CSA fines EY Ghana GH¢360,000 over cybersecurity licensing breaches  

The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.   The post CSA fines EY Ghana GH¢360,000 over cybersecurity licensing breaches   appeared first on Ghana Business News.

CSA fines EY Ghana GH¢360,000 over cybersecurity licensing breaches  


















The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.  

The penalty follows the company’s continued provision of cybersecurity services, including to owners of Critical Information Infrastructure (CII), despite regulatory directives to comply with Ghana’s cybersecurity licensing regime.  

The CSA said in a statement that it directed EY Ghana on March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days, but later determined that the company had failed to comply with three separate directives.  

The Authority said the breaches fell under Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which prohibit the provision of regulated cybersecurity services without a licence and provide sanctions for failure to comply with directives issued by the CSA.  

It said it imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance, bringing the total administrative penalty to GH¢360,000.  

EY Ghana has been directed to pay the penalty within 14 calendar days of the final enforcement directive.  

The company has also been ordered to immediately cease providing regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services.  

It is required to confirm in writing to the CSA that the affected services have ceased and complete the application process for a CSP licence.  

The Authority stressed that submitting a licence application did not authorise an entity to operate as a CSP, and that providers must obtain the requisite licence before commencing regulated cybersecurity services.  

The CSA said the requirement was particularly important for services provided to owners of CII, whose systems were essential to national security, the economy and the delivery of essential services.  

It said the size, reputation, expertise or clientele of a service provider did not exempt it from the cybersecurity laws.  

“All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” the Authority said.  

The CSA has directed all organisations and professionals providing regulated cybersecurity services without a licence to cease operations and regularise their status.  

It said it would continue to monitor compliance and take enforcement action against both institutions that engaged unlicensed providers and entities that provided regulated cybersecurity services without a licence.  

Such enforcement could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, where permitted by law.  

The Authority urged organisations, particularly owners of CII, to procure cybersecurity services only from licensed providers.  

It said cybersecurity licensing was a legal requirement and that it would continue to enforce the licensing regime to protect critical systems and sensitive information.  

Source: GNA  

The post CSA fines EY Ghana GH¢360,000 over cybersecurity licensing breaches   appeared first on Ghana Business News.

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow