Cybersecurity is often discussed after an organisation loses data, suffers fraud or finds its systems encrypted. By that point, recovery is expensive and public trust has already been damaged. Ugandan government institutions, businesses, schools, hospitals and civil-society organisations need practical security measures that operate every day, not policies that remain in files until an incident occurs.
The first priority is knowing what must be protected. Organisations should maintain an inventory of computers, servers, network equipment, cloud services, software, databases and accounts. An institution cannot secure systems it does not know it owns. Each asset should have a responsible person, approved purpose, update status and record of the information it stores or accesses.
Identity security is the next defence. Staff should use individual accounts rather than shared usernames that make accountability impossible. Strong passwords, multifactor authentication and prompt removal of accounts belonging to former workers reduce common risks. Administrators should receive separate privileged accounts and use them only for technical tasks. Access should follow job responsibilities, with regular review when staff transfer or change roles.
Software updates must be organised. Unsupported operating systems and applications expose known weaknesses that attackers can exploit. Institutions need a schedule for testing and installing security patches, including on routers, cameras, printers and other connected devices. Where an old system cannot be updated immediately, it should be isolated and monitored while replacement is planned.
Backups are essential but frequently misunderstood. A copy stored permanently on the same network may be encrypted or deleted during an attack. Organisations should keep multiple backups, including one protected from normal user accounts or stored offline. Restoration tests matter because a backup that cannot be recovered is not protection. Critical services should have documented recovery priorities and acceptable downtime.
Staff awareness should focus on realistic behaviour. Employees need to recognise suspicious links, unexpected attachments, payment-change requests and attempts to obtain passwords or verification codes. Training should explain how to report a mistake quickly without fear. Attackers rely on delay and embarrassment; an employee who reports a suspicious click immediately can help technicians prevent wider damage.
Network design can limit the impact of compromise. Guest Wi-Fi, administrative systems, payment devices, CCTV and public computers should not automatically share one unrestricted network. Segmentation and properly configured firewalls reduce movement between systems. Remote access needs encryption, strong authentication and logging. Default passwords on routers, cameras and recorders should be changed before deployment.
Incident response must be prepared in advance. Staff should know whom to contact, how to disconnect affected equipment safely and how decisions will be made. Technical teams need procedures for preserving evidence, notifying leadership, communicating with users and reporting to competent authorities. Public communication should be accurate and should not expose security details that assist attackers.
Data protection and cybersecurity are connected. Institutions should collect only necessary personal information, retain it for justified periods and control who can download or share it. Encrypting sensitive data reduces harm if a device is lost or a database is copied. Contracts with technology suppliers should specify security responsibilities, breach notification and secure deletion when services end.
Leadership must treat cyber risk as an organisational responsibility, not a problem for one IT officer. Boards and accounting officers should receive regular reports on vulnerabilities, incidents, training, recovery tests and unresolved risks. Budgets need to include maintenance, licensing and skilled personnel. Buying a new security product will not compensate for poor processes or unsupported systems.
Uganda’s digital services will continue expanding, making resilience increasingly important. The strongest defence is a collection of basic controls performed consistently: accurate inventories, secure accounts, updates, tested backups, trained staff, segmented networks and prepared response. Institutions should strengthen these measures before an attacker provides the motivation.
Sources: National Information Technology Authority–Uganda, https://www.nita.go.ug/; Uganda Communications Commission, https://www.ucc.co.ug/; Personal Data Protection Office, https://www.pdpo.go.ug/.
Photo credit: Nile Journal editorial illustration.


