Do ISP Billing Systems Really Matter?

Views: 96

Do ISP Billing Systems Really Matter?

Uganda has over 11 million internet users. Hundreds of small ISPs have sprung up to serve them — each running on MikroTik, mobile money, and one of these seven billing platforms. This is the guide that actually tells you what's wrong with each one.

11M+

Internet users in Uganda

90%

ISPs running MikroTik

7

Major billing platforms

 

MARKET REACH

Reported or estimated active ISP clients per platform:

·         Hotspot Uganda: 10,000+ clients

·         Centipid: 1,000+ clients

·         XenFi: ~400 clients

·         Wave Billing: ~200 clients

·         Cute Profit: ~150 clients

·         NG-NetBill: ~100 clients

·         Amikhmon: ~80 clients

QUICK COMPARISON

Platform

Score

Best for

Top Strengths

Key Weakness

Hotspot Uganda (Top Pick)

4.0 / 5

Any size ISP

Free tier, 10k+ ISPs, Auto-reconnect

Free tier caps too early

XenFi

4.5 / 5

Growing ISPs

Multi-vendor, Best portal, Bank+MoMo

Most expensive option

Centipid

3.8 / 5

MikroTik-only

RouterOS v7, Auto invoicing, Analytics

Slows past 3k subscribers

Wave Billing

3.7 / 5

New operators

Clean UI, $5/mo flat, Analytics

USD pricing adds friction

Cute Profit

3.2 / 5

Selling hardware

Billing+inventory, SMS alerts, UGX priced

Aging UI, no mobile app

NG-NetBill (Local)

3.0 / 5

Local UGX operators

RADIUS, UGX pricing, Local support

Sparse docs, slow updates

Amikhmon (Local)

3.1 / 5

Micro-ISPs

Lightweight, Simple setup, Community

Hard to find documentation

 

DEEP DIVE EVALUATION

Hotspot Uganda (Score: 4.0)

   Strengths:

·  Free to start

·  10,000+ ISPs trust it

·  Auto disconnect/reconnect

·  Customer roaming across routers

·  MikroTik native support

   Weaknesses:

·  Free tier expires when sales hit UGX 100k

·  Support is slow at this scale

·  Dashboard has grown cluttered

·  Poor support for non-MikroTik routers

·  Shared infra raises peak uptime concerns

XenFi (formerly ZenFii) (Score: 4.5)

   Strengths:

·  Multi-vendor router support

·  Best captive portal UX on the market

·  PPPoE + hotspot + static IP

·  Integrates mobile money and bank payments

·  Active development, frequent updates

   Weaknesses:

·  Most expensive option — hard for micro-ISPs

·  ZenFii→XenFi rebrand left docs outdated

·  MoMo payment failures not handled gracefully

·  Over-engineered for small neighborhood ISPs

·  No reliable offline fallback

Centipid (Score: 3.8)

   Strengths:

·  Clean MikroTik RouterOS v7 integration

·  Automated invoicing out of the box

·  Real-time analytics dashboard

·  Active local ISP community

·  Straightforward PPPoE and hotspot setup

   Weaknesses:

·  100% MikroTik dependent — any other router struggles

·  Basic reporting with no revenue forecasting

·  UI feels dated compared to newer platforms

·  Performance slips past ~3,000 subscribers

·  Inconsistent support during holidays

Wave Billing (Score: 3.7)

   Strengths:

·  Cleanest modern UI in the market

·  Flat $5/month — no hidden fees

·  Good analytics and revenue reports

·  Fast onboarding, get running in minutes

·  Active feature roadmap

   Weaknesses:

·  USD pricing is friction in a UGX market

·  Limited battle-tested history in Uganda

·  Very small local support/integrator network

·  No offline fallback if server connection drops

·  Community is too small for peer troubleshooting

Cute Profit (Score: 3.2)

   Strengths:

·  Only platform combining billing and hardware inventory

·  Auto-invoice generation before expiry

·  Bulk SMS to all clients for outages

·  Supports hotspot, PPPoE, static IP

·  Priced in UGX

   Weaknesses:

·  Interface is visibly aging

·  No mobile app — desktop/browser only

·  Customer self-service portal is bare-bones

·  SMS costs added via third-party gateways

·  Financial reports lack depth for data-driven decisions

NG-NetBill (Score: 3.0)

   Strengths:

