Skip to content

Author

Elijah Musosi

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access Jul 2026

A Cybersecurity Controls Framework for Secure System and Network Access in the Hospitality Sector: A Case of Lake Victoria Hotel, Entebbe, Uganda

Hotels across Uganda increasingly rely on networked systems for reservations, payments, and guest services, yet many still operate without a structured, risk-based approach for protections, a gap that leaves properties such as Lake Victoria Hotel (LVH) in Entebbe exposed, as cyber threats facing the hospitality sector continue to grow. This study set out to close that gap by designing Cybersecurity Controls Framework (LVH-CCF) for secure system and network access, tailored to LVH's operational and regulatory environment. This study was guided by three objectives: evaluating existing access control measures, including multi-factor authentication, role-based access control, privileged access management, and VLAN segmentation; developing an incident response and recovery plan aligned with NIST SP 800-61 Rev. 3; and finally, designing a controls framework anchored in NIST CSF 2.0, NIST SP 800-53 Rev. 5, Uganda's Data Protection and Privacy Act (DPPA) 2019, and the Computer Misuse (Amendment) Act (CMAA) 2022. The study is theoretically grounded in Systems Theory (Pigola et al., 2025), Protection Motivation Theory (Maalem Lahcen et al., 2020), and Compliance and Regulatory Theory. The study used a mixed-methods case study design, drawing on structured surveys, semi-structured interviews, OpenVAS-assisted technical audits, and expert panel assessments across five respondent groups management, IT personnel, staff, external experts, and guests (N = 72). Quantitative data were analysed in SPSS using Wilcoxon Signed-Rank and Spearman correlation tests, while qualitative data were analysed thematically. The findings painted a picture of a reactive, fragmented security posture. Basic perimeter defences were largely in place antivirus (100%), firewalls (86%), and backups (86%) but preventive and governance controls were almost entirely absent: no multi-factor authentication, a documented policy covering only 14% of respondents, network segmentation at just 14%, no staff training, and no incident response plan. Introducing a structured framework had a significant effect on secure system and network access (Wilcoxon W = 5.000, p = 0.0196), and access control measures showed a strong positive relationship with system security (Spearman ρ = 0.922, p < 0.001) a result consistent with Protection Motivation Theory's prediction that behavioural security gains in one domain carry over into adjacent ones. The link between incident response preparedness and business continuity could not be statistically confirmed, given the small management sample (n = 7), though qualitative and cross-group evidence supported it. The resulting LVH-CCF comprises 39 controls spanning the six NIST CSF 2.0 functions Govern (6), Identify (5), Protect (16), Detect (4), Respond (4), and Recover (4) sequenced across a five-phase roadmap. Implementing it would close LVH's most critical vulnerabilities, achieve verifiable DPPA 2019 compliance, and strengthen guest trust.

Elijah Musosi, Ali Najib, David Kaketo et al. · 0 citations