CSA Fines EY Ghana GH¢360,000 For Providing Cybersecurity Services Without Licence

Court

The Cyber Security Authority (CSA) has imposed a GH¢360,000 administrative penalty on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without the requisite licence.

The Authority said EY Ghana continued to provide regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives to regularise its operations.

In a statement dated August 18, 2026, the CSA said it directed EY Ghana on March 20, 2026, to submit an application for a Cybersecurity Service Provider (CSP) licence within 15 days.

However, the Authority subsequently determined that the firm had failed to comply with three separate regulatory directives.

The CSA said the conduct constitutes breaches of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which regulate the provision of cybersecurity services and provide sanctions for non-compliance.

Under Sections 49(2), 92(2) and 93 of Act 1038, the CSA imposed a penalty of 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance.

This brings the total administrative penalty imposed on EY Ghana