Overview:

Dr Atingi-Ego said Uganda’s rapid shift towards a digital economy has created a web of interconnected systems in which an attack on one institution or service could quickly spread to other sectors.

KAMPALA — Cyberattacks could evolve from isolated technical disruptions into financial stability crises, threatening payment systems, businesses and public confidence in Uganda’s economy, Bank of Uganda Governor Dr Michael Atingi-Ego has warned.

Dr Atingi-Ego said Uganda’s rapid shift towards a digital economy has created a web of interconnected systems in which an attack on one institution or service could quickly spread to other sectors.

He said cybersecurity should therefore no longer be treated as an information technology concern for individual institutions, but as a national economic resilience issue requiring coordinated action by regulators, businesses and government agencies.

“That’s why we treat cybersecurity this morning not as an IT agenda item but as a macroeconomic one,” Dr Atingi-Ego said.

He was speaking at the inaugural National Cyber Security Conference organised by the Uganda Communications Commission (UCC), which brought together regulators, security agencies, financial institutions, telecommunications operators, technology companies, academics and other stakeholders.

The warning comes as Uganda’s digital economy expands, with an estimated 23 million people now online. Digital platforms increasingly support financial transactions, commerce, education and delivery of government services.

The country’s Digital Transformation Roadmap for 2023/24–2027/28 also seeks to expand digital access, with long-term targets including 90 per cent broadband coverage and 90 per cent of citizens accessing e-services online by 2040.

But Dr Atingi-Ego said every expansion of digital connectivity also increases the potential impact of cyber threats.

“Trust is not a soft virtue added on top of sound economics. It is an infrastructure as real and as load-bearing as a road or a power line,” he said.

“Remove it, and every investment we make in connectivity, financial inclusion and digital government sits on that ground can give way without warning.”

Rising cybercrime

The Governor cited Uganda Police annual crime reports showing that reported cybercrime cases increased from about 245 in 2023 to 474 in 2024, before declining to 412 in 2025.

Despite the decline, he said cyberattacks continue to cause financial losses running into billions of shillings each year.

A national assessment by the National Information Technology Authority-Uganda (NITAU), he added, found that about four in every 10 small and medium enterprises had experienced some form of cyberattack.

Dr Atingi-Ego said the growing interconnectedness of the financial system means the country can no longer assess cyber risks by looking at individual institutions alone.

“The power of digital technology comes not from individual systems, but from the connections between them,” he said.

He cited payment platforms linking banks, telecom operators, merchants and consumers, as well as digital identity systems and cloud infrastructure shared by multiple institutions.

“That interconnectedness creates enormous value, and it’s also precisely how disruption works,” he said.

“A vulnerability in a telecommunications network can surface as a crisis in the financial services. A compromise in one identity credential can open doors across the entire ecosystem.”

For the central bank, the Governor said, this has changed how financial stability risks must be assessed.

“Financial stability has always depended on capital liquidity. It now depends equally on availability, integrity, and reliability of the systems through which financial activity flows,” he said.

He warned that a cyber incident could begin as a technical problem but, within hours, become a payment disruption, trigger loss of confidence and potentially develop into a financial stability event.

“Our supervisory work looks beyond individual balance sheets to system-wide vulnerabilities and interconnections, precisely because cyber incidents that begin as a technical failure can, within hours, become a payment disruption, a loss of confidence, and if we are not prepared, a financial stability event,” Dr Atingi-Ego said.

Compliance not enough

The Bank of Uganda introduced cyber and technology risk management guidelines in December 2024, requiring supervised financial institutions to strengthen governance, data protection and security controls.

But Dr Atingi-Ego said compliance with regulations alone would not make institutions resilient.

He challenged financial institutions and other organisations to test whether they could continue operating when critical systems fail, technology providers become unavailable or several institutions are attacked simultaneously.

“The more useful question is, how well prepared are we when prevention fails? That is the discipline of resilience, the capacity to anticipate, withstand, detect, respond, recover, and critically, to learn,” he said.

He said institutions should regularly test their continuity plans and recovery systems rather than assuming that written plans automatically translate into preparedness.

“A continuity plan nobody has rehearsed, a backup nobody has restored is not yet a capability. It is a hope written down on paper,” he said.

Dr Atingi-Ego also called for stronger sharing of threat intelligence, coordinated responses to cyber incidents and joint exercises involving institutions from different sectors.

He said cybersecurity standards applied to banks should not remain confined to the financial sector because banks depend on telecommunications networks, technology providers, government systems and other critical infrastructure.

“The rigour we now require of banks under our cyber and technology risk management guidelines should not remain a banking sector achievement alone,” he said.

“Telecommunications, government agencies, and utility providers all have good reason to speak the same language of security, even where regulatory mandates that govern them differ.”

Security by design

Dr Atingi-Ego also rejected the view that cybersecurity could slow technological innovation.

He said security should instead be treated as a prerequisite for sustainable digital growth.

“There’s sometimes a temptation to frame our choice as one between security and innovation. To me that is wrong. The real choice is between innovation that is trusted and an innovation that is fragile,” he said.

“Security, properly understood, is not the tax we pay for innovation. It is one of the conditions that makes innovation sustainable.”

He urged institutions to adopt a “security by design” approach, where cybersecurity, privacy and responsible governance are incorporated into digital systems from the outset rather than added after deployment.

“Whether we are building a payments platform, a digital identity system, or deploying artificial intelligence in public services, security, privacy, and responsible governance belong in the design from the very first day,” he said.

The Governor further urged boards and senior executives to take direct responsibility for cybersecurity rather than leaving the matter to ICT departments.

“Cybersecurity is no longer solely the responsibility of ICT departments. It is a boardroom issue, an executive leadership responsibility, and increasingly a matter of national policy,” he said.

UCC calls for cooperation

UCC executive director Nyombi Thembo said Uganda’s communications sector continues to face significant cyber threats despite a decline in reported malware infections.

He said malware infections declined from about 1.59 million in 2024 to 1.41 million in 2025, but the sector’s overall security rating remained in the basic security category, indicating an elevated level of risk.

Mr Nyombi Thembo said Uganda is facing mobile malware, ransomware, denial-of-service attacks, vulnerable web infrastructure and increasingly sophisticated phishing and impersonation attacks, including those enabled by artificial intelligence.

He called for faster sharing of threat intelligence and closer cooperation among government agencies, regulators, security agencies, telecom operators, financial institutions, academia and cybersecurity practitioners.

“Cybersecurity must not be something we add to digital transformation after the infrastructure has been built. Cybersecurity must be part of the infrastructure itself. Actually, it must be a culture,” he said.

The warnings come as Uganda accelerates the adoption of digital financial services, online government platforms and other interconnected technologies.

For policymakers, the challenge is increasingly not simply expanding digital access, but ensuring that the systems connecting citizens, businesses and government can withstand disruption without undermining economic activity and public confidence.