
Day 5: Cybersecurity Awareness Month, 2026: championed by forensicsinstitute.org in Uganda.
In October 2020, Ugandans woke up to a visible reminder of how dependent our economy had become on invisible digital connections.
Stanbic Bank, MTN Uganda and Airtel Uganda announced that a third-party service provider had suffered a system incident affecting bank-to-mobile-money transactions. The service was suspended while technical teams investigated. MTN later identified the provider as Pegasus Technologies and described what had happened as a security breach. Customer balances were reported as unaffected, but the connection between banks and wallets had been disrupted.
That incident has stayed with me because it captures cyber risk better than most board presentations ever will.
Nothing needed to happen to the customer’s phone, to the bank branch and to the mobile-money agent standing down the road.
One important digital bridge between organisations had a problem, and suddenly services on either side of that bridge were affected.
That is modern cyber risk.
We keep drawing neat boxes around our companies and asking whether our own systems are secure. Unfortunately, customers do not live inside our organisation charts. They experience an ecosystem.
A bank may be secure, but its payment aggregator may fail. A telecom company may be secure, but one of its integration partners may be compromised. An insurance company may have excellent controls, but the hospital, broker, cloud provider or payment partner connected to it may become the route through which trouble arrives.
My message to leaders at executive and board levels is that the most dangerous computer in your organisation may be the one you do not own.
Start with what must never stop
Whenever I sit with executives discussing cyber risk, I prefer to start with a business question rather than a technology question.
What must never stop?
If you are running a bank, customers must be able to access and move their money.
If you run an insurance company, customers must still be able to lodge claims and receive legitimate payments.
If you run a telecom business, communications and mobile money must remain available. Of late, MTN Uganda has been playing games. The office fibre Internet is always intermittent. At home, the fibre is so slow that you cannot run any AI sorry, SI model. The buffering is next level. When customers with active subscriptions cannot access their services, you know security has been breached as availability is a core cybersecurity objective.
If you run a hospital, clinicians must be able to access the information required to treat patients safely.
That conversation is far more valuable than asking whether the organisation has bought the latest security appliance.
I have seen executives visibly relax when the IT team says, “We have a firewall.”
I normally spoil the mood.
“So does almost every organisation that has ever been hacked.”
A firewall is important. So are locks on your office door. Neither proves that the organisation can survive a serious incident. Look at these as scarecrows. They are meant to scareaway casual adversaries.
Cybersecurity is a dependency problem
Our businesses have quietly accumulated enormous numbers of dependencies.
- Cloud providers.
- Payment switches.
- Mobile-money integrations.
- Fintechs.
- APIs.
- Payroll companies.
- Outsourced IT providers.
- Software vendors.
- Internet providers.
- AI platforms.
- The list is endless…
The interesting problem is that the smallest company on that list may carry one of your largest operational risks. Boards therefore need to stop ranking suppliers only by how much money they are paid.
I prefer another question:
“If this supplier disappears at 10 a.m. tomorrow, what stops working by lunchtime?”
You will learn more from that question than from most vendor-risk questionnaires.
Then AI arrived
AI makes this discussion much more interesting. For years we trained employees to recognise badly written phishing emails. That was convenient and easy. The criminal practically introduced himself with poor grammar and case.
AI has fixed his English.
Today a criminal can produce a perfectly written email in seconds, imitate a senior executive’s writing style, translate it naturally into local languages, create convincing documents and increasingly reproduce voices.
Imagine a CFO receiving a WhatsApp voice note:
“Sarah, I am boarding. The supplier is threatening to stop the shipment. Process the UGX 480 million now. Do not hold this because of paperwork. I will sign when I land.”
It sounds exactly like the CEO.
What should Sarah do?
Five years ago, somebody might have said, “I know my CEO’s voice.”
That control has expired.
The effective control is process.
Call back on a known number.
Use a second approver.
Verify changes to payment instructions independently.
And, importantly, create a culture in which staff are allowed to challenge urgency.
I have always found this slightly amusing: some executives demand strong cybersecurity and then become irritated when controls slow down their own urgent requests.
You cannot tell employees, “Verify unusual instructions,” and then shout at them when they verify yours.
That is how fraudsters eventually discover that the easiest password in the organisation is the CEO’s temperament.
AI creates another risk from inside
There is another AI problem that receives less attention.
The employee is not malicious. She is simply busy. She receives a confidential 70-page document and thinks, quite reasonably, “AI can summarise this in thirty seconds.”
Copy.
Paste.
Done.
The productivity gain is wonderful. The governance question comes afterwards.
What information was just uploaded? Where did it go? Was the service approved? Can the data be retained? Was customer information included?
The next major information leak in your organisation may not involve a hacker. It may involve a hardworking employee trying to save twenty minutes. That is why AI governance must be practical rather than philosophical.
Tell people which tools they may use, what information they may put into them, what information must never leave approved environments, and which decisions still require human judgement.
Stop drowning the board in cyber statistics
Boards also need better reporting.
I have seen cyber dashboards that contain so much information that the directors leave knowing exactly nothing.
- Number of attacks blocked.
- Number of antivirus alerts.
- Number of patches installed.
Interesting.
But I would rather give the board answers to five questions.
- What could stop the business?
- What could cause us a material financial loss?
- Where is customer information most exposed?
- What cannot we recover quickly?
- What decision does management need from us?
Now we have a board conversation.
And please test the backups
Whenever management tells me, “We have backups,” I ask: “When did you last restore the business from them?”
Having backups and being able to recover are not the same thing.
It is like owning a parachute that nobody has ever opened and confidently announcing, “We are fully prepared for landing.” Boards should demand evidence of restoration, not evidence that somebody purchased backup software.
Then rehearse the bad day
One of the most valuable things a board can do is experience a cyber crisis before criminals organise one for them.
- At 8:30 a.m., tell the directors that mobile banking is unavailable.
- At 9:00, tell them customers are complaining online.
- At 9:30, tell them there are indications that customer information may have been accessed.
- At 10:00, the regulator wants an explanation.
- At 10:15, a journalist calls.
Then ask:
- Who is in charge?
- Do we shut systems down?
- Who speaks publicly?
- What do we tell customers?
- When do we inform regulators?
- Which supplier do we call?
- How long can we operate manually?
That morning will teach the organisation more about its cyber resilience than another policy sitting peacefully in SharePoint. The lesson from the Uganda mobile-money incident remains relevant years later. The digital economy runs on connections and partnerships.
And connections create dependencies.
Cybersecurity therefore cannot simply mean stopping hackers.
It must mean knowing what matters, understanding what you depend on, detecting trouble quickly, making good decisions under pressure and recovering before customers lose confidence.
That is the board’s real job.
So I would leave every CEO with one question:
If your most important digital service stopped tonight, could your organisation tell me by breakfast what happened, who is in charge, what customers should hear, and how the business will recover?
If the room goes quiet, do not call IT yet.
You have just discovered your next board agenda.
I remain, IFIS Faculty.



