• Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
RegisterLogin

Computer Security

  • Home
  • Blog
  • Computer Security

The enemy within: Why your staff may be the biggest cyber threat

  • Posted by Mr Strategy
  • Date August 27, 2025
  • Comments 0 comment

On 7th November 2024, a well-known humanitarian NGO in Kampala discovered that donor funds, meant for a maternal health project in Lira, had mysteriously dwindled. Bank statements showed UGX 1.6 billion disbursed to “beneficiary suppliers.” Yet on the ground, no medicines had arrived, and the health centre shelves remained empty.

At first, management suspected supplier fraud. They called in Summit Consulting Ltd to investigate. What we uncovered was far more chilling, the breach was inside the house.

How insiders weaponised access

The NGO’s finance system required two approvals for any payment above UGX 10 million. But insiders knew the weaknesses. Suspect 1, a trusted finance officer, had legitimate system credentials. Suspect 2, an IT administrator, had the power to override password resets.

Together, they created “ghost suppliers”, registered companies with near-identical names to real vendors. For example, “Gulu Health Supplies Ltd” vs. “Gulu Health Supplies Uganda Ltd.”

Funds were routed to accounts in the ghost companies, then siphoned through mobile money withdrawals in Gulu and Lira. The scheme ran undetected for nine months. Each transfer was small enough, UGX 25 million here, UGX 40 million there, to escape donor scrutiny.

The human side of cyber risk

Most executives think of cyber threats as hackers in hoodies in Russia or China. The reality in Uganda is different: your biggest threat is wearing your branded T-shirt, attending your morning devotion, and smiling in your staff WhatsApp group.

Why? Because insiders know your controls. They know what auditors look for, and what they ignore. Understand your timing. They know when approvers are distracted (e.g., month-end rush, board meetings, retreats). Exploit trust. In cultures where sharing passwords over WhatsApp is normal, controls collapse.

This is why your staff may be your greatest cyber vulnerability.

The investigation trail

Investigators always follow the leads. Bank account forensics. The ghost supplier accounts had no other business transactions, only NGO deposits. Mobile money analysis. Large cash withdrawals happened consistently within 48 hours of every NGO transfer. IP address tracking. Payment approvals allegedly made “by the CFO” actually came from the same office subnet used by Suspect 1. Lifestyle audit. Suspect 1, earning UGX 3 million monthly, had just completed a two-storey house in Najjera and was driving a Subaru Forester.

The pattern was unmistakable.

Red flags ignored

The auditors had seen the signs but failed to escalate.

  1. Repeated vendor name similarities. No supplier vetting had been done for years.
  2. Unusual working hours. Approvals at 11:47 pm were logged as “routine.”
  3. Lifestyle inflation. The same officer suddenly stopped borrowing salary advances and started flashing new gadgets.
  4. Weak IT segregation. One administrator had access to both the system backend and the finance workflow.

In short, the enemy was within, but the system was too trusting to notice.

Why insiders turn rogue

Interviews revealed three motives

  1. Perceived injustice. Suspect 1 felt underpaid compared to expatriate staff.
  2. Weak controls meant ghost suppliers could slip through with ease.
  3. The suspects claimed, “Donor’s waste money anyway; at least ours built something.”

This is the classic fraud triangle: pressure, opportunity, and rationalisation, played out in cyber terms.

The cultural dilemma

Many organisations struggle with a cultural contradiction; they value loyalty over verification. Managers say, “We are like family here.” Yet in cyber risk, family culture can be fatal. Trust is not a control. In fact, it is a vulnerability. The stronger the “family” culture, the easier it is for insiders to exploit it without suspicion.

How to fight the enemy within

  1. Zero Trust principles must be applied, but tailored to Ugandan realities
  2. Segregate duties. No single person should control end-to-end financial transactions.
  3. Automated monitoring. Deploy analytics that flag duplicate suppliers, unusual working hours, and suspicious clustering of payments.
  4. Continuous vetting. Do lifestyle audits, especially for staff in finance and IT.
  5. Enforce least privilege. Give staff access only to what they need, nothing more.

Whistleblower protection. Create safe channels. Most frauds are exposed by insiders, not systems. By the time the case closed, the NGO had lost UGX 1.6 billion. Donors froze funding. Reputational damage was catastrophic. As investigators, we recommended interventions to rebuild the control environment, retrain staff, and implement continuous monitoring tools. But the lesson was permanent: the cyber threat was not outside. It was inside. Cyber resilience is not about buying the latest firewall. It is about hardening your organisation against betrayal from within.

Your staff may be your greatest asset. But under pressure, they may also become your greatest liability.

The new imperative for every Ugandan board is clear:

Trust people. But design systems that do not need to.

Until next week, we remain, IFIS.

  • Share:
Mr Strategy

Previous post

Zero trust, full protection: The new risk management imperative
August 27, 2025

Next post

Blind spots in risk: What you don’t see could sink you
September 3, 2025

You may also like

secure-data
Your organization’s resources are Targeted: Level up the attacker’s playing field and reduce the aftermath
September 24, 2025
The-Role-of-Cybersecurity-Risk-Assessment-Software-in-Mitigating-Cyber-Threats
Strategic shield: Aligning cybersecurity risk priorities across the board
September 24, 2025
AdobeStock_825821897
A growing cyber threat landscape of East Africa – part 2
September 17, 2025

Leave A Reply Cancel reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Popular Courses

Internal Audit Core

Internal Audit Core

$1,120
Certified Fraud Forensic Professional

Certified Fraud Forensic Professional

$1,120
Certified Cyber Security Manager

Certified Cyber Security Manager

$1,120

At IFIS, we live by our motto. Every course, certification, and training session emphasizes practical, hands-on skills that empower you to solve real-world challenges from day one. Learn by doing. Be empowered to transform your career and life.

Facebook X-twitter Youtube Instagram

Quick Links

  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact

Contact Us

  • info@forensicsinstitute.org
  • +256 783373637
  • +256 782 610333
  • Strategy Place, Trinity Building, Block 216, Plot 2475, Kayondo Road, off Ntinda–Kiwatule Road, Kalinabiri, Ntinda, P.O. Box. 40292, Kampala.
  • Privacy Policy
  • Terms & Conditions

© 2026 – Forensic Institue. All rights reserved.

Login with your site account

Or login with:

Google
Are you human? Please solve:Captcha


Lost your password?

Not a member yet? Register now

Register a new account

Or login with:

Google
Are you human? Please solve:Captcha


Are you a member? Login now