Rwanda's top technology executives gathered in Kigali for the country's first CITO East Africa Summit, and the conversation they had was candid and built on a simple premise: the problems IT leaders face in isolation are better solved in company.
Close to 40 CIOs, heads of IT and chief technology officers from across the country sat around a table under the Chatham House rule and spoke plainly. Three themes dominated the evening.
The most pressing issue to surface was structural, with Rwanda's IT leaders recognising their organisations' vulnerability to attack, several in the room had experienced phishing incidents firsthand. What they described as the deeper problem is that when attacks happen, the information stays locked inside the affected institution, shared quietly, if at all, rather than communicated in a way that allows others to prepare.

Security gaps
“When it comes to cyber security, I think it's important that we learn to work together. You might know why an attack happened, or you have better tools to do the analysis and dig deeper, and some other people don't have any clue what happened. That is one of the biggest problems that we are facing,” one executive said.
The point drew immediate recognition around the table. CIOs noted how Rwanda does not yet have a widely accessible security operations centre (SOC) for the private sector, and establishing one costs upwards of three to four million dollars, with annual software licensing on top of that, figures that price out most of the organisations in the room.
“The Central Bank has begun offering a shared SOC facility to financial institutions at reduced cost, and Rwanda National Police operates its own, but the majority of companies remain exposed. Disaster recovery sites present a similar gap, most that exist are located within Kigali rather than at a distance that would provide meaningful protection in a major incident,” another IT leader observed.
The conversation kept returning to awareness as the variable that mattered most.
“Information security is not only left to IT, it is the responsibility of everyone in the organisation. You really have to drive that change of mindsets among employees so that whatever they do, anything they do, they have to have that mindset of protecting assets,” a tech leader said.
One CIO described running monthly internal phishing simulation campaigns, mandatory online security courses tied to performance appraisals, and a dedicated cybersecurity awareness month with prize incentives. Even with that investment, they acknowledged that sophisticated tools still cannot close the gap entirely, 30 to 40 percent of leakage risk, they estimated, would always run through human behaviour.
Talent constraints
Alongside security, the skills gap generated the most sustained discussion. Rwanda's technology sector is growing, and the demand for skilled professionals is outpacing the supply. For leaders who came to Rwanda from Nigeria, Kenya, India or Europe, the contrast with larger markets was sharp.
“Skill is one of the hardest challenges. When your board of directors is telling your CEO to move faster, and the CEO is telling you to move faster, and then I'm looking at my CEO like, sorry, do you see the tools you have given me to move faster? It is not very easy," one participant noted.
The CIOs observed that the issue is not unwillingness but pipeline. Training centres exist but are still few, and those that do operate tend toward theory over practice. For specialist areas like cybersecurity, the historical path ran through studying abroad, an option that has never been broadly accessible.
Leaders also raised a structural challenge that sits above hiring, the tendency for management to treat the head of IT as a single point of all technical knowledge and to resist requests to bring in specialist staff.
“When I ask to hire a security officer, they ask me, can't the network person handle this? When you had to get knowledge about security, you had to go abroad, locally, we had nothing,” another attendee said.
One voice pushed back with a different observation, that Rwanda holds significant volumes of data across sectors, but the capacity to draw insight and build product from that data is underdeveloped.

Opportunity and pace
The challenge, they argued, is about building the analytical layer that turns infrastructure into innovation rather than hiring engineers.
Not everything raised over dinner was a problem. Several participants described Rwanda's current stage of development as the defining advantage of working there rather than in more mature markets.
“The possibilities are enormous. It is at a very privileged position of almost skipping some of the challenges that other parts of the world have faced and leapfrogging them in terms of technology. For someone who wants to look at innovation and try to solve real issues, that is the biggest advantage,” one leader said.
What struck several in the room was the speed at which individuals are translating ideas into working products. One participant described encountering a young developer who had built a USSD-based payment tool for motorcycle taxi drivers, which was simple, functional and addressed a real need. The solution had moved from concept to live product rapidly.
“The country's leadership understands technology at a level that creates a different environment for IT leaders than they had experienced elsewhere. That understanding does not resolve the budget battles, the talent constraints or the infrastructure gaps. But it creates a foundation,” multiple participants noted.
The summit ended with a commitment to reconvene.
“The value was not in the agenda. It was in being in a room with people who understood the problems without needing them explained,” several participants said independently.





