General News

CSA fines EY Ghana GH¢360,000 for unlicensed cybersecurity services

Story by Eugene Nyarko Jnr. I Accra l August 18, 2026

The Cyber Security Authority (CSA) has imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.

The action follows EY Ghana’s continued provision of regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives from the CSA requiring the company to comply with Ghana’s cybersecurity licensing regime.

According to the CSA, it directed EY Ghana in correspondence dated March 20, 2026, to submit an application for a CSP licence within 15 days.

The Authority subsequently determined that EY Ghana had failed to comply with three separate regulatory directives.

The CSA said the conduct constituted a breach of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which prohibit the provision of regulated cybersecurity services without the requisite licence and provide sanctions for failure to comply with directives issued by the Authority.

GH¢360,000 penalty

Pursuant to Sections 49(2), 92(2) and 93 of Act 1038, the CSA imposed a penalty of 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance.

The three penalties resulted in a total administrative sanction of GH¢360,000.

EY Ghana has been directed to pay the penalty within 14 calendar days from the date of the final enforcement directive.

Cease-and-desist order

The CSA has also directed EY Ghana, with immediate effect, to cease and desist from providing all regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services.

The company has further been directed to provide written confirmation to the Authority that the affected services have ceased and to complete the application process for a CSP licence.

The CSA stressed that submitting an application for a licence does not confer a licence to operate as a Cybersecurity Service Provider.

It said entities are required to obtain the requisite licence from the Authority before commencing the provision of regulated cybersecurity services.

Warning to service providers

The CSA has issued a strong warning to organisations and professionals providing regulated cybersecurity services without the requisite licence to cease such services and regularise their operations immediately.

It said compliance was particularly critical where cybersecurity services were provided to owners of Critical Information Infrastructure, whose security and resilience were essential to Ghana’s national security, economy and delivery of essential services.

The Authority said the size, reputation, expertise or clientele of a service provider did not exempt it from Ghana’s cybersecurity laws.

“All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” it stated.

The CSA further warned that it would continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity services without the requisite licence.

Such action, where necessary, could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, as permitted by law.

Call to critical infrastructure owners

The Authority has urged organisations, particularly owners of Critical Information Infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed service providers.

It said cybersecurity licensing was a legal requirement and not merely an administrative formality.

The CSA said it remained committed to protecting Ghana’s digital ecosystem and would use its regulatory powers to ensure that organisations entrusted with critical systems and sensitive information met their cybersecurity obligations.

It urged organisations requiring clarification on licensing requirements or the scope of regulated cybersecurity services to contact the Cyber Security Authority.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button