Kampala, Uganda | 15 July 2026 – The Minister of ICT and National Guidance, Rt. Hon. Justine Kasule Lumumba, has today officially launched the Updated National Information Security Framework (NISF) 2026, reaffirming Government's commitment to strengthening cybersecurity and building a secure, resilient, and trusted digital Uganda.
The launch, held at Four Points by Sheraton Kampala, brought together government representatives from Ministries, Departments, Agencies and cybersecurity stakeholders. The event was hosted by the National Information Technology Authority–Uganda (NITA-U) under the Uganda Digital Acceleration Project – Government Network (UDAP-GovNet).
In her remarks, the Minister emphasized that information security has become a national development imperative.
"Information security is no longer just a technical matter for ICT officers. It is now a matter of national security, economic development, public service delivery, and public trust," Rt. Hon. Lumumba said.
She noted that as Government increasingly delivers services through digital platforms, safeguarding information systems and protecting citizens' data must remain a national priority.
The Minister observed that the original National Information Security Framework, developed by NITA-U in 2014 under the National Information Security Strategy, was endorsed through Presidential Security Directive No. 1 of 2014, providing Government institutions with a common approach to managing information security risks.
Recognizing the significant changes in technology and the evolving cyber threat landscape over the past decade, she said the updated Framework equips institutions with practical guidance to strengthen cybersecurity governance, conduct security assessments, implement baseline security controls, and build resilience against emerging threats.
"Cybersecurity must begin with leadership. Accounting Officers, Boards and senior managers must understand that information security risks are institutional risks. A serious cyber incident can disrupt service delivery, lead to financial losses and erode public trust," she said.
The Minister called upon all Ministries, Departments and Agencies (MDAs) to work closely with NITA-U in implementing the Framework, conducting regular cybersecurity assessments, addressing identified vulnerabilities, and strengthening institutional cybersecurity capabilities.
She also urged private sector organisations operating critical infrastructure; including those in banking, telecommunications, energy, transport and health to collaborate with Government in protecting Uganda's interconnected digital ecosystem.
Speaking at the launch, Dr. Hatwib Mugasa, Executive Director of NITA-U, said the updated Framework represents an important milestone in Uganda's cybersecurity journey and reflects the country's commitment to keeping pace with an increasingly complex digital environment.
Dr. Mugasa noted that NITA-U, established under the NITA-U Act of 2009, has continued to coordinate secure digital transformation across Government, building on the foundation laid by the National Information Security Strategy of 2011 and the original Framework launched in 2014.
"The updated National Information Security Framework is not just another policy document. It is a practical guide that reflects today's threat landscape, aligns Uganda with current international best practices, and provides institutions with the tools they need to assess their cybersecurity maturity and strengthen their resilience," he said.
He observed that while Government has made significant progress in raising awareness of information security and establishing national standards, many institutions remain at the awareness stage rather than full implementation of minimum cybersecurity controls.
"Our next task is to move from awareness to measurable implementation. Through the updated Framework and its accompanying toolkit, we are committed to helping Ministries, Departments and Agencies strengthen compliance and build genuine resilience against current and emerging cyber threats," Dr. Mugasa added.
The Executive Director further highlighted that the Framework is anchored on seven guiding principles: leadership accountability, collective responsibility, individual responsibility, risk management, secure information sharing, trusted personnel, and organisational resilience. These principles, he said, provide the foundation for strengthening cybersecurity governance across Government.
He reaffirmed NITA-U's commitment to coordinating implementation of the Framework, monitoring compliance, providing technical support to MDAs, and working with stakeholders to safeguard Uganda's critical information infrastructure.
The Updated National Information Security Framework (NISF) 2026 introduces practical cybersecurity assessment tools, strengthens governance requirements, and establishes minimum baseline security controls for critical information infrastructure and operational technology. Its implementation is expected to improve institutional resilience, protect national information assets, and strengthen public confidence in digital government services.
The launch forms part of Government's broader efforts to accelerate digital transformation while ensuring that Uganda's digital infrastructure remains secure, reliable, and resilient.
About NITA-U
The National Information Technology Authority–Uganda (NITA-U) is mandated to coordinate, promote and regulate Information Technology services in Uganda, set national IT standards, and provide firstlevel technical support and advice on all matters relating to information technology, while driving secure digital transformation across Government.
Media Contact
Communications Unit National Information Technology Authority – Uganda (NITA-U)
Email: communications@nita.go.ug
Website: www.nita.go.ug