It began, as most disasters do, with silence. A mid-sized local bank’s board meeting ended early that day. The CEO had told the board that “IT reported having fully patched the system,” and everyone nodded, relieved. No one asked which system or what was patched.

Weeks later, the same board would hold an emergency session after a ransomware attack froze all accounts for 36 hours. The problem wasn’t the hacker. It was the silence in that room.

Boards often treat cybersecurity as an operational nuisance; a line item, a compliance checkbox, something the “tech guys” handle. But governance, not gadgets, defines resilience. The first breach always happens in the boardroom when leaders choose comfort over comprehension.

If you sit on a board and cannot explain the difference between a vulnerability and a threat vector, you are the threat vector.

The illusion of control

Many Ugandan banks have state-of-the-art firewalls, intrusion detection systems, and shiny new SOC dashboards; yet remain dangerously exposed. Why? Because they mistake technology for security.

A hacker’s best ally is a confident board that believes “we’re covered.” Spending on cybersecurity is not the same as managing cyber risk. The board’s job is to ask, “How does this control protect our business model?” not “How much did we spend?”

In one case I investigated, the fraudster didn’t exploit a software flaw. He exploited overconfidence. He used a legitimate API connection, authorized, logged, and “secure”, to siphon funds to mobile wallets. It wasn’t a hack. It was a handshake gone wrong.

Oversight without understanding is an illusion of control, the most profitable condition for an attacker.

When governance becomes a loophole

Many local corporate charters are full of noble words: “oversight,” “fiduciary duty,” “risk governance.” Yet, when breaches occur, those same boards suddenly “refer to management.” That is abdication dressed as delegation.

Cyber risk is not a technical domain. It’s an ethical one. Who owns the risk when an insider misuses access? When does a vendor leak client data? When does a customer’s trust evaporate overnight? If the answer is still “the IT department,” governance has already failed.

At Summit Consulting Ltd, our investigations reveal the same pattern: unclear accountability, no cyber reporting lines to the CEO, and a CISO who must “route” concerns through operations. The result is predictable: late detection, poor response, and a costly cover-up.

If your CISO cannot access the board directly, your cyber defense is cosmetic.

How hackers exploit leadership delay

Hackers move in seconds. Boards move in quarters.

During one simulated ransomware drill we conducted for a financial institution, the “board” took 27 minutes to approve an emergency response. The attacker’s timer expired at 10. Decision delay is the new vulnerability.

Every escalation layer is a hacker’s oxygen tank. The longer you deliberate, the more they download. Yet many boards still debate “public relations strategy” while systems are under siege.

In this new world, your speed of governance determines your survivability. That means: pre-authorized incident playbooks, delegated powers for rapid decisions, and a board that knows when not to wait for “confirmation.”

Because in cyber warfare, waiting for certainty guarantees loss.

The anatomy of a silent breach

Suspect 1 was a systems administrator. Well respected. Always “helping” after hours. His midnight logins were logged as normal because he had legitimate credentials. Over three months, he exfiltrated data in 27-megabyte chunks to a cloud account linked to a friend’s phone number.

No alarms went off. Nothing looked abnormal. When we were called in, the audit logs told a chilling story: 136 logins. All authorized. All unnoticed.

This is the anatomy of modern breaches; they don’t break doors; they borrow keys. They rely on trust, fatigue, and a lack of curiosity.

Boards must ask: “How would we know if someone inside is quietly stealing our data?” If your only answer is “the IT team will alert us,” you’ve already been breached; you just haven’t discovered it yet.

The human firewall is underfunded

Every bank runs an annual cybersecurity awareness session; usually a PowerPoint marathon where employees click “next” until they see the certificate of completion. Meanwhile, the same staff reuse passwords across MoMo, Gmail, and work systems.

Humans are the final firewall, and the least funded one. To borrow the popular strategy adage attributed to M. Porter, “Culture eats cybersecurity policy for breakfast.

” If people fear reporting mistakes, they will hide incidents. If leaders laugh at “IT rules,” others will follow. The real defense lies in rewarding safe behavior, not punishing errors.

Training must become muscle memory; brief, frequent, scenario-based. Ask every teller, driver, and secretary, “How would you detect a phishing attempt?” If they can’t answer, the organization is still naked.

How mobile money and shadow IT magnify risk

Our banking innovation story is both inspiring and dangerous. The rise of mobile money, fintech integrations, and digital lending has outpaced governance.

Employees often link personal phones to internal systems for “quick MoMo transactions.” Vendors integrate APIs without rigorous third-party vetting. A single token leak can open a backdoor into the core banking system.

One of our investigations traced a UGX 940 million fraud to a staff member who had synced their office credentials with a third-party MoMo reconciliation app. The hacker didn’t need brute force; he simply bought the app’s source code online.

The lesson? Innovation without control is chaos disguised as progress.

The myth of the cyber insurance parachute

Some directors believe cyber insurance is a parachute. It’s not. It’s a first-aid kit after a plane crash.

Most policies exclude social engineering, insider abuse, and third-party negligence; the very causes of most breaches. And even when they pay, no insurer can restore lost reputation or public trust.

When your customers queue outside branches demanding answers, you cannot hand them your policy document.

Cyber insurance is a complement, not a substitute, for competence. The true protection is proactive governance; a board that reads, questions, and prepares.

The Summit Consulting investigation lesson

In 2023, Summit Consulting investigated a breach at a mid-tier bank where an auditor shared a password with a finance officer “for convenience.” The officer was later compromised through a fake payroll approval link. Within hours, the fraudsters moved UGX 1.8 billion through accounts disguised as vendors.

The fix? The bank introduced multi-factor authentication and password vaults. But the real breakthrough came later, when the board established a dedicated Cyber Risk Committee.

From that moment, the tone changed. Cyber ceased being a footnote and became a standing agenda item. Awareness became policy. Ignorance lost its seat.

From ignorance to intelligence

Cybersecurity is no longer a back-office function. It’s a boardroom mindset.

The directors of tomorrow will need fluency in cyber risk the same way yesterday’s directors mastered finance. Data is now capital. Digital trust is the new credit rating.

So, here’s the test: if your next board meeting doesn’t include a discussion about threat intelligence, third-party risk, and incident simulation, you are running an analog board in a digital war.

The future belongs to boards that learn faster than hackers adapt.

Because in Uganda’s banking boardrooms, the most dangerous malware isn’t in your systems. It’s in your assumptions.