{
  "id": 1764847,
  "title": "ORC challenges CSA cybersecurity sanction, says penalty was premature and procedurally unfair",
  "url": "https://urgent.news/2026/08/18/orc-challenges-csa-cybersecurity-sanction-says-penalty-was-premature",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-18T17:39:54.000Z",
  "source": {
    "name": "MyJoyOnline Ghana",
    "slug": "myjoyonline-ghana",
    "url": "https://www.myjoyonline.com/orc-challenges-csa-cybersecurity-sanction-says-penalty-was-premature-and-procedurally-unfair/"
  },
  "original_language": "en",
  "account": "The Office of the Registrar of Companies (ORC) has contested a cybersecurity sanction imposed by the Cyber Security Authority (CSA), contending that the penalty was both premature and procedurally unfair. According to the ORC, the sanction pertains to the acquisition of a Network Operations Centre (NOC) and Security Operations Centre (SOC). The ORC maintains that these projects were substantially completed before the CSA instructed Critical Information Infrastructure (CII) organizations to partner with Tier One licensed cybersecurity service providers. This dispute arises from a statement released by the CSA announcing sanctions against the ORC and Purpleline Solutions Limited due to alleged cybersecurity non-compliance. The ORC rejects the implication that it deliberately chose an unlicensed cybersecurity provider. The ORC asserts that the Ministry of Finance approved the procurement on November 28, 2025, advertising the project on December 4, 2025. After receiving bids, an evaluation on December 22 recommended Purpleline Solutions, and the contract was awarded and executed on February 11, 2026. The ORC argues that the procurement and contract were completed before the CSA's directives were issued on May 20 and June 15, 2026, which required CII institutions to engage Tier One cybersecurity companies. The ORC contends that applying the subsequent directive to an already finished procurement process constitutes retrospective application of the requirement. The Office is also challenging the timing of the CSA's enforcement action, stating that it was given 90 days to address identified cybersecurity deficiencies. The ORC claims it had already started implementing corrective measures and had resolved some of the issues while others were still in progress. The ORC argues that the CSA announced the sanction 57 days into the 90-day compliance period, leaving only 33 days before the deadline. Consequently, the ORC contends that the sanction prevented it from completing the necessary corrective measures and submitting a thorough response.",
  "summary": "The Office of the Registrar of Companies (ORC) has challenged a cybersecurity sanction imposed by the Cyber Security Authority (CSA), arguing that the penalty was premature and procedurally unfair. The ORC says the sanction relates to its procurement of a Network Operations Centre (NOC) and Security Operations Centre (SOC), a process it insists was substantially completed before the CSA directed…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}