In 2021, a SACCO in Eastern Uganda watched UGX 421 million vanish in 36 hours. No broken doors. No masked robbers. Just silence, and a blinking server light in the back office that no one had checked in weeks. Their audit committee didn’t know the firewall hadn’t been updated in 18 months. The IT officer, also the cashier, never changed the router password. “admin123”. When they finally reported the incident, the board chair asked, “Who is responsible for cybersecurity in this organisation?” That, right there, was the real breach.
The real threat is at the top
In most SACCOs, cybersecurity is treated like broken furniture, out of sight, out of mind, until someone gets hurt. Boards assume it’s an IT issue. It’s not. It’s a strategy, governance, and continuity issue. A failure to understand this is why you’re seeing headline-making breaches. Not because hackers are too smart, but because boards are asleep at the wheel.
Cybersecurity is not about firewalls. It’s about foresight. About asking the hard questions:
a) What are our digital assets?
b) Who has access, and how is that access monitored?
c) What is the board’s policy on cyber incident disclosure?
You wouldn’t let your cashier approve loans without limits, but you’ve given a single IT intern root access to all your systems, no logs, no alerts, no backups. That’s not naivety. That’s negligence.
"Bring cybersecurity from the basement to the boardroom. Until you do, your biggest risk isn’t the hacker in Russia, it’s the silence in your boardroom.”
Tweet
The SACCO’s invisible war
That same SACCO had just spent UGX 150 million on a new loan management system. Yet no one asked where it was hosted, who configured it, or what penetration testing was done. When the attackers hit, they didn’t need to breach a firewall. They logged in using dormant accounts of former staff whose emails were still active.
The board had reviewed credit risk, liquidity ratios, and delinquency metrics. Yet, they had no clue where their data was, who could access it remotely, or whether the system had multi-factor authentication. Cyber risk wasn’t even on the board agenda.
The 6Q board cyber audit
Ask these six questions in every board meeting:
- Do we have a cyber incident response plan tested in the last 12 months?
- Who owns cybersecurity at the board level?
- Are we insured for cyber breaches? What’s covered?
- How often are staff trained on phishing and social engineering?
- What’s our recovery time if core systems are wiped out?
- Who audits our third-party tech vendors?
If the CEO or the IT head cannot answer these questions clearly, your SACCO is living on borrowed time.
Many boards are scared of tech, so they avoid it. That’s no excuse. As a leader, your job is not to code, but to comprehend. To challenge. To demand clarity. You don’t need to be a techie to ask why backups aren’t tested or to require quarterly cyber risk dashboards.
Bring cybersecurity from the basement to the boardroom. Until you do, your biggest risk isn’t the hacker in Russia, it’s the silence in your boardroom.
