The inaugural National Cybersecurity Conference, organised by the Uganda Communications Commission (UCC), officially opened at the Sheraton Kampala Hotel on Tuesday this week under the theme “Securing Uganda’s Digital Future: Collaboration, Resilience and Trust.” The two-day event, running from Tuesday, August 11 through Wednesday, August 12, 2026, brought together regulators, law enforcement, financial sector leaders and technology experts to examine how Uganda can protect its fast-growing digital economy and strengthen public confidence in the systems and services that increasingly shape everyday life.
Among the most engaging sessions was the discussion on the “State of Cybersecurity in Uganda,” which explored key issues surrounding emerging cyber threats, national cybersecurity readiness, and where the priority risks lie, including child online protection. The session featured insights from Eng. Christine Mugimba, Johnson Tumusiime, and Andrew Mubiru of the Uganda Police Force, who shared perspectives from UCC, NITA-Uganda, and the Uganda Police Force, respectively.
Growth outpacing preparedness
Eng. Christine Mugimba, Director of ICT and Research at UCC, told delegates that “the threat landscape is evolving faster than our preparedness,” with attack activity increasingly shifting away from core networks toward end-user devices, identities, and exposed services. She noted that UCC’s Computer Emergency Response Team monitors the landscape daily, feeding threat intelligence that shapes the sector’s posture, but the numbers she presented showed how much ground there is to cover.
According to UCC Market Performance Report Q2 2026, Uganda counted 49 million active mobile subscriptions as of June 2026, alongside 19.7 million mobile internet users, 20.5 million smartphones and 37.8 million mobile money subscriptions, citing Bank of Uganda figures. That growth is powering everything from e-government platforms to financial transactions and e-learning, Eng. Mugimba said, but it is also widening the door for cyber incidents, fraud and data breaches.
She pointed to a scam many Ugandans will recognize: fraudsters impersonating telecom or regulatory officials, warning victims their phones will be switched off unless a SIM card is “re-registered.” It’s a small but telling example, she suggested, of how the same connectivity driving Uganda’s digital economy also creates new openings for abuse.
Much of the pressure, she added, traces back to forces far beyond Uganda’s borders: geopolitical conflict, hacktivism, and artificial intelligence (AI) lowering the barrier to entry for attackers. Citing a Microsoft report from March 2026, she said hackers are now using AI to run multilingual phishing campaigns targeting executives. “AI is also helping criminals create more convincing scams,” she warned.

Where Uganda stands
The readiness numbers were less comforting. Eng. Mugimba said Uganda’s telecom sector scores 585 on a tool-based index she described as still at the “basic” tier, out of three tiers ranging from basic to high. On the International Telecommunication Union’s (ITU) Global Cybersecurity Index, last updated in 2024, Uganda sits at Tier 3, while several neighbouring countries, Kenya, Rwanda, and Tanzania have reached Tier 1.
There were pockets of improvement in botnet activity; networks hijacked to spread malicious traffic declined by 16.4% compared with previous years. But compromise at the device and application level is rising, and in the past 12 months alone, 713,235 credentials tied to Uganda were found compromised, from leaked email records to malware logs harvested by so-called infostealers.
“People, processes, technologies, and governance must all mature together,” Eng. Mugimba said, warning leaders that laws and frameworks mean little until they’ve actually been tested. Regulation already exists across finance, communications and security, she said, but few institutions can say with confidence that their systems would hold up if an incident actually happened.
The AI wildcard
Presenting NITA-Uganda’s perspective, their Governance and Risk Manager, Johnson Tumusiime, said threats have grown sharply over the past five years, and while regulatory foundations are largely in place, implementation remains uneven, hampered by inconsistent budgets and skills gaps across sectors. “The risks remain because we are not moving as fast as the digitisation gap is,” he said.
He singled out AI as the issue causing the most unease among regulators, precisely because it remains so poorly understood. Referencing a case he said had already been raised by the Bank of Uganda Governor, Dr. Michael Atingi-Ego, Tumusiime described an incident around July 2026 in which an AI model under test reportedly broke out of its sandbox environment, identified and exploited a separate unpatched vulnerability, and manipulated the results it reported back to its own researchers.

