A 2025 PwC report placed knowledge and skills gaps among the top challenges organisations face when implementing AI for cyber defence. Mpesa Africa’s head of cybersecurity Tim Theuri, Ecobank Uganda’s head of IT Juliet Kyomugisha and WASREB’s head of IT Brenda Anzagi weigh in on the challenge of finding talent in IT.
Tim Theuri, Mpesa Africa's head of cybersecurity, knows firsthand how difficult it is to get the right talent in cybersecurity.
"There's a role I've been recruiting for six months. We get someone who is either not suitable, declines the role, or wants more money because of how lucrative cybersecurity is. There's another role that took us almost a year to fill. It was for our digital apps security and you have to be an expert in Android and iOS security. Unfortunately, there are very few experts in that area which is why it took that long,” he says.
Tim notes that organisations can always train people internally, but the approach has limits.
"We have graduate recruitment for graduates, those who are learning. But for certain key roles, you need someone who's experienced. Sometimes you also need someone who will assume a specific role immediately,” he says.
Even when training works, it doesn't always pay off. Tim observes that organisations often train people who then move on once they've gained the expertise, forcing the company to start the hiring and training cycle all over again, a time-consuming process with no guaranteed return.
Tim isn't the only one seeing this play out. Juliet Kyomugisha, head of IT at Ecobank Uganda, has observed the same problem in the banking industry.
"There's a new regulation from our central bank requesting that our board members be trained in cybersecurity, and that we have at least one IT person who understands cybersecurity to advise the board accordingly. There must have been a gap, otherwise this wouldn't have come up as a guideline,” she says.
Juliet believes that the new regulation has exposed the existing shortages in the labour market.
“With the central bank requiring each bank to have at least a chief information security officer (CISO) or a security head who is separate from technology, I think that has caused a bit of a shortage too, because CISOs are now in high demand and you find there are few in the market."
The talent that won't stay put
Beyond the difficulty of hiring, Juliet also notes that there's a problem of retention where skilled cybersecurity professionals tend not to stay in one place for long.
"You get guys who get to head of cyber, and then they move to another bank. They are always moving. You never find a time where you are just comfortable, because there is always somebody about to leave after you've kept them well. Their talent is unique, so they keep moving to get the best opportunities elsewhere," she says.
Even for those who stay, there is still a challenge of staying relevant amidst changes in the industry. Brenda Anzagi, head of IT at WASREB, advocates for constant upskilling as part of the answer.
"I am beginning to realise the importance of having people who are motivated and want to upskill themselves,” she says, adding that she acquired most of the skills she uses today while on the job.
“If you don't have that, you find yourself playing catch-up, which is not good. You're supposed to be ahead, especially when you're talking about issues of security," she says.





