Now Reading
Ghana’s Cybersecurity Authority Slaps GH¢360,000 Fine on EY Ghana for Unlicensed Services

Ghana’s Cybersecurity Authority Slaps GH¢360,000 Fine on EY Ghana for Unlicensed Services

Ghana's Cybersecurity Authority Slaps GH¢360,000 Fine on EY Ghana for Unlicensed Services - Africa

Ghana’s Cyber Security Authority (CSA) has levied a substantial administrative penalty of GH¢360,000 against Ernst & Young (EY) Ghana for operating without the requisite Cybersecurity Service Provider (CSP) licence. This enforcement action underscores the stringent regulatory landscape governing cybersecurity services in Ghana, particularly concerning Critical Information Infrastructure (CII).

The CSA’s directive, issued on 20 March 2026, mandated EY Ghana to apply for a CSP licence within 15 days. Despite this clear instruction and two subsequent regulatory directives, EY Ghana continued to offer regulated cybersecurity services, including those crucial for CII owners. This persistent non-compliance has been deemed a direct breach of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038). These sections explicitly prohibit the provision of licensed cybersecurity services without authorisation and prescribe sanctions for failing to adhere to CSA directives.

The penalty was structured as GH¢120,000 for each of three distinct instances of non-compliance, culminating in the total GH¢360,000 fine. EY Ghana has been given a strict 14-day deadline from the final enforcement directive to remit the payment. Furthermore, the CSA has ordered the immediate cessation of all regulated cybersecurity services, including Governance, Risk and Compliance (GRC) offerings, until the company secures the necessary licence. EY Ghana is required to provide written confirmation of service discontinuation and to complete its CSP licence application process.

The Authority emphatically stated that the mere application for a licence does not grant operational authority. Companies must obtain the official CSP licence from the CSA before commencing any regulated cybersecurity activities. This ruling serves as a critical reminder to all entities operating within Ghana’s digital infrastructure sector.

See Also

The CSA issued a broader warning, highlighting the heightened importance of compliance when cybersecurity services are provided to CII owners. The security and resilience of such systems are paramount to Ghana’s national security and economic stability. The Authority clarified that established reputation, extensive expertise, or a prestigious client list do not exempt any service provider from Ghana’s cybersecurity legislation. Organisations and professionals currently offering regulated cybersecurity services without a valid licence are urged to cease these operations immediately.

The CSA has pledged to maintain vigilant oversight and to pursue enforcement actions against unlicensed providers. These actions may encompass administrative sanctions, legal proceedings, and public disclosure of non-compliant entities. The Authority strongly advises all organisations, especially CII owners, to engage cybersecurity services exclusively from licensed providers, reinforcing that cybersecurity licensing is a mandatory legal requirement, not a mere administrative formality.

View Comments (0)

Leave a Reply

Your email address will not be published.

© Copyright 2025 All Rights Reserved | Designed by Renix Consulting

Scroll To Top