• Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
RegisterLogin

Blog

  • Home
  • Blog
  • Blog

Day 5: Cybersecurity Awareness Month, 2026: championed by forensicsinstitute.org in Uganda.

  • Posted by IFIS TEAM
  • Date October 5, 2026
  • Comments 0 comment

In October 2020, Ugandans woke up to a visible reminder of how dependent our economy had become on invisible digital connections.

Stanbic Bank, MTN Uganda and Airtel Uganda announced that a third-party service provider had suffered a system incident affecting bank-to-mobile-money transactions. The service was suspended while technical teams investigated. MTN later identified the provider as Pegasus Technologies and described what had happened as a security breach. Customer balances were reported as unaffected, but the connection between banks and wallets had been disrupted.

That incident has stayed with me because it captures cyber risk better than most board presentations ever will.

Nothing needed to happen to the customer’s phone, to the bank branch and to the mobile-money agent standing down the road.

One important digital bridge between organisations had a problem, and suddenly services on either side of that bridge were affected.

That is modern cyber risk.

We keep drawing neat boxes around our companies and asking whether our own systems are secure. Unfortunately, customers do not live inside our organisation charts. They experience an ecosystem.

A bank may be secure, but its payment aggregator may fail. A telecom company may be secure, but one of its integration partners may be compromised. An insurance company may have excellent controls, but the hospital, broker, cloud provider or payment partner connected to it may become the route through which trouble arrives.

My message to leaders at executive and board levels is that the most dangerous computer in your organisation may be the one you do not own.

Start with what must never stop

Whenever I sit with executives discussing cyber risk, I prefer to start with a business question rather than a technology question.

What must never stop?

If you are running a bank, customers must be able to access and move their money.

If you run an insurance company, customers must still be able to lodge claims and receive legitimate payments.

If you run a telecom business, communications and mobile money must remain available. Of late, MTN Uganda has been playing games. The office fibre Internet is always intermittent. At home, the fibre is so slow that you cannot run any AI sorry, SI model. The buffering is next level. When customers with active subscriptions cannot access their services, you know security has been breached as availability is a core cybersecurity objective.

If you run a hospital, clinicians must be able to access the information required to treat patients safely.

That conversation is far more valuable than asking whether the organisation has bought the latest security appliance.

I have seen executives visibly relax when the IT team says, “We have a firewall.”

I normally spoil the mood.

“So does almost every organisation that has ever been hacked.”

A firewall is important. So are locks on your office door. Neither proves that the organisation can survive a serious incident. Look at these as scarecrows. They are meant to scareaway casual adversaries.

Cybersecurity is a dependency problem

Our businesses have quietly accumulated enormous numbers of dependencies.

  1. Cloud providers.
  2. Payment switches.
  3. Mobile-money integrations.
  4. Fintechs.
  5. APIs.
  6. Payroll companies.
  7. Outsourced IT providers.
  8. Software vendors.
  9. Internet providers.
  10. AI platforms.
  11. The list is endless…

The interesting problem is that the smallest company on that list may carry one of your largest operational risks. Boards therefore need to stop ranking suppliers only by how much money they are paid.

I prefer another question:

“If this supplier disappears at 10 a.m. tomorrow, what stops working by lunchtime?”

You will learn more from that question than from most vendor-risk questionnaires.

Then AI arrived

AI makes this discussion much more interesting. For years we trained employees to recognise badly written phishing emails. That was convenient and easy. The criminal practically introduced himself with poor grammar and case.

AI has fixed his English.

Today a criminal can produce a perfectly written email in seconds, imitate a senior executive’s writing style, translate it naturally into local languages, create convincing documents and increasingly reproduce voices.

Imagine a CFO receiving a WhatsApp voice note:

“Sarah, I am boarding. The supplier is threatening to stop the shipment. Process the UGX 480 million now. Do not hold this because of paperwork. I will sign when I land.”

It sounds exactly like the CEO.

What should Sarah do?

Five years ago, somebody might have said, “I know my CEO’s voice.”

That control has expired.

The effective  control is process.

Call back on a known number.

Use a second approver.

Verify changes to payment instructions independently.

And, importantly, create a culture in which staff are allowed to challenge urgency.

I have always found this slightly amusing: some executives demand strong cybersecurity and then become irritated when controls slow down their own urgent requests.

You cannot tell employees, “Verify unusual instructions,” and then shout at them when they verify yours.

That is how fraudsters eventually discover that the easiest password in the organisation is the CEO’s temperament.

AI creates another risk from inside

There is another AI problem that receives less attention.

