Cyber Security Authority Threatens Sanctions Over Unlicensed Providers as EY Ghana Hit With GH¢360,000 Fine

Cyber Security Authority Threatens Sanctions Over Unlicensed Providers as EY Ghana Hit With GH¢360,000 Fine

The Cyber Security Authority (CSA) has warned cybersecurity firms providing regulated services without a licence to immediately stop operating or face enforcement action, including possible administrative sanctions and court proceedings, following its imposition of a GH¢360,000 penalty on Ernst & Young (EY) Ghana for licensing breaches .

The Authority said the warning applies to all cybersecurity service providers operating in Ghana, regardless of their size, reputation, expertise or clientele, under the Cybersecurity Act, 2020 (Act 1038) and directives issued by the regulator .

Key Development: EY Ghana Sanctioned

The CSA imposed a GH¢360,000 administrative penalty on EY Ghana for allegedly providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence . The Authority said EY Ghana was instructed in a March 20, 2026 letter to apply for a CSP licence within 15 days, but subsequently failed to comply with three separate regulatory directives .

For each of the three instances of non-compliance, the CSA imposed a penalty of 10,000 penalty units, valued at GH¢120,000. The total administrative sanction therefore amounts to GH¢360,000 .

EY Ghana has been given 14 calendar days to settle the penalty and has also been ordered to stop providing regulated cybersecurity services until it obtains the required licence, including Governance, Risk and Compliance (GRC) services .

CSA Warning: No Provider Exempt

The CSA said it considers compliance especially important where cybersecurity services are provided to owners of critical information infrastructure, whose systems are essential to Ghana’s national security, economy and delivery of critical services .

“Cybersecurity licensing is a legal requirement, not an administrative formality,” the authority said in a statement issued Aug. 18 . The regulator directed organisations and professionals providing regulated cybersecurity services without the required licence to cease those services and regularise their operations immediately .

The CSA also warned organisations that engage unlicensed providers that they could face enforcement action. It said it will monitor compliance and take action against both service providers operating without licences and institutions that procure their services .

Possible measures include administrative sanctions, court proceedings and, where permitted by law, publication of the names of unlicensed service providers, according to the Authority .

Compliance Deadlines and Legal Framework

The enforcement push follows earlier directives requiring all Cybersecurity Service Providers (CSPs), Cybersecurity Establishments (CEs), and Cybersecurity Professionals (CPs) to obtain the appropriate licence or accreditation to operate lawfully in Ghana .

Under Section 49(1) of Act 1038, it is a criminal offence to provide cybersecurity services without approval granted by the Authority. Defaulters will face the full rigours of the law, including formal legal action through the courts, heavy fines and regulatory sanctions, as provided under Section 49(2) of the Act .

The CSA urged organisations, particularly owners of critical information infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed providers . The Authority said it will use its regulatory powers to ensure organisations responsible for critical systems and sensitive information meet their cybersecurity obligations .

Verification of licence status can be done online at https://www.csa.gov.gh/licence .

Implications for the Industry

The enforcement action against EY Ghana sends a clear signal that the CSA is moving from warnings to active enforcement . The Authority has made clear that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws .

All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA . The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality

Leave a Reply

Your email address will not be published. Required fields are marked *