“We have no clue of what happens in between the input and the output,” Tumusiime said of AI systems more broadly, arguing that governance, not just technical controls, is now unavoidable.
He urged a shift in institutional mindset: “Yesterday’s hackers focused more on attacking systems and people. However, now it’s about attacking the ecosystem; people, identities, processes, data and infrastructure all at once, often through the weakest partner in a chain of suppliers and contractors,” he said.
A well-defended ministry or regulator means little, he warned, if a hospital or small business plugged into the same digital ecosystem remains exposed. “Cyber security issues will not differentiate between a weak MDA or a weak government entity,” he said. “They just come for you.”
“A glass house with curtains”
ACP. Andrew Mubiru, Director of Forensic Science at Uganda Police Force, brought the law enforcement lens. Recalling a conversation with a cybersecurity vendor while travelling in Thailand, he said the outsider’s verdict on the region’s defences was blunt: “Most of the African countries are as good as a glass house with curtains, attractive and seemingly secure, until someone pulls the curtains back.”
Financial services remain the top target, he said, “because everybody is looking at the money.” He illustrated the imbalance starkly: a cheaply bought exploit, in the wrong hands, could be worth billions if deployed against the right system. But he pushed back on the idea that outside hackers are Uganda’s biggest problem. “The insider threat is real,” he said, calling it a bigger concern even than AI-driven attacks, especially as government digitizes sensitive infrastructure such as oil refineries and citizen records.
Underreporting compounds the problem, ACP. Mubiru said. Institutions, particularly in banking, often disclose incidents only once the damage is severe, while different sectors respond in silos. “We need to harmonise,” he said.
ACP. Mubiru also raised the cross-border, diplomatic dimension of cybercrime, citing a recent attack on a bank in neighbouring Rwanda in which stolen funds were routed through and withdrawn in Uganda. Left unaddressed, he warned, this is the kind of incident a neighbouring state could interpret as closer to a hostile act than an ordinary crime.

“A cybersecurity exposure may actually turn out to be a national security risk,” he said. Uganda has signed the United Nations Convention against Cybercrime, adopted in Hanoi, Vietnam, in 2025, but has yet to complete domestic ratification, and gaps remain in domesticating the African Union’s Malabo Convention on cybersecurity omissions, he said, which are already limiting Uganda’s access to advanced digital forensics tools from international partners.
Looking ahead, Mubiru said financial fraud, particularly through mobile money, should be the priority over the next 12 months, alongside protecting government records such as national IDs and driving permits, securing supply chains that remain heavily import-dependent, and confronting the rise of AI-enabled impersonation and voice cloning.
Uganda’s children online
Child online protection ran through all three presentations as a distinct, urgent thread. Eng. Mugimba cited a UCC survey conducted around the COVID-19 period showing that 1 in 5 school-going children aged 6 to 17 had encountered explicit content online, with boys reporting far less concern about the exposure than girls. The same survey found that 85.3% of children did not tell a parent when something troubling happened online, confiding instead in peers, while 76.8% of parents reported little to no involvement in their children’s online activity beyond buying the device.
Tumusiime framed the stakes starkly. “For a child, the cybersecurity incident is not about the compromise of their device. It’s about their dignity, their safety and their well-being,” he said, noting that predators often exploit children’s innocence and limited grasp of consequences to manipulate them, a problem, he said, that “technology alone will not be able to solve.”
ACP. Mubiru, on the other hand, pointed to rising cases of cyberstalking and cyberbullying affecting children, and cited an international example: an incident in Sweden in which minors were reportedly manipulated online into committing violence against adults as a warning of how far such exploitation can escalate, particularly given that children below a certain age are not criminally liable under Ugandan law.
He said case numbers his office handles have climbed from 129 in 2019 to 833 today, and called for dedicated, child-accessible reporting channels such as hotlines, alongside stronger legislation and sustained public awareness campaigns.
All three speakers converged on the same solution: a national child online protection system built on “security by design,” embedding safeguards into digital platforms and services for children from the outset rather than retrofitting them after harm occurs.
Also read:
- Airtel commits to protect children against cyberbullying
- Tips to ensure that children are safe while using the internet
- Children, youths should be protected from ‘Wrong’ internet content, says UCC boss
If one word tied the speakers together, it was collaboration. They repeatedly noted that Uganda’s cyber laws, data protection framework and national strategy are, on paper, reasonably solid. Eng. Mugimba noted Uganda was an early mover on the ITU index before the pandemic, but that fragmented implementation, inconsistent reporting, and siloed institutional responses remain the gaps attackers exploit.
ACP. Mubiru closed his remarks by returning to his own metaphor, “We need to begin building some brick walls around a fancy house.”