The employee is not malicious. She is simply busy. She receives a confidential 70-page document and thinks, quite reasonably, “AI can summarise this in thirty seconds.”

Copy.

Paste.

Done.

The productivity gain is wonderful. The governance question comes afterwards.

What information was just uploaded? Where did it go? Was the service approved? Can the data be retained? Was customer information included?

The next major information leak in your organisation may not involve a hacker. It may involve a hardworking employee trying to save twenty minutes. That is why AI governance must be practical rather than philosophical.

Tell people which tools they may use, what information they may put into them, what information must never leave approved environments, and which decisions still require human judgement.

Stop drowning the board in cyber statistics

Boards also need better reporting.

I have seen cyber dashboards that contain so much information that the directors leave knowing exactly nothing.

  1. Number of attacks blocked.
  2. Number of antivirus alerts.
  3. Number of patches installed.

Interesting.

But I would rather give the board answers to five questions.

  1. What could stop the business?
  2. What could cause us a material financial loss?
  3. Where is customer information most exposed?
  4. What cannot we recover quickly?
  5. What decision does management need from us?

Now we have a board conversation.

And please test the backups

Whenever management tells me, “We have backups,” I ask: “When did you last restore the business from them?”

Having backups and being able to recover are not the same thing.

It is like owning a parachute that nobody has ever opened and confidently announcing, “We are fully prepared for landing.” Boards should demand evidence of restoration, not evidence that somebody purchased backup software.

Then rehearse the bad day

One of the most valuable things a board can do is experience a cyber crisis before criminals organise one for them.

  1. At 8:30 a.m., tell the directors that mobile banking is unavailable.
  2. At 9:00, tell them customers are complaining online.
  3. At 9:30, tell them there are indications that customer information may have been accessed.
  4. At 10:00, the regulator wants an explanation.
  5. At 10:15, a journalist calls.

Then ask:

  1. Who is in charge?
  2. Do we shut systems down?
  3. Who speaks publicly?
  4. What do we tell customers?
  5. When do we inform regulators?
  6. Which supplier do we call?
  7. How long can we operate manually?

That morning will teach the organisation more about its cyber resilience than another policy sitting peacefully in SharePoint. The lesson from the Uganda mobile-money incident remains relevant years later. The digital economy runs on connections and partnerships.

And connections create dependencies.

Cybersecurity therefore cannot simply mean stopping hackers.

It must mean knowing what matters, understanding what you depend on, detecting trouble quickly, making good decisions under pressure and recovering before customers lose confidence.

That is the board’s real job.

So I would leave every CEO with one question:

If your most important digital service stopped tonight, could your organisation tell me by breakfast what happened, who is in charge, what customers should hear, and how the business will recover?

If the room goes quiet, do not call IT yet.

You have just discovered your next board agenda.

I remain, IFIS Faculty.

  • Share:
IFIS TEAM

Learn By Doing. We offer practical training to individuals and corporate entities who demand the very best.

Previous post

Cyber Hygiene for Non-Tech Staff
October 5, 2026

You may also like

27922cd9e67432a45c5efb1d5e06e0d7 (1)
Cyber Hygiene for Non-Tech Staff
October 3, 2026
e08de5df06d4dc3b5dcb5cf8838bc7c3
Agentic AI governance and risks: an investigator’s perspective
September 16, 2026
58f061b709df6258c4e3d418a4a8fd58
Why employees ignore anti-fraud policies: The policy was signed, but the shortcut ran the company
August 13, 2026

Leave A Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Courses

Protected: Why IFRS 9 Matters for URA

Protected: Why IFRS 9 Matters for URA

Free
Internal Audit Core

Internal Audit Core

$1,120
Certified Fraud Forensic Professional

Certified Fraud Forensic Professional

$1,120

At IFIS, we live by our motto. Every course, certification, and training session emphasizes practical, hands-on skills that empower you to solve real-world challenges from day one. Learn by doing. Be empowered to transform your career and life.

Facebook X-twitter Youtube Instagram

Quick Links

  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact
  • Home
  • About Us
  • Courses
  • Membership
    • Registration
  • Events
  • Blog
  • Contact

Contact Us

  • admissions@forensicsinstitute.org
  • +256 783373637
  • +256 782 610333
  • Strategy Place, Trinity Building, Block 216, Plot 2475, Kayondo Road, off Ntinda–Kiwatule Road, Kalinabiri, Ntinda, P.O. Box. 40292, Kampala.
  • Privacy Policy
  • Terms & Conditions

© 2026 – Forensic Institue. All rights reserved.

Login with your site account

Lost your password?

Not a member yet? Register now

Register a new account

Are you a member? Login now