CSA fines EY Ghana GH₵360,000 over unlicensed cybersecurity services

-

Carbonatix Pre-Player Loader

Audio By Carbonatix

The Cyber Security Authority (CSA) has imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.

The sanction follows the company’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives from the CSA to comply with the licensing requirements under the Cybersecurity Act, 2020 (Act 1038).

In a statement dated August 18, 2026, the CSA said it directed EY Ghana in a letter dated March 20, 2026, to apply for a CSP licence within 15 days.

However, the Authority said EY Ghana failed to comply with three separate regulatory directives issued to the company.

According to the CSA, the breaches contravene Sections 49 and 92 of Act 1038, which prohibit the provision of regulated cybersecurity services without the required licence and provide sanctions for failure to comply with directives from the Authority.

The CSA said it imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance under Sections 49(2), 92(2) and 93 of the Act.

This brings the total administrative penalty imposed on EY Ghana to GH¢360,000.

The company has been directed to pay the amount within 14 calendar days from the date of the final enforcement directive.

The CSA has also issued an immediate cease-and-desist order against EY Ghana, directing the company to stop providing all regulated cybersecurity services without the requisite licence.

This includes Governance, Risk and Compliance (GRC) services.

EY Ghana is further required to submit written confirmation to the CSA that the affected services have been discontinued and complete the process of applying for a CSP licence.

The Authority stressed that merely submitting an application does not permit an entity to operate as a licensed Cybersecurity Service Provider.

It said providers must obtain the requisite licence before commencing regulated cybersecurity services.

CSA warns unlicensed cybersecurity providers

The CSA said the enforcement action against EY Ghana should serve as a warning to organisations and professionals providing regulated cybersecurity services without the required licence.

The Authority stressed that compliance is particularly important when such services are provided to owners of Critical Information Infrastructure, whose security and resilience are critical to Ghana’s national security, economy and the delivery of essential services.

It noted that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.

According to the CSA, all Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the Authority.

The CSA has therefore directed all organisations and professionals providing regulated cybersecurity services without a valid licence to immediately stop such activities and regularise their operations.

It warned that it will continue monitoring compliance and take enforcement action against institutions that engage unlicensed providers and entities that offer cybersecurity services without the required licence.

Such action, the Authority said, could include administrative sanctions, court proceedings and, where permitted by law, the publication of the names of unlicensed service providers.

The CSA also urged organisations, particularly owners of Critical Information Infrastructure, to obtain cybersecurity services only from appropriately licensed providers.

It stressed that cybersecurity licensing is a legal requirement and not merely an administrative formality.

The Authority said it would continue to use its regulatory powers to protect Ghana’s digital ecosystem and ensure that organisations responsible for critical systems and sensitive information meet their cybersecurity obligations.

Also read:

DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.

Latest Posts