CSA fines EY Ghana GH¢360,000 for providing cybersecurity services without a licence
The Cyber Security Authority (CSA) has imposed a GH¢360,000 administrative penalty on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without the requisite licence. The Authority said EY Ghana continued to provide regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives to regularise its operations. In…
The Cyber Security Authority (CSA) has imposed a significant administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing cybersecurity services without the necessary license. The Authority noted that EY Ghana continued to offer regulated cybersecurity services, including to Critical Information Infrastructure (CII) owners, despite orders to formalize its operations.
On March 20, 2026, the CSA instructed EY Ghana to apply for a Cybersecurity Service Provider (CSP) license within 15 days; however, the firm failed to comply with three separate regulatory directives. For each instance of non-compliance, the CSA imposed a penalty of 10,000 penalty units, totaling GH¢120,000 per violation. The cumulative administrative fine now amounts to GH¢360,000.
EY Ghana is required to settle this within 14 days from the enforcement directive's date. The Authority also directed the firm to immediately halt all regulated cybersecurity services without a valid license, including Governance, Risk and Compliance (GRC) services. EY Ghana must subsequently confirm to the CSA that these services have ceased and proceed with the CSP license application.
The CSA stressed that merely applying for a license does not grant permission to operate; a license must be obtained before providing regulated cybersecurity services. This enforcement action follows a warning to other unlicensed cybersecurity service providers in Ghana, emphasizing that size, reputation, expertise, or clientele do not exempt service providers from Ghana's cybersecurity laws.
The CSA directed all cybersecurity service providers to adhere to the same regulatory requirements under Act 1038 and its directives, and warned of continued monitoring and enforcement actions, including administrative sanctions and court proceedings. The Authority urged organizations, particularly owners of Critical Information Infrastructure, to procure cybersecurity services only from appropriately licensed providers, emphasizing that cybersecurity licensing is a legal requirement, not an administrative formality.
Written by urgent.news from MyJoyOnline Ghana's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.