·  Built in Uganda, support in Uganda

·  UGX pricing, no currency friction

·  RADIUS-powered for solid auth

·  MikroTik hotspot ready

·  Good for small neighborhood ISPs

   Weaknesses:

·  Very sparse public documentation

·  RADIUS setup is complex without a network engineer

·  Slow feature updates and unclear roadmap

·  Low brand awareness — hard to discover

·  Not ideal for ISPs that grow quickly

Amikhmon (Score: 3.1)

   Strengths:

·  Simple, lightweight — low learning curve

·  Popular in local ISP WhatsApp communities

·  Good for MikroTik-only micro-ISPs

·  Fast initial setup

·  Affordable entry point

   Weaknesses:

·  Documentation is nearly impossible to find online

·  Feature set is narrower than all other platforms

·  Small user base means limited peer support

·  Mobile money integration less polished

·  Unclear product roadmap and long-term direction

 

PROBLEMS EVERY PLATFORM SHARES

·         Mobile money failures. When MTN or Airtel APIs go down, customers pay and stay offline. No platform handles this gracefully.

·         No subscriber self-service. Customers can't check usage, change packages, or raise tickets without calling in.

·         Data lock-in. Migrating between platforms is painful — customer history rarely exports cleanly.

·         Weak security. Fraud detection and audit trails are afterthoughts across the market.

BOTTOM LINE VERDICT

Starting out:
Hotspot Uganda or Wave

Scaling fast:
XenFi or Centipid

Want local pricing:
NG-NetBill or Amikhmon

Need billing + stock:
Cute Profit

 

Related Insights

May 26, 2026

Zero Trust Networking: Why “Never Trust, Always Verify” Matters

For years, Virtual Private Networks (VPNs) were the standard solution for secure remote access. They allowed employees to connect to company networks from outside the office and helped businesses support remote work securely. But the cybersecurity landscape has changed dramatically. Cloud computing, remote work, mobile devices, and increasingly sophisticated cyberattacks have exposed the limitations of traditional network security models. In response, organizations are rapidly adopting a modern approach known as Zero Trust Networking. Unlike traditional security methods that automatically trust users once they’re inside the network, Zero Trust assumes that no user, device, or connection should be trusted by default. Its philosophy is simple: Never trust. Always verify. What Is Zero Trust Networking? Zero Trust Networking is a cybersecurity model that continuously verifies every user, device, application, and request before granting access to company resources. Traditional networks operated like a castle: Strong defenses around the perimeter Open trust once inside This worked when employees mainly worked from office buildings using company-managed devices. But today: Employees work remotely Applications live in the cloud Personal devices access corporate systems Attackers target user identities instead of networks As a result, trusting users simply because they connected to the network is no longer safe. Zero Trust removes that assumption by verifying access continuously and limiting permissions to only what users truly need. What Is a VPN? A VPN, or Virtual Private Network, creates an encrypted connection between a user’s device and a company’s internal network. VPNs are designed to: Protect internet traffic Allow remote access Hide user activity from outside interception Secure communications over public networks When users connect through a VPN, they are often treated as if they are physically inside the company’s office network. This approach was highly effective for many years — but it also introduced a major problem: Once connected, users often gain broad access to internal systems. If attackers steal credentials or compromise a device, they can potentially move throughout the network with fewer restrictions. How Zero Trust Differs from VPNs Zero Trust and VPNs may appear similar because both deal with secure access, but they operate very differently. A VPN focuses on securing the connection. Zero Trust focuses on securing identity, access, and behavior continuously. Zero Trust vs Traditional VPN Feature Zero Trust Networking Traditional VPN Security Model “Never trust, always verify” Trust once connected Access Control Granular, role-based access Broad