CSA hits EY Ghana with GH¢360,000 penalty over licensing breach
By Seli Baisie The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence. The Authority said EY Ghana continued to provide cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives to comply with Ghana’s cybersecurity licensing…
The Cyber Security Authority (CSA) has imposed a substantial penalty of GH¢360,000 on Ernst & Young (EY) Ghana for operating cybersecurity services illegally. The Authority accused EY Ghana of continuing to provide cybersecurity services to owners of Critical Information Infrastructure (CII) despite repeated directives to obtain a valid license.
The penalty was announced on August 18, 2026, following three separate regulatory directives ignored by EY Ghana. The CSA imposed a fine of 10,000 penalty units per instance of non-compliance, equivalent to GH¢120,000 each, totaling GH¢360,000. EY Ghana has been given 14 days to pay the penalty. In addition to the financial penalty, the CSA ordered EY Ghana to cease providing unlicensed services and provide written confirmation of service discontinuation.
The Authority emphasized that compliance with cybersecurity licensing requirements is mandatory and critical, especially for entities providing services to Critical Information Infrastructure. The CSA urged all unlicensed cybersecurity service providers to comply with the law and warned of further enforcement actions against violators.
Written by urgent.news from GBC Ghana's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.