________________
Financial institutions must find ways to make cybersecurity strong without turning it into a burden for customers, particularly the most vulnerable users of mobile money services, an Information and Communications Technology (ICT) expert has advised.
Albert Gitta, the Chief Technology and Information Officer at MTN Mobile Money Uganda Limited, cautioned delegates at Uganda's inaugural National Cybersecurity Conference at the Sheraton Kampala Hotel today (August 12) that such technology has to account for the uneven levels of digital and financial literacy among Ugandans, especially farmers, traders and other vulnerable customers who rely heavily on mobile money.
"We need to make security invisible and effective. Executive leadership should push for security by design," Gitta said. The two-day event held between August 11–12, was organised by the Uganda Communications Commission (UCC) through the Uganda Computer Emergency Response Team (UgCERT).
Gitta called on financial institutions to build "security by design" into their systems by deploying tools such as intelligent fraud detection, biometrics, and risk-based authentication to guard against increasingly sophisticated cyber threats.
He said intelligent fraud-detection systems can flag suspicious transactions automatically alongside biometric authentication.
Gitta questioned how well customers in remote areas, including illiterate users who depend on mobile money daily, understand technologies like biometrics.
He, however, warned that stronger authentication does not eliminate risk on its own, since criminals continue to exploit social engineering and handset takeovers to gain control of customers' phones and manipulate access to their accounts.
"When we introduce biometrics, there will still be a level of social engineering. These guys are very clever. They can take over the handset. The farmer retains the phone, but the biometrics have disappeared onto another handset," he said.
Gitta urged financial institutions to design systems capable of confirming that the person accessing an account is its genuine owner, even in cases where fraudsters have compromised a handset or manipulated the authentication process.
Risk-based authentication, he noted, has a role to play, but customers should never be expected to become cybersecurity experts just to transact safely.
"At the end of the day, the customer should not have to become a cybersecurity expert to deal with social engineering and fraud," Gitta advised.
He argued that genuine financial inclusion means designing services around the different literacy and technology levels of customers. He commended UCC for raising cybersecurity awareness while pressing for the effort to reach ordinary users beyond conference rooms and Information Technology professionals.
"Now the question will be; when we get to the cybersecurity person, how do we reach the farmer? I think that's our challenge. How do we reach that farmer, how do we reach that trader, how do we reach this vulnerable customer and speak their language?" he asked.
Cybersecurity education, he added, needs to be simple, intuitive and accessible for people who may not grasp technical jargon, but are increasingly reliant on digital financial services.
Joyce Juliet Nabbosa Ssebugwawo, the Minister of State for ICT, opened the two-day conference, with Bank of Uganda Governor Dr Michael Atingi-Ego delivering the keynote speech.
UCC's latest sector assessment showed malware infections falling from roughly 1.59 million in 2024 to 1.41 million in 2025, though the sector's overall security rating remained at a basic level.
UCC executive director George William Nyombi Thembo told delegates that connectivity "must be meaningful, safe, resilient, and trusted." He stressed that cyber threats cut across institutions and borders, making cross-sector collaboration essential.