Peter Ojekunle took a risk, leaving PwC Nigeria for PwC Uganda at a time when the market was still young. After close to a decade in East Africa, Peter believes that companies must build risk-aware capabilities to survive ever increasing pervasive IT and security risks in the region.
When Peter Ojekunle was offered the chance to move from PwC Nigeria to PwC Uganda, it seemed counterintuitive at first. The Nigeria office had over 1,000 people and a client base that had been commissioning serious IT risk work for years. Uganda, at the time, had around 180. But he moved without hesitation, because the size of the challenge was precisely the point.
"I also sensed that the market from an East Africa perspective may not have been as mature as what we have in the west, and typically with those kinds of circumstances it means a lot of demand in terms of stretching yourself in improving your business acumen to be able to unlock the opportunities to serve a variety of client base," he says.
Leaving the comfort zone
Peter had built his foundation at PwC Nigeria after graduating with a degree in electrical and computer engineering, specialising in information technology. Before the PwC opportunity arrived, he had on his own initiative completed training in risk management without a clear plan for how it would be used. When the graduate trainee role in risk assurance appeared, the two disciplines clicked into place.
"Once the opportunity from PwC came to sign up and apply for an opportunity as a graduate trainee in risk assurance, it was an easy pick because I saw the intersection between the trainings I had acquired from my degree in information technology as well as the trainings that I had done on risk management and it was just a perfect blend to aspire to then develop a career in IT risk assurance," he says.
He has now spent more than thirteen years building that combination into one of PwC Uganda's core practices, advising clients across the region on how to manage the risks that come with putting critical operations online. The move to Uganda demanded more of Peter than the Lagos years had.
"It was an opportunity to step out of my comfort zone. In the Nigeria office we had a lot going already, we had a lot of support systems, but I did not anticipate that I was going to have that in Uganda, and it was an opportunity to stretch myself leaps and bounds and increase my capacity as far as my technical competencies were concerned," he says.
What keeps Peter engaged after more than a decade is that each client brings a problem he has not solved in quite that form before. A bank in Kampala and a manufacturer in Nairobi may both ask for a cyber maturity assessment but the decisions that created the gaps and the people responsible for fixing them will be different every time.
"The absence of the monotony, which I might have had to deal with if I was probably in the industry working for a particular entity, is really what excites me. The challenge that I've got to deal with from one engagement or one project after the next is really the most exciting aspect," he says.

Beyond compliance
One of the patterns Peter has observed most consistently is what happens when a major system goes live without adequate change management behind it. Transactions that should trigger alerts pass through because the controls were never tuned to the new environment.
"I have served a number of clients where the significant fraud that occurred happened at the point of transition from a legacy system to a new system, simply because the governance and the change management around that transition was not effective," he says.
In East Africa, regulators have mandated periodic ICT audits in the major sectors. But the practice, Peter argues, has settled into something closer to paperwork. Institutions treat the exercise as a box to tick before the regulator's deadline.
"Most institutions have begun to see it as a compliance exercise. The moment such a critical exercise is looked at from the perspective of compliance, there is a significant risk that it could be executed as a tickbox exercise," he says.
The exercise Peter advocates in its place is a maturity assessment. This is a benchmarking of an institution against known standards and against its peers across domains including governance and cyber security. It shows where an institution sits on a spectrum and what it would take to move further along it. The question it asks is harder than whether the minimum has been met, and the answer it produces is considerably more useful.
Building risk-aware capabilities
As Peter sees it, the direction of travel in East Africa is clear. Rapid digitisation across both the private and public sectors is expanding the technology footprint of institutions, while the growing adoption of advanced technologies such as AI is introducing new layers of complexity. As a result, the cyber threat landscape is evolving just as quickly, with institutions becoming increasingly exposed to more sophisticated and pervasive IT and security risks at every stage of their digital journey.
"The focus must shift away from simply meeting minimum regulatory requirements to building real, risk-aware capability. Organisations need to invest in the right skills, define meaningful and practical AI use cases, establish robust governance frameworks, and take a structured approach to managing technology and cyber risk as they advance their transformation journey," he says.





