The contract covers uptime and price. It usually says nothing about who can reach your data or what happens on a breach.

Institutions across the region outsource more than they realize. Systems administration, hosting, payment processing, payroll, email, backups and support all sit with external parties holding credentials into your environment.
Those parties are rarely assessed. The contract covers uptime and price. It usually says nothing about who can access your data, what happens on a breach, or what you get back when the relationship ends.
The outsourced ICT provider with permanent administrator access and credentials shared across several clients. The cloud platform holding your data in a jurisdiction you have never considered. The payment partner whose compromise instantly becomes your incident. And the small supplier with a legitimate login into your network that nobody has reviewed since the day they were onboarded.
You do not need to audit every supplier. Rank them by what they can reach and what breaks if they fail. Assess the top tier properly, ask the middle tier to complete a short security questionnaire, and simply maintain an accurate register for everyone else.
Then fix the contracts. Breach notification within a defined period, a right to audit, data return and deletion on exit, and named security responsibilities. These clauses cost nothing at signing and matter enormously later.
Build a complete vendor register
Rank vendors by access and impact
Assess the top tier properly
Add breach notification clauses
Define data return on exit
Review third party logins quarterly
Nakawa, Kampala, Uganda
Uganda and East Africa
Onsite and remote
John Doe joined UHA
12 people registered today
ECG Interpretation Workshop