____________________
Cybersecurity has evolved from a technical concern into a national economic security issue that could threaten financial stability, investor confidence and continuity of essential services, Bank of Uganda (BOU) Governor Dr Michael Atingi-Ego has warned.
Atingi-Ego, who was the keynote speaker at the inaugural National Cybersecurity Conference at Sheraton Kampala Hotel in Kampala on Tuesday (August 11), said Uganda’s rapid digital transformation had created significant opportunities for economic growth while exposing the economy to new and interconnected risks.
The conference brought together government officials, regulators, security agencies, telecommunications operators, financial institutions, technology companies, academics, innovators and cybersecurity practitioners.

The BOU boss said cybersecurity should be treated as a foundation of a resilient digital economy rather than an issue left to information technology departments.
“Technology can accelerate transformation. Finance can turn transformation into investments, production and opportunities. But trust is what allows businesses and institutions to participate in the economy. Cybersecurity is increasingly the principal means by which that trust is sustained,” he said.
Atingi-Ego said Uganda’s expanding digital footprint was increasingly supporting commerce, financial inclusion, education and government services, making the resilience of digital infrastructure critical to the wider economy.
“The power of digital technology comes not only from the systems, but from the connections between them,” he said.
He cited the links between banks, telecommunications companies, payment platforms, consumers and cloud-service providers, warning that disruption in one part of the ecosystem could quickly spread to other sectors.
Atingi-Ego said a compromised digital identity could expose several services connected to the same credentials, while an attack on a critical service provider could disrupt financial or government services.
He said BOU has strengthened its regulatory framework through cyber and technological risk-management requirements covering governance, data protection and security controls.
“Our supervisory work goes beyond the balance sheet to assessing vulnerabilities and interconnections, precisely because cyber risks may begin at one point and, within hours, become a payment disruption, loss of confidence and even a financial stability event,” he said.
He urged institutions to regularly test their preparedness for cyber incidents instead of relying on contingency plans that had never been exercised.
“A continuity plan nobody has rehearsed, a backup nobody has restored, is not really a capability; it is a form written down on paper,” he said.
Atingi-Ego called for stronger threat-intelligence sharing, coordinated incident response and joint exercises involving institutions across different sectors.
He also rejected the perception that cybersecurity and innovation were competing priorities.
“The real choice is between innovation that is trusted and innovation that is vulnerable; between growth that compounds over years and growth that can be haunted by a single avoidable shock,” he said.
He urged organisations to incorporate security into the design of digital products and services rather than addressing vulnerabilities after deployment.
“Build security in, do not bolt it on later,” Atingi-Ego said.
The keynote address set the economic-security tone for the conference, while Uganda Communications Commission (UCC) executive director Nyombi Thembo focused on the need to make cybersecurity an integral part of the country’s expanding digital ecosystem.

Uganda Communications Commission (UCC) executive director Nyombi Thembo speaking during the inaugural National Cybersecurity Conference at Sheraton Kampala Hotel in Kampala on Tuesday.
Thembo said Uganda’s digital transformation would have limited value if citizens, businesses and government agencies were connected, but could not trust the systems supporting those connections.
“If Uganda succeeded in connecting every citizen, every business and every government service, but those connections couldn’t be trusted, would we have succeeded? I believe the answer is no,” Thembo said.
He said UCC’s latest Communications Sector Cybersecurity Posture Report showed reported malware infections falling from approximately 1.59 million in 2024 to 1.41 million in 2025.
Despite the decline, Thembo said the sector’s overall security rating remained in the basic security category, indicating elevated risk.
Thembo said the country was also facing mobile malware, ransomware, denial-of-service attacks, vulnerable web infrastructure and increasingly sophisticated phishing and impersonation, including the use of artificial intelligence.
“The question before us, therefore, is: How do we ensure that the defenders stay ahead of the threat? The answer is in one word: collaboration,” he said.
He said UCC was using the Uganda Computer Emergency Response Team (UgCERT) to provide cyber-threat intelligence, support incident response, provide digital-forensics capability and conduct cyber drills and simulation exercises.
Thembo said the commission had also developed Minimum Cybersecurity Guidelines for licensed operators to establish baseline measures for protecting critical infrastructure, consumer data and digital services.
The UCC chief urged organisations to treat cybersecurity compliance as part of risk management, business continuity and national security.
“Compliance should not be a box-ticking exercise, but rather an expression of commitment to risk management, customer trust, business continuity and national security,” he said.
Thembo identified faster threat-information sharing, improved incident coordination, stronger cybersecurity governance, investment in local skills and consumer resilience as key priorities.

He said boards, chief executive officers (CEOs) and accounting officers should take responsibility for cybersecurity risks rather than leaving the matter entirely to technical teams.
“Cybersecurity is no longer an issue to be delegated entirely to the technical teams. Boards, CEOs and Accounting Officers must understand and own the risks,” he said.
Thembo said UCC’s vision of “A Connected Uganda 2030” should also be understood as a commitment to a secure digital country.
“A Connected Uganda must also be a Secure Uganda, and that security cannot be built by one regulator, one ministry, one telecom company or one CERT. We must build it together,” he said.