network access Authentication Continuous verification Usually verified only at login Network Exposure Minimal exposure Larger internal network exposure Remote Work Security Built for modern distributed teams Designed for older perimeter networks Lateral Movement Risk Greatly reduced Higher if compromised Device Verification Frequently enforced Often limited Cloud Compatibility Strong cloud-native integration Less optimized for cloud systems Threat Detection Real-time monitoring and response Basic session monitoring Scalability Flexible and modern Can bottleneck under heavy usage User Experience Direct access to specific resources Full network tunnel access Why Businesses Are Moving Toward Zero Trust Modern cyberattacks no longer focus only on breaking through firewalls. Instead, attackers target: Weak passwords Phishing emails Stolen credentials Unsecured devices Human error Once attackers gain access to a traditional VPN-connected environment, they may move laterally across systems. Zero Trust helps prevent this by: Restricting unnecessary access Continuously validating identities Monitoring behavior in real time Segmenting networks into smaller protected zones This significantly limits how far attackers can go if an account or device becomes compromised. Core Principles of Zero Trust 1. Verify Every User and Device Every access request must be authenticated and validated, regardless of where it originates. This may include: Multi-factor authentication (MFA) Device security checks Identity verification Behavioral analysis 2. Least Privilege Access Users receive access only to the systems and data they need to perform their tasks. This reduces exposure to sensitive resources. 3. Micro-Segmentation Networks are divided into smaller protected sections to prevent attackers from moving freely between systems. 4. Continuous Monitoring Zero Trust systems constantly analyze activity for suspicious behavior, including: Unusual login attempts Unexpected file transfers Abnormal access patterns Unauthorized privilege changes Benefits of Zero Trust Networking Stronger Security Zero Trust minimizes blind trust and reduces attack surfaces. Better Remote Work Support Employees can securely work from anywhere without exposing entire networks. Reduced Breach Impact If attackers gain access, their movement is heavily restricted. Improved Visibility Organizations gain deeper insight into users, devices, and application activity. Better Cloud Security Zero Trust aligns naturally with modern cloud environments and hybrid infrastructures. Challenges of Implementing Zero Trust Although Zero Trust offers major advantages, implementation can be challenging. Organizations may face: Complex infrastructure changes Legacy application compatibility issues Higher upfront investment User resistance to additional verification steps However, many businesses consider these trade-offs worthwhile given the growing threat landscape. Can Zero Trust Replace VPNs Completely? In some cases, yes. Many organizations are adopting Zero Trust Network Access (ZTNA) solutions that provide secure application-level access without exposing the full network. However, VPNs still remain useful for: Legacy systems Certain internal tools Temporary remote access needs Smaller organizations with simpler infrastructures Today, many businesses use a hybrid approach where VPNs coexist with Zero Trust strategies during transition periods. The Future of Cybersecurity Cybersecurity is moving away from perimeter-based security toward identity-based security. As businesses continue embracing: Remote work Cloud computing SaaS applications Mobile devices AI-powered systems Traditional trust-based models become increasingly risky. Zero Trust Networking represents a modern security mindset built for today’s digital environment — one where every access request must earn trust continuously. Final Thoughts VPNs helped shape secure remote work for decades, but modern threats require more adaptive security approaches. Zero Trust Networking offers a smarter framework by: Continuously verifying access Limiting unnecessary permissions Monitoring activity in real time Reducing attacker movement across systems In an era where cyberattacks are becoming more sophisticated every day, trusting nothing by default may be the strongest defense organizations can build.

