Uganda’s inaugural National Cybersecurity Conference held last week at the Sheraton Kampala Hotel drew policymakers, regulators, cybersecurity agencies, telecom operators, banks, technology firms, academics, and civil society groups under the theme “Securing Uganda’s Digital Future: Collaboration, Resilience and Trust.”
The two-day conference, organised by the Uganda Communications Commission (UCC) in partnership with the Ministry of ICT and National Guidance, saw delegates explore how to protect Uganda’s fast-growing digital economy and preserve public confidence in the systems and services that increasingly shape everyday life.
Opening the conference, UCC Executive Director George William Nyombi Thembo argued that cybersecurity cannot be an afterthought bolted onto digital systems once they are built. “Cybersecurity must not be something we add to digital transformation after the infrastructure has been built; it must be part of the infrastructure itself. Actually, it must be a culture,” he said.

Thembo cited UCC’s latest communications-sector cybersecurity posture report, which he said painted a mixed picture: reported malware infections declined from roughly 1.59 million in 2024 to 1.41 million in 2025, but the sector’s overall security rating remained in the “basic security” category, signalling continued elevated risk. Mobile malware, ransomware, denial-of-service attacks, vulnerable web infrastructure and increasingly sophisticated phishing and impersonation, including attacks that exploit artificial intelligence, remain persistent problems, he said.
“These threats are real,” Thembo said. “The question before us, therefore, is how do we ensure that the defenders stay ahead of the threat? The answer is in one word: collaboration.” Cyber criminals, he added, do not respect institutional lines. “The cyber criminal does not stop to consider which government agency has jurisdiction before launching an attack. A fraudster does not care whether a transaction crosses a telecommunication network, a bank, a fintech platform or a cloud service. Ransomware does not respect institutional boundaries.”
He pointed to the Uganda Computer Emergency Response Team (UG-CERT), established in 2013, which provides threat intelligence, indicators of compromise, and digital forensics support to licensed operators, alongside the CyberSTARS programme for developing young cybersecurity talent and the newly issued minimum cybersecurity guidelines for licensed operators.
Compliance with those guidelines, he stressed, “should not be a box-ticking exercise, but rather an expression of commitment to risk management, customer trust, business continuity and national security.”
Thembo asked delegates to focus the conference on five practical areas: faster threat-information sharing, stronger national incident coordination, better cybersecurity governance and accountability, greater investment in local skills, and keeping consumers at the centre of every decision.
“A connected Uganda must also be a secure Uganda,” he said, referencing UCC’s “Connected Uganda 2030” tagline. “That security cannot be built by one regulator, one ministry, one telecom company. We must build together.”
In a keynote address, Bank of Uganda Governor Dr. Michael Atingi-Ego made an economic case for cybersecurity, arguing that public trust in digital systems is a measurable asset rather than a soft concept.
“Trust is not an intangible. It has economic value,” he said. “It’s why a citizen adopts a digital public service, why a business commits capital to a digital platform, why an investor backs our markets with confidence rather than caution.” Once lost, he warned, trust is far costlier to rebuild than to protect in the first place, which is why safeguarding it, in his view, “is not a defensive expense” but “an investment in the credibility of our entire digital economy.”
Atingi-Ego rejected the idea that Uganda must trade off security against innovation. “The real choice is between innovation that is trusted and innovation that is fragile,” he said, “between growth that compounds over years and growth that can be halted by a single avoidable shock.” His guiding principle for delegates was blunt: “Build security in. Do not bolt it on.” Whether the country is building a payments platform, a digital identity system or deploying artificial intelligence in public services, he said, security and responsible governance belong in the design from day one, “not the review that follows after something has gone wrong.”

He proposed that the conference’s most useful outcome would be a shared national compact built on three commitments: not letting institutional boundaries become gaps through which risk travels, judging national preparedness by the ability to withstand, recover from & learn from incidents rather than by the ability to prevent every one, and measuring digital transformation by whether Ugandans trust it enough to build their futures on it.
Responsibility for that compact, he said, starts at the top. “Cybersecurity is no longer solely the responsibility of ICT departments,” Atingi-Ego said. “It is a boardroom issue, an executive leadership responsibility, and increasingly a matter of national policy.”
He closed his keynote by congratulating UCC and its partners for convening the conference.
The State Minister for the Ministry of ICT and National Guidance, Hon. Joyce Nabbosa Ssebugwawo, later declared the inaugural National Cybersecurity Conference open, stating that cybersecurity has outgrown its old identity as a purely technical concern.
“Not long ago, cybersecurity was largely regarded as a technical issue, something for ICT departments and system administrators to worry about. Today that has changed,” she said. “Across the world, cybersecurity has moved into the boardrooms, the cabinet room, and increasingly the political arena,” she added, pointing to global examples of elections targeted by cyberattacks, data hacking and disinformation as evidence that digital security now extends to election systems, political party databases and media platforms.
The State Minister also stated that “Cybersecurity is no longer simply about protecting computers; it is about protecting institutions, economies, election management systems, political party databases, media platforms, and national security.”

Hon. Ssebugwawo called on banks, telecom companies, government agencies, and private businesses running critical infrastructure to share threat information faster and hold joint training, cautioning that “the Ministry of ICT and National Guidance cannot secure Uganda alone,” just as UCC and the country’s security agencies cannot do it by themselves.
“As a government, we remain committed to creating the right policies, rules, and support to protect Uganda online,” she said. “However, everyone else must also do their part to keep the country safe.”
She later declared the conference open, which will be held annually.