Michael Atingi-Ego: Cyber threats have put Uganda’s digital economy and business growth at risk
The Governor rejected the idea that businesses must choose between security and innovation.

Uganda’s rapidly expanding digital economy is creating new opportunities for businesses, investors and consumers, but the growing exposure to cyber threats is emerging as a major economic risk that could undermine confidence in digital services and investment.
Bank of Uganda Governor, Dr. Michael Atingi-Ego, has warned that cybersecurity must no longer be treated as an information technology issue but as a core business, financial stability and investment concern.
Speaking at the inaugural National Cybersecurity Conference in Kampala on August 11, the Governor said Uganda’s digital transformation will only succeed if finance, technology and trust advance together, with cybersecurity increasingly becoming the foundation for maintaining confidence in the digital economy.
Cyber risks rise with digital growth
Uganda’s digital footprint is expanding rapidly, with an estimated 23 million Ugandans, nearly half the population, now online, driving e-commerce, financial inclusion, education and digital government services.
The country’s Digital Transformation Roadmap 2023/24–2027/28 targets even greater connectivity, including 90 percent broadband coverage and 90 percent of citizens accessing e-services online by 2040.
But the expansion is also increasing the potential economic impact of cyberattacks.
According to figures cited by the Governor, reported cybercrime cases recorded by the Uganda Police Force increased from 245 in 2023 to 474 in 2024, representing a rise of more than 93 percent.
Although cases fell to 412 in 2025, they remained close to twice the 2023 level, with financial losses running into billions of shillings annually.
The exposure is particularly significant for Uganda’s private sector. A national assessment by NITA-U found that roughly four in every 10 Ugandan small and medium enterprises had experienced some form of cyberattack.
For businesses that increasingly depend on digital payments, cloud services, online customer platforms and electronic records, a cyber incident can quickly translate into operational disruption, financial losses and reputational damage.
Cybersecurity moves into the boardroom
The Governor argued that the economic significance of cybersecurity means responsibility can no longer be left to ICT departments.
“Trust is not a soft virtue added on top of sound economics; it is infrastructure,” the Governor said, stressing that digital investment, financial inclusion and e-government depend on public confidence in the systems supporting them.
This places cybersecurity increasingly within the responsibility of company boards and senior executives.
For businesses, the question is no longer simply whether their networks have firewalls or security software. It is whether they can continue operating when systems fail, suppliers are compromised or several organisations within the same ecosystem are attacked simultaneously.
Financial sector faces systemic exposure
The financial sector is particularly vulnerable because modern financial services are interconnected across banks, telecommunications companies, payment platforms, merchants and consumers.
The Governor warned that a vulnerability in one part of the digital ecosystem can quickly spread into another sector. A telecommunications disruption, for example, can affect financial transactions, while a compromised digital identity can potentially provide access to multiple services.
For the Bank of Uganda, cyber resilience has therefore become part of the broader financial stability agenda.
The central bank’s Cyber and Technology Risk Management Guidelines, effective from December 2024, require supervised financial institutions to strengthen governance, data protection and security controls, backed by supervisory enforcement.
The Bank has also aligned its own information-security programme with international standards, including ISO/IEC 27001, under executive and board oversight.
From compliance to resilience
The Governor challenged businesses and institutions to move beyond simply complying with cybersecurity requirements and develop practical resilience.
He urged organisations to test what would happen if their primary systems failed, a key technology provider became unavailable or several institutions were attacked simultaneously.
A continuity plan that has never been tested, he argued, offers limited protection when a real crisis occurs.
For businesses, this means investing in backup systems, recovery procedures, incident-response teams and regular simulations rather than assuming that cybersecurity investment is complete once policies have been written.
Cybersecurity as an investment
The economic argument for stronger cybersecurity is increasingly shifting from the cost of preventing attacks to the value of protecting trust.
The Governor said trust determines whether consumers adopt digital services, whether businesses invest in digital platforms and whether investors have confidence in markets.
Once lost, that trust can be significantly more expensive to rebuild.
This makes cybersecurity a potential competitive advantage for Ugandan companies seeking to attract customers and investors in an increasingly digital economy.
The message from the central bank is therefore that security should be incorporated into the design of digital products and services from the beginning rather than added after problems emerge.
Collaboration becomes the new business imperative
The conference also highlighted the growing need for cooperation across Uganda’s digital ecosystem.
The Governor called for stronger threat-intelligence sharing, coordinated incident response and joint cross-sector exercises involving financial institutions, telecommunications companies, government agencies and utility providers.
The argument is straightforward: cyber threats do not respect institutional boundaries, so cybersecurity defences cannot operate in isolation.
Uganda’s National Cybersecurity Strategy 2022–2026 and the recently launched Updated National Information Security Framework 2026 provide a policy foundation for this approach.
The challenge now is translating those frameworks into everyday practices across both public and private institutions.
Protecting the next phase of digital growth
Uganda’s ambition to expand broadband access, digital public services, electronic payments and technology-driven businesses means cybersecurity will increasingly determine how quickly and confidently the digital economy can grow.
The Governor rejected the idea that businesses must choose between security and innovation.
Instead, he argued that secure digital infrastructure is one of the conditions that makes innovation sustainable.
For Uganda’s private sector, the implication is significant: cybersecurity is no longer merely an expenditure required to protect computers and databases. It is becoming an investment in business continuity, customer confidence, financial stability and long-term growth.
As more Ugandans move online and more economic activity becomes digitally interconnected, the country’s ability to secure that ecosystem could ultimately determine whether digital transformation becomes a sustainable engine of investment and productivity, or a source of new economic vulnerabilities.