Jun 21, 2026

Starlink's Kenya Problem: When Satellite Internet Meets Its Own Success

When Starlink landed in Kenya in July 2023, it arrived with a simple promise: beam fast internet down from space, skip the messy business of digging trenches and laying cable, and connect places fiber would never reach. For a while, it delivered. Speeds hit 200 Mbps. Rural lodges in the Maasai Mara, off-grid farms, and households fed up with patchy local ISPs signed up in droves. Three years later, the story looks more complicated. The Numbers Tell the Story As of March 2026, Starlink's median download speed in Kenya had fallen to 34.55 Mbps  a 26% drop from the previous year and an all-time low for the service in the country. That's a long way down from the 200 Mbps users enjoyed at launch. The cause isn't a technical failure. It's success outpacing capacity. Starlink now counts close to 25,000 active subscribers in Kenya, and each satellite beam can only handle so many users in a given radius before everyone's connection starts to slow down. The more people who sign up in a concentrated area, the more the network strains — and the worse it gets for everyone sharing that beam. This Has Happened Before If this sounds familiar, it's because Kenya already lived through a version of this story. In November 2024, Starlink froze new residential sign-ups across Nairobi, Kiambu, Machakos, Kajiado, and Murang'a — the country's busiest, most densely populated counties — after capacity ran out. Anyone trying to subscribe was met with a blunt "sold out" message. The freeze lasted seven months. That pause cost Starlink dearly. Existing customers watched speeds crater to around 45 Mbps. The Communications Authority of Kenya's data showed the company lost roughly 2,000 subscribers in a single quarter, and its market share slipped from 1.1% down to 0.8%. Starlink did eventually add capacity and reopen sign-ups, clawing back some of the lost subscribers but never the market share. Now, in 2026, congestion is back, and it's arguably worse than the first time. Losing Ground to Local Rivals While Starlink has been wrestling with its own bandwidth math, Kenya's terrestrial ISPs haven't been standing still. Safaricom alone controls nearly 35% of the fixed internet market, offering fiber and 5G router packages with speeds up to 1,000 Mbps — at a fraction of Starlink's cost. JTL Faiba holds another 20%. Smaller players like Vilcom Networks, Ahadi Wireless, and Mawingu have all grown faster than Starlink over the past two years. The result: Starlink's once-dominant speed advantage over local providers has shrunk to just 2.24 times faster down from a much wider gap at launch. For many urban and peri-urban customers, that's no longer enough to justify the higher price tag, which still runs about three to four times what comparable local fiber packages cost. Put simply: Starlink disrupted the market just enough to wake up the competition, and the competition responded. Where Starlink Still Wins None of this means Starlink has failed in Kenya. It's just found a narrower lane than originally advertised. The satellite segment as a whole posted nearly 14% subscriber growth last quarter, driven almost entirely by exactly the customers Starlink was built for: rural households, remote businesses, NGOs, schools, and tourist camps where fiber will likely never arrive. Starlink has also leaned into that identity. It now sells hardware through retail partnerships at major Kenyan chains, alongside everyday electronics a sign the company is settling into a steady, if unglamorous, role as rural connectivity's default option rather than the urban broadband disruptor it was once pitched as. What's Next More competition is coming, not less. Amazon's Project Kuiper is working through regulatory approval to enter the Kenyan market, with plans for the company's first African ground station to be based there. That will only intensify pressure on an already strained satellite internet sector and could force Starlink to either invest seriously in local infrastructure or cede the rural niche it's carved out. For now, the pattern looks set to repeat: rapid uptake, congestion, a pullback, and a slow climb back  with each cycle leaving Starlink a little further from the broadband revolution it once promised, and a little more comfortable as Kenya's connectivity option of last resort.

