Across East Africa’s financial services ecosystem, rapid digital acceleration has fundamentally transformed institutional delivery models. From integrated mobile financial services and agent banking networks to real-time gross settlement systems, financial transactions are executed with unprecedented efficiency. However, this expansion has exposed a major operational vulnerability: the velocity of digital transformation has significantly outpaced the development of specialised risk governance talent.
During the premiere episode of BrighterMonday Uganda’s HR Unlocked Series, industry experts examined the structural barriers impeding institutional cyber resilience. Data insights presented by key speaker Jerome Okot, Chief Commercial Officer at Milima Security, alongside national crime reports, underscores the scale of financial exposure facing the sector today.
Quantification of Risk and Sector Vulnerability
The financial impact of threat vectors targeting Ugandan financial institutions has escalated sharply. According to the Uganda Police Annual Crime Report and industry documentation reviewed by New Vision, registered financial cybercrime losses reached approximately UGX 72.1 billion (~$72 million USD) in a single annual cycle, with recovery rates stagnating below 1%.
“2024 showed that financial institutions lost up to 72 billion shillings to cybercrime… Out of that, only about 700 million shillings was recovered. Banks are losing massively…because there are significant gaps in cybersecurity staffing in most of these financial institutions.” — Jerome Okot, CCO, Milima Security
This observation aligns with global benchmarking metrics. The International Monetary Fund (IMF) Financial Stability Report notes that the financial sector experiences nearly triple the rate of cyberattacks compared to any other global industry, with extreme concentration in developing financial systems where regulatory compliance enforcement faces human resource constraints.
Executive Governance Deficits and the Internal Labor Market
The financial services workforce in Uganda exhibits steady macro growth, yet it remains characterized by an acute skills gap:
- 350,000+ Total Sector Labor Force: Encompassing commercial banks, microfinance deposit-taking institutions (MDIs), Tier 4 SACCOs, mobile money operators, and fintech enterprises.
- 12,000+ Annual New Positions: Sustained expansion across retail and digital channels.
- 2.9% Compound Annual Growth Rate: Steady structural footprint growth between 2019 and 2025.
Despite this labor force inflow, executive cybersecurity leadership remains disproportionately sparse. Out of 34 commercial banking institutions operating under the regulatory oversight of the Bank of Uganda (BoU), only 7 institutions maintain a dedicated Chief Information Security Officer (CISO).
Jerome Okot highlighted how this structural gap directly undermines risk strategy:
Its very easy for certain decisions to be made erroneously, or for some strategies to be overlooked, or budget allocations not to be met because there is this whole perception that cybersecurity is expensive… In some cases, the head of IT is just doubling as a cybersecurity guy, or someone who is doing IT support is also doing cybersecurity work. — Jerome Okot, CCO, Milima Security
This staffing dynamic creates an operational conflict of interest. When general IT administrators manage security functions, the teams responsible for infrastructure deployment are tasked with auditing their own systems for vulnerabilities—violating core tenets of the Bank of Uganda Cyber Risk Management Guidelines.
Market Dynamics: The Modern Cybersecurity Labor Market
The cybersecurity talent market in Uganda and across sub-Saharan Africa is affected by two primary market realities:
- Global Remote Talent Poaching: Senior cyber talent based in Kampala is increasingly recruited by multinational organizations offering foreign-denominated remote compensation. This dynamic makes lateral recruitment prohibitively expensive for domestic tier-2 banks, SACCOs, and local microfinance firms.
- The Entry Barrier Misconception: While entry-level technology graduates enter the labor market annually, many lack practical, lab-based threat mitigation experience, leaving them stuck in general IT support functions.
Reflecting on how small-to-medium financial institutions and SACCOs can navigate these market dynamics without overextending operational budgets, Okot emphasized:
“You can look inwardly… What some SACCOs have done is they’ve gotten IT guys to upskill in cybersecurity. Once they are good enough, they make them the head of information security, and then the junior guy comes up and continues doing the IT work. Build your talent internally… or partner with institutions that are training this talent. Go upstream so it’s easy for you to obtain talent without competing with existing, very expensive talent.”
Strategic Human Resource Development Framework
To achieve sustainable cyber resilience, executive boards and HR leaders must move beyond transactional recruitment toward structured talent development:
1. Institutional Upskilling Tracks (IT-to-Cyber Transition)
Organizations should establish formal 6-to-18-month capability transition frameworks. General IT staff already possess institutional knowledge regarding core banking systems, operational workflows, and access controls. Sponsoring their enrollment in hands-on certifications through academies like Milima Cyber Academy builds specialized expertise while retaining institutional context.
2. Upstream Academic and Institutional Partnerships
HR departments must build direct pipelines with specialized technical academies and universities. Securing early talent acquisition agreements allows banks to onboard certified entry-level threat analysts before they enter competitive open-market bidding wars.
3. Formal Separation of IT and Security Functions
In accordance with central bank guidelines, financial institutions must separate information security governance from routine IT support operations. Establishing clear CISO reporting lines directly to executive board risk committees ensures security budgets are evaluated based on risk mitigation rather than departmental overhead.
Building Capable Teams with BrighterMonday Uganda
Securing financial infrastructure requires deliberate human capital strategy. Whether your institution is structuring executive search for dedicated CISO roles, benchmarking technical compensation bands, or scaling institutional recruitment pipelines, BrighterMonday Uganda delivers data-backed recruitment solutions tailored for the financial services sector.
Join Our Upcoming Sector Events & Webinars
Want to participate in future industry roundtables or stay informed about upcoming executive events? Email our team directly at marketing@brightermonday.co.ug to be added to our priority guest list.
Related BrighterMonday Uganda Resources
- Employer Solutions: BrighterMonday Employer Portal & Talent Sourcing Services
- Workplace Insights: Employer Corner & Talent Acquisition Strategy Articles



