Menu

EY Ghana fined GH¢360,000 by CSA over unlicensed cybersecurity services

EY COMPANY The company has been fined for violating CSA laws

Tue, 18 Aug 2026 Source: www.ghanaweb.com

The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.

The Authority said the company continued to provide cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives to comply with Ghana’s cybersecurity licensing requirements.

CSA sanctions ORC, Purpleline Solutions over cybersecurity licensing breaches

In a statement issued on Tuesday, August 18, 2026, the CSA said it directed EY Ghana in a letter dated March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days.

“The CSA had specifically directed EY Ghana, by correspondence dated 20 March 2026, to submit an application for a CSP licence within fifteen (15) days. The Authority subsequently determined that EY Ghana failed to comply with three separate regulatory directives,” portions of the statement read.

However, according to the Authority, EY Ghana failed to comply with three separate regulatory directives.

The CSA said the conduct breaches Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which require providers of regulated cybersecurity services to obtain the necessary licence and comply with directives issued by the Authority.

The GH¢360,000 penalty was imposed at GH¢120,000 for each of the three instances of non-compliance.

“Pursuant to Sections 49(2), 92(2) and 93 of Act 1038, the CSA imposed a penalty of 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance, resulting in a total administrative penalty of GH¢ 360,000.

“EY Ghana has been directed to pay the penalty within fourteen (14) calendar days from the date of the final enforcement directive,” the statement added.

Furthermore, the CSA has also directed EY Ghana to immediately stop providing all regulated cybersecurity services without a licence, including Governance, Risk and Compliance (GRC) services.

The company has also been ordered to provide written confirmation that the affected services have stopped and to complete its application for a CSP licence.

The CSA stressed that applying for a licence does not allow an entity to operate as a Cybersecurity Service Provider.

“Entities are required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services,” the Authority said.

The Authority also warned that the size, reputation, expertise or clientele of a service provider does not exempt it from the country’s cybersecurity laws.

“All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” it said.

The CSA said it would continue monitoring compliance and take action against institutions that engage unlicensed providers as well as entities that offer cybersecurity services without the required licence.

It said enforcement action could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, where permitted by law.

BoG warns cybersecurity could slow digital finance growth

The Authority has also urged organisations, especially owners of Critical Information Infrastructure, to ensure that cybersecurity services are obtained only from licensed providers.

“Cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate,” is stated.

Read the CSA's statement below:



MAG/VPO

Source: www.ghanaweb.com