Cybersecurity

A plain cybersecurity checklist for Ugandan SMEs

By PUCHU Technologies · 24 June 2026 · 8 minute read

You do not need an enterprise security budget to stop the vast majority of what actually hits small and mid-sized businesses in Uganda. Almost every breach we get called in to clean up traces back to one of a handful of ordinary gaps — not a sophisticated attacker, just an open door nobody remembered to close. Here is the order we actually work through with clients, cheapest and highest-impact first.

1. Fix passwords and logins before anything else

Shared logins are the single biggest risk we see. When three staff members use the same "admin" password for the company Gmail, Facebook page and accounting software, one phished employee compromises everything at once — and you can't tell which of them it was. Give every person their own login, everywhere. Turn on two-factor authentication on email, banking and social media accounts today; it is free and it stops the majority of account takeovers outright, even when a password does leak.

Mobile money PINs deserve the same discipline. We've seen agent-facing staff write PINs on the till drawer "just for backup." Treat a mobile money PIN with the same seriousness as a bank vault code, because functionally that's what it is.

2. Keep software and phones updated

Most malware doesn't exploit a secret zero-day — it exploits a patch that was released months ago and never installed. Turn on automatic updates for Windows, Android and any accounting or point-of-sale software you run. If a device is too old to receive security updates at all, budget to replace it; the cost of a breach through an unpatched machine is almost always higher than the device itself.

3. Back up your data — and actually test the restore

A backup that has never been restored is a hope, not a backup. Ransomware and simple hardware failure are both common enough in our climate and power situation that "we'll deal with it if it happens" is not a plan. Keep at least one backup copy off the same premises and off the same network as your main systems, and once a quarter, actually try restoring a file from it. The number of "working" backup systems that fail their first real restore is higher than you'd expect.

4. Train staff to spot the obvious scams first

Fancy phishing simulations are nice, but most SME staff have never had even a five-minute conversation about what a fake invoice email or a fraudulent mobile money agent call looks like. Cover three things: never enter a password after clicking a link in an unexpected email or SMS; verify any change to supplier bank details by phone, on a number you already have, not one in the email; and treat any "urgent, don't tell your manager" instruction as an automatic red flag, since that pressure is the scam's real weapon.

5. Remove access when people leave

A former employee retaining access to the company email, cloud storage or accounting system is a routine finding, not a rare one. Build a simple leaver's checklist — email, shared drives, accounting software, social media, remote access — and run through it on someone's last working day, not whenever someone remembers.

6. Protect the devices data actually lives on

Laptop and phone theft is a real, physical security risk with a digital consequence. Enable full-disk encryption (built into modern Windows, macOS and Android at no cost) so a stolen device is a hardware loss, not also a data breach. Set a screen lock with a real PIN, not a swipe pattern visible from across a room.

If you only do three things this month: turn on two-factor authentication everywhere it's offered, confirm your backups actually restore, and agree a phone-verification rule for any change to bank or payment details.

When it's time to bring someone in

These six steps close the gaps that cause the overwhelming majority of incidents we see. Where it gets harder — handling donor or customer data under a formal compliance requirement, running your own servers, or recovering from an incident already in progress — is where a proper review earns its cost. That's exactly what our cybersecurity service is built around: a plain-language risk assessment, the unglamorous fixes above done properly, and a response plan you can actually follow under pressure.

Want a proper look at where you actually stand?

A short conversation is usually enough to tell you whether you need a full review or just a few of the fixes above.