May 19, 2026

Beyond the Internet: Creative and Unexpected Things You Can Do With MikroTik

Most people hear the name MikroTik and immediately think: “Oh, those are internet routers.” And yes — MikroTik devices are incredible for networking. But here’s the fun part: A MikroTik router can become far more than just an internet box. With the right setup, it can act like a mini server, automation brain, security guard, smart-home controller, monitoring station, or even a hacking lab for learning cybersecurity and enterprise networking. If you already own a MikroTik router, you’re probably using only 20% of what it can actually do. Let’s explore some fascinating things you can build with MikroTik that have little to do with “just internet access.” 1. Turn Your Home Into a Smart Network Lab A MikroTik router can simulate the kind of infrastructure used in real companies, data centers, and ISPs. You can create: separate departments using VLANs, multiple virtual networks, enterprise-style routing, firewall zones, and secure device segmentation. For students learning networking, cybersecurity, or IT, this is one of the cheapest ways to build a professional-grade lab at home. You can even practice: OSPF, BGP, MPLS, VXLAN, GRE tunnels, and IPv6 routing. That’s the same technology used by telecom companies and cloud providers. 2. Build a Network-Wide Ad Blocker Instead of installing ad blockers on every phone and computer, MikroTik can block ads for your entire network. You can: redirect DNS traffic, block tracking domains, filter malicious websites, and stop annoying popups. Some users integrate MikroTik with Pi-hole for even stronger filtering. The result? Cleaner browsing, fewer malicious ads, and faster loading times across all devices. 3. Create a Smart Home Security System MikroTik can help isolate and secure smart home devices. You can separate: security cameras, smart TVs, IoT devices, voice assistants, and personal devices. Why does this matter? Because many cheap smart devices have terrible security. With MikroTik firewall rules and VLANs, you can prevent your smart bulbs or cameras from accessing sensitive devices like your laptop or NAS. You can also: monitor suspicious traffic, block unknown connections, and receive alerts when strange activity appears. 4. Run a Mini Cybersecurity Defense System MikroTik routers are surprisingly powerful security devices. You can configure them to: detect brute-force attacks, block suspicious IP addresses, limit scanning attempts, stop port scans, and rate-limit malicious traffic. Some enthusiasts even create automatic blacklists that dynamically block attackers. It’s a great way to learn practical cybersecurity. 5. Build a CCTV Monitoring Network Many people don’t realize MikroTik works beautifully with surveillance systems. You can: isolate cameras from the main network, prioritize CCTV traffic, create remote viewing access, and secure video streams. If you run cameras in multiple buildings, MikroTik can link them together securely. Some setups even allow centralized monitoring dashboards. 6. Use It as a Learning Platform for Ethical Hacking Because MikroTik supports advanced routing and firewalling, it’s perfect for cybersecurity labs. You can: simulate attacks safely, practice penetration testing, build isolated environments, and learn traffic analysis. Many networking students use MikroTik to understand: packet inspection, firewall behavior, VPN tunneling, and network segmentation. It’s one of the best low-cost learning tools for aspiring network engineers. 7. Build a Private Cloud Network With VPNs and routing features, you can create your own secure private infrastructure. Imagine: accessing your files remotely, connecting multiple homes, linking office systems, or securely reaching your home server from anywhere. You control the network instead of depending entirely on third-party cloud services. 8. Create a Powerful Gaming Network Gamers love MikroTik for one reason: Control. You can: prioritize gaming traffic, reduce lag spikes, manage latency, and eliminate bufferbloat. Some users create dedicated gaming VLANs that isolate gaming devices from everything else. This can dramatically improve consistency during online gameplay. 9. Build Long-Range Wireless Links MikroTik hardware is famous for wireless bridging. You can connect: two houses, office buildings, farms, schools, or remote structures. In many parts of Africa, MikroTik devices are used to provide long-distance wireless connectivity across villages and towns. Some links can span several kilometers with proper antennas. 10. Create a Full Monitoring Dashboard MikroTik devices generate huge amounts of useful data. You can monitor: bandwidth usage, connected devices, CPU and memory load, suspicious activity, and uptime statistics. Tools like: The Dude, Grafana, Zabbix, and LibreNMS can transform your MikroTik setup into a professional monitoring center. 11. Run Containers on Your Router Newer MikroTik devices support lightweight containers. That means your router can run small applications directly. People are experimenting with: Pi-hole, automation scripts, monitoring tools, DNS services, and lightweight Linux utilities. Your router becomes more like a tiny server. 12. Build a Neighborhood Network One of the coolest uses for MikroTik is community networking. You can create: apartment networks, campus systems, community Wi-Fi, or local communication networks. Some enthusiasts even build local-only services: chat systems, file-sharing servers, community dashboards, and neighborhood CCTV monitoring. This becomes especially useful in areas with unreliable internet access. 13. Learn Real Enterprise Networking Without Expensive Equipment Cisco labs can be expensive. MikroTik gives students and hobbyists access to advanced networking at a fraction of the cost. You can practice: enterprise routing, ISP technologies, failover systems, dynamic routing, and advanced firewalling. Many network engineers started their careers using MikroTik gear in home labs. 14. Build Automation Systems With scripts and schedulers, MikroTik can automate tasks. Examples include: rebooting devices automatically, changing firewall rules, sending alerts, restarting failed connections, or activating backup links. Some people even integrate MikroTik with smart-home platforms. 15. Create a Digital Fortress at Home A properly configured MikroTik router can dramatically improve privacy and security. You can: isolate devices, block trackers, secure remote access, encrypt traffic, and control exactly what enters or leaves your network. For privacy enthusiasts, MikroTik offers an incredible amount of control. Why MikroTik Is Loved by Tech Enthusiasts MikroTik sits in a unique space between: consumer routers, enterprise networking, and Linux-style flexibility. That combination makes it extremely powerful. It’s affordable enough for students and hobbyists, yet capable enough for ISPs and enterprise environments. And unlike many locked-down consumer routers, MikroTik encourages experimentation. That’s why people use it for: labs, automation, cybersecurity, wireless infrastructure, smart homes, monitoring, and advanced networking projects. Final Thoughts A MikroTik router is not just a device that “gives Wi‑Fi.” It can become: a learning platform, a security appliance, a smart-home controller, a monitoring system, a mini server, or even the backbone of an entire community network. The deeper you go into MikroTik, the more you realize: It’s less like a normal router… and more like a tiny programmable network computer. And that’s what makes it fun. Need Help Setting Up Your MikroTik? Whether you want: advanced configurations, gaming optimization, VLANs, hotspot systems, CCTV networking, cybersecurity setups, smart-home segmentation, or a full MikroTik homelab, you can get assistance and guidance. For more information: WhatsApp: +256763206676