Governor Atingi-Ego: Cybercrime threatens Uganda’s digital economy as cases nearly double

Uganda is facing a growing cybercrime threat exposing the risks that come with the country’s rapid shift to digital services. The cases nearly doubled from 245 in 2023 to 474 in 2024. The cases declined slightly to 412 in 2025, but Michael Atingi-Ego, the Bank of Uganda Governor warned that the continued expansion of Uganda’s digital economy […] The post Governor Atingi-Ego: Cybercrime threatens Uganda’s digital economy as cases nearly double appeared first on Daily Star.

Governor Atingi-Ego: Cybercrime threatens Uganda’s digital economy as cases nearly double

Uganda is facing a growing cybercrime threat exposing the risks that come with the country’s rapid shift to digital services.

The cases nearly doubled from 245 in 2023 to 474 in 2024. The cases declined slightly to 412 in 2025, but Michael Atingi-Ego, the Bank of Uganda Governor warned that the continued expansion of Uganda’s digital economy requires stronger protection of the systems on which businesses, financial institutions and government services increasingly depend.

Speaking at the inaugural National Cybersecurity Conference in Kampala, Atingi-Ego said cybersecurity should no longer be treated as an information technology concern but as an issue of economic stability and national resilience.

Uganda’s digital footprint has expanded rapidly, with an estimated 23 million people, nearly half of the population, now accessing the internet.

The Governor said the growth presents opportunities for financial inclusion, commerce, education and delivery of public services, but also exposes individuals, businesses and institutions to cyber threats.

“Our digital footprint is expanding rapidly, an estimated 23 million Ugandans, nearly half our population, are now online. But every gain in reach is also a gain in exposure,” he said.

The figures on cybercrime were drawn from the Uganda Police Force Annual Crime Report.

Atingi-Ego said the reported incidents have also been associated with financial losses running into billions of shillings, raising concern about the impact of cybercrime on businesses and the wider economy.

A national assessment by the National Information Technology Authority Uganda (NITA-U) also found that about four in every 10 small and medium enterprises had experienced some form of cyberattack.

The Governor said the growing reliance on digital systems means that a cyberattack can quickly move beyond an ICT problem and disrupt financial transactions and essential services.

He said financial stability, which has traditionally been associated with capital and liquidity, increasingly depends on the availability, integrity and reliability of digital systems.

“A cyber incident that begins as a technical failure can, within hours, become a payments disruption, a loss of confidence, and   if we are not prepared a financial-stability event,” he said.

The Bank of Uganda introduced Cyber and Technology Risk Management Guidelines in December 2024, requiring supervised financial institutions to strengthen governance, data protection and security controls.

The central bank has also aligned its information security programme with international standards, including ISO/IEC 27001, under executive and board oversight.

However, the Governor said cybersecurity cannot be left to the financial sector or ICT departments alone because cyber threats cut across different sectors of the economy.

He called for stronger cooperation between regulators, financial institutions, telecommunications companies, government agencies, security agencies and technology companies to share information and respond to emerging threats.

The Governor also challenged institutions to move beyond developing cybersecurity policies and instead ensure that their systems can withstand and recover from actual attacks.

He warned that contingency plans that are never tested may offer little protection when an institution suffers a cyberattack.

“A continuity plan nobody has rehearsed, a backup nobody has restored, is not yet a capability. It is a hope written down on paper,” he said.

Uganda has adopted the National Cybersecurity Strategy 2022–2026 and recently launched the Updated National Information Security Framework 2026, which provides public institutions with minimum security controls and practical tools.

The Governor said the challenge now is to translate the frameworks into practical measures across the economy.

He said cybersecurity should also be incorporated into digital systems at the design stage rather than being treated as an afterthought following an attack.

“Security, privacy and responsible governance belong in the design from the first day, not the review that follows after something goes wrong,” he said.

The Governor said Uganda’s digital transformation will depend not only on increasing internet access and digital services but also on whether citizens and businesses trust the systems they use.

He described trust as an economic asset, saying public confidence influences whether citizens adopt digital services and whether businesses and investors are willing to commit resources to the digital economy.

“Trust is not an intangible. It has economic value,” he said.

He urged company boards and senior executives to take greater responsibility for cybersecurity, arguing that the issue can no longer be left to ICT departments.

“Cybersecurity is no longer solely the responsibility of ICT departments; it is a boardroom issue, an executive leadership responsibility, and increasingly a matter of national policy,” he said.

The conference brought together regulators, security agencies, financial institutions, telecommunications companies, technology firms, academics, development partners and government officials to discuss ways of strengthening Uganda’s digital security and resilience.

The post Governor Atingi-Ego: Cybercrime threatens Uganda’s digital economy as cases nearly double appeared first on Daily Star.