Bank of Uganda governor Michael Ating-Ego has warned Ugandan institutions to strengthen their preparedness for cyberattacks, saying a major incident could quickly escalate from a technical disruption into a financial stability crisis.
Ating-Ego said Uganda’s growing reliance on interconnected digital systems means cybersecurity can no longer be treated solely as an information technology concern, but as a matter of national economic resilience.
He warned that a cyber incident could disrupt payment systems, businesses and essential services, undermine public confidence and, if not properly managed, trigger wider financial instability.
Ating-Ego was speaking at the inaugural National Cyber Security Conference organised by the Uganda Communications Commission (UCC), which brought together regulators, security agencies, financial institutions, telecommunications operators, technology companies, academics and other cybersecurity stakeholders.
He said the growing interconnectedness of Uganda’s digital infrastructure had created both opportunities and new vulnerabilities.
“Trust is not a soft virtue added on top of sound economics. It is an infrastructure as real and as load-bearing as a road or a power line. Remove it, and every investment we make in connectivity, financial inclusion and digital government sits on that ground that can give way without warning,” he said.
Uganda has an estimated 23 million people online, with digital platforms increasingly supporting commerce, financial inclusion, education and government service delivery.
The country’s Digital Transformation Roadmap for 2023/24–2027/28 also targets wider digital access, including 90 per cent broadband coverage and 90 per cent of citizens accessing e-services online by 2040.
Ating-Ego said every expansion of the country’s digital footprint also increases its exposure to cyber threats. According to Uganda Police annual crime reports cited by the governor, reported cybercrime cases increased from about 245 in 2023 to 474 in 2024, before declining to 412 in 2025.
He said cyberattacks continue to cause financial losses running into billions of shillings each year, while a national assessment by NITA-U found that about four in every 10 small and medium enterprises had experienced some form of cyberattack.
Interconnected systems, bigger risks
Ating-Ego said the greatest threat was no longer attacks against individual institutions, but the possibility of a vulnerability in one part of the digital ecosystem affecting several others.
“The power of digital technology comes not from individual systems, but from the connections between them,” he said.
He cited payment platforms linking banks, telecom operators, merchants and consumers; digital identity systems connecting citizens to multiple services; and cloud infrastructure shared by several institutions.
“That interconnectedness creates enormous value, and it’s also precisely how disruption works. A vulnerability in a telecommunications network can surface as a crisis in the financial services. A compromise in one identity credential can open doors across the entire ecosystem,” he said.
For the central bank, Ating-Ego said, this interconnectedness had changed the way financial stability risks should be assessed.
“Financial stability has always depended on capital liquidity. It now depends equally on availability, integrity, and reliability of the systems through which financial activity flows,” he said.
The Bank of Uganda introduced cyber and technology risk management guidelines in December 2024, requiring supervised financial institutions to strengthen governance, data protection and security controls.
Ating-Ego, however, said compliance with regulations alone would not make institutions resilient to cyberattacks. He urged institutions to regularly test their ability to continue operating when critical systems fail, key technology providers become unavailable or several institutions come under attack simultaneously.
“The more useful question is, how well prepared are we when prevention fails? That is the discipline of resilience, the capacity to anticipate, withstand, detect, respond, recover, and critically, to learn,” he said.
He challenged institutions to ask themselves what would happen if their primary systems failed, a key technology provider became unavailable for a day or several institutions were attacked at the same time.
“What happens if our primary system fails? If our key technology provider is unavailable for a day? If several institutions are hit simultaneously, who decides, who communicates, who coordinates, and how quickly can we restore what matters most?” he asked.
“A continuity plan nobody has rehearsed, a backup nobody has restored is not yet a capability. It is a hope written down on paper. These are the questions that separate the prepared from the merely compliant,” he said.
Call for joint response
Ating-Ego called for stronger sharing of threat intelligence, coordinated responses to cyber incidents and joint exercises involving institutions from different sectors.
He said cybersecurity requirements imposed on banks should not remain confined to the financial sector because telecommunications companies, government agencies and utility providers are all part of the same interconnected digital ecosystem.
“The rigour we now require of banks under our cyber and technology risk management guidelines should not remain a banking sector achievement alone. Telecommunications, government agencies, and utility providers all have good reason to speak the same language of security, even where regulatory mandates that govern them differ,” he said.

He also cautioned against viewing cybersecurity as an obstacle to technological innovation, arguing that secure systems were necessary for sustainable digital growth.
“There’s sometimes a temptation to frame our choice as one between security and innovation. To me that is wrong. The real choice is between innovation that is trusted and innovation that is fragile,” he said.
Ating-Ego urged institutions to adopt a “security by design” approach, incorporating security, privacy and responsible governance into digital systems from the outset rather than attempting to address vulnerabilities after deployment.
“Whether we are building a payments platform, a digital identity system, or deploying artificial intelligence in public services, security, privacy, and responsible governance belong in the design from the very first day. Not the review that follows after something has gone wrong,” he said.
He said cybersecurity should ultimately become a leadership responsibility, with boards and senior executives taking direct responsibility for the security and resilience of their organisations.
“Cybersecurity is no longer solely the responsibility of ICT departments. It is a boardroom issue, an executive leadership responsibility, and increasingly a matter of national policy,” he said.
UCC warns of growing threats
UCC Executive Director Nyombi Thembo backed the governor’s concerns, saying Uganda’s communications sector continues to face significant cyber threats despite a decline in reported malware infections.
He said malware infections fell from approximately 1.59 million in 2024 to 1.41 million in 2025, but the sector’s overall security rating remained in the basic security category, indicating elevated risk.
According to Nyombi Thembo, Uganda continues to face mobile malware, ransomware, denial-of-service attacks, vulnerable web infrastructure and increasingly sophisticated phishing and impersonation attacks, including those involving artificial intelligence.
He called for faster sharing of threat intelligence and closer cooperation among government agencies, regulators, security agencies, telecommunications operators, financial institutions, academia and cybersecurity practitioners.
“Cybersecurity must not be something we add to digital transformation after the infrastructure has been built. Cybersecurity must be part of the infrastructure itself. Actually, it must be a culture,” he said.
Nyombi Thembo said Uganda’s digital transformation would only be meaningful if the systems connecting citizens, businesses and government services could be trusted.