclusively on central networks. Additionally, social engineering, SIM-swap fraud, account takeovers, impersonation and AI generated phishing have become part of the everyday threat facing ordinary citizens and national institutions.

This was revealed at Uganda’s inaugural National Cybersecurity Conference, held at the Sheraton Kampala Hotel on August 11–12, 2026. The conference was an important and timely national initiative.

By bringing together government institutions, regulators, financial institutions, telecommunications operators, law-enforcement agencies, academia and technology companies, the conference elevated cybersecurity from a specialised technical concern to a matter of national importance.

Its theme, “Securing Uganda’s Digital Future: Collaboration, Resilience and Trust,” correctly captured the challenge before the country.

Uganda’s digital economy has expanded rapidly through mobile money, digital banking, electronic government services, smartphones and internet connectivity.

These developments have created real opportunities for economic participation and improved service delivery. They have also increased exposure to fraud, identity theft, data breaches, malware and attacks supported by artificial intelligence.

The conference heard that more than 700,000 compromised credentials associated with Uganda had been discovered during the preceding twelve months. Such a figure should prompt more than public concern. Government and industry need to establish how many of those credentials belonged to public officers or critical institutions, whether the affected organisations were notified, whether compromised accounts were disabled, and whether multi-factor authentication was introduced.

The conference was also right to emphasise collaboration. Banks cannot effectively combat account takeover without telecommunications companies. Telecommunications operators cannot properly verify subscribers without reliable identity systems.

The Police require evidence and cooperation from service providers, while regulators need accurate threat information if they are to set appropriate standards. Collaboration, however, must not become a substitute for clearly assigned authority and institutional accountability.

The conference appears to have concentrated principally on cyber threats, consumer awareness, skills, cooperation and incident response. These elements are indispensable, but they do not fully address Uganda’s underlying digital preparedness. The deeper question is how government itself is digitally organised, interconnected, supervised and held accountable.

NITA-U was established to coordinate, regulate and supervise information technology across government. Its essential purpose was to prevent ministries, departments and agencies from developing incompatible, duplicated and insecure systems under differing technical standards. That mandate should remain central to Uganda’s cybersecurity strategy.

Every government institution may retain its legal responsibilities and control over its own data, but it should not be free to operate outside common national technology and cybersecurity standards.

NITA-U needs the institutional capacity and practical enforcement mechanisms to inspect government systems, identify vulnerabilities, require corrective action and verify compliance with national standards.

An insecure ministry connected to the wider government network can become the entry point through which an attacker reaches other institutions.

Government must also know precisely what it is protecting. Uganda needs a continuously updated national register of government databases, websites, networks, software, cloud services, technology suppliers, system administrators and data custodians. It is impossible to defend systems that the central technical supervisor does not know exist.

Fragmented technology procurement presents another serious risk. Ministries frequently procure systems independently, sometimes producing several platforms that perform similar functions yet cannot communicate with one another. Some contracts leave government dependent on suppliers for passwords, maintenance, source code, encryption keys or system recovery. Cybersecurity requirements must therefore be built into procurement from the outset, rather than introduced after systems have already been installed.

The writer is the former executive director of Uganda Communications Commission

Help us improve! We're always striving to create great content. Share your thoughts on this article and rate it below.

Tags:
Cyber
Tech