Ecobank Uganda's Juliet Kyomugisha tackles data governance and cybersecurity

post-title

As head of technology services at Ecobank Uganda, Juliet Kyomugisha is at the forefront of the bank's digital transformation and cybersecurity efforts. She oversees technology projects, strengthens governance frameworks, and helps the bank stay ahead of evolving cyber threats. She shares how Ecobank leverages data, manages cybersecurity risks, and balances innovation with security.

There is so much data in the bank. How do you ensure that data is useful?

We have developed a number of dashboards that help business teams make informed decisions. For example, we monitor ATM usage to understand transaction volumes, values, and overall performance. This information helps finance teams assess the cost-benefit of certain systems and investments.

We also use data extensively for regulatory reporting, operational monitoring, and service management. Our monitoring tools provide insights that guide decisions on whether services should be upgraded, maintained, or discontinued. In addition, data from our IT service desk helps us identify the root causes of recurring issues and improve service delivery.

Who is responsible for the data in an organisation?

Data management is a shared responsibility. Before any regulatory information is submitted, the executive team must review and understand it. Ultimately, the managing director is accountable for ensuring that the organisation submits accurate information to regulators. At the same time, every department that generates, uses, or manages data is responsible for its accuracy and integrity. It is a collective effort across the organisation.

What are the biggest technology and cybersecurity risks that banks are facing today?

One of the biggest risks comes from third-party providers because organisations have limited visibility and control over what happens within their partners' environments. Banks must therefore put in place strong controls to protect themselves from potential threats that may originate from integrated partners and service providers.

Another major risk involves users. While people are often the first line of defense, they can also be a point of vulnerability. This is why we invest heavily in ongoing cybersecurity awareness training. We also promote accountability by conducting periodic simulations and spot checks, such as sending phishing-style links, to help staff recognise potential threats and strengthen their security awareness.

How has AI changed the risk landscape? Do you feel it is also contributing to some of these threats?

Yes, particularly from a data protection perspective. Many AI tools are publicly available, and organisations cannot always control what information users may upload or share with those platforms.

In my view, one of the biggest risks associated with AI is data leakage. Employees may unintentionally expose sensitive company information when using AI tools without understanding where that data is stored, processed, or shared. As organisations adopt AI, it becomes increasingly important to establish clear governance and usage guidelines.

How do you balance innovation while ensuring proper security?

The key is to start every innovation initiative with security in mind. Security should not be an afterthought.

For any new project, technology and security teams should be involved from the beginning because they are often able to identify risks that may not be immediately visible to business teams. When security considerations are addressed early, organisations can design appropriate controls and mitigations without slowing innovation. No system is completely risk-free, but identifying risks early makes it much easier to manage them effectively while still achieving business objectives.

What processes have you put in place for incident response?

While I have not personally experienced a major cybersecurity incident, it is important for every organisation to have a clearly defined incident response team and process in place.

When an incident occurs, the first priority is to quickly identify the source and contain the threat. Depending on the nature of the incident, this may involve isolating affected systems, temporarily shutting down services, or implementing other containment measures. If the issue relates to physical security, the relevant physical security teams must also be engaged. Effective incident response depends on having the right people, processes, and communication channels in place to respond quickly and minimize impact.

 

Related articles

How AI is arming cybercriminals, according to four tech leaders

AI has not only made work easier for organisations, but it has also added a layer of complexity when dealing with cybersecurity. Across different conversations, Jacqueline Madara, head of ICT at Machakos University, Yuki Ouchi, head of digital products and e-commerce at KFC Kenya, James Kwezi, digital transformation manager at AFR Rwanda, and Alex Siboe Wekunda, CIO at Stanbic Bank Kenya, weigh in on how AI is reshaping the threat on the other side of the firewall.

Erick Ngwiri unpacks why organisations get data wrong 

Erick Ngwiri has spent 17 years helping organizations turn complex, scattered information into decisions they can act on. Within that time he has seen why most organisations still get data wrong, and what it takes to fix it, one clear problem at a time. 

How Adili Group's CISO Kiprono Rugut builds digital trust

When it comes to information security, Kiprono Rugut brings both technical depth and business perspective. His more than two-decade career spans financial technology and legal-sector advisory work before cyber investigations brought him to his current role at Adili Group, where he is chief information security officer (CISO).

Clearer data governance frameworks dominate discussions at CITO Summit

When Ecobank Uganda's Juliet Kyomugisha, Nation Media Group's Russell Akuom and AAR Hospital's Ibrahim Juma took to the stage at the CITO East Africa Data and Cybersecurity Summit to report back from the roundtable sessions, the consistent message was that implementation is the hard part of data governance.

CIOs tackle governance and cyber resilience at CITO Summit 

As CIOS weighed in on topics of data access, governance, cyber security and cyber resilience at the CITO East Africa Data and Cyber Security Summit held at Villa Rosa Kempinski Nairobi, it was apparent that human actors have a bigger role to play than the tech. 

Tech leaders explain why people are cybersecurity's weakest link

Cybersecurity remains one of the biggest challenges that tech leaders grapple with on a daily basis. While companies continue to invest in technology to make their systems robust, Bank of Kigali’s CIO Eveque Mutabaruka, Del Monte’s head of IT Kennedy Njenga and Nairobi Water’s head of IT Jimmy Thuo believe that none of this counts for much if the person sitting behind the keyboard does not understand the risks they are exposed to every single day.

Eveque Mutabaruka leads the transformation in African banking

Bank of Kigali’s CIO Eveque Mutabaruka has built his entire career by stewarding transformation programs in different financial institutions, from Rwanda to Botswana and Kenya. In every program, his leadership philosophy is simple: empower first then follow up.

AFR’s digital transformation manager James Kwezi builds cyber resilience in Rwanda

James Kwezi is on a mission to do more than digitalise; he is securing the future of finance in Rwanda. As digital transformation manager at AFR, he is driving responsible innovation, building cyber resilience and leading the charge on ethical AI. He shares how strategy, vigilance and vision are shaping the next chapter of digital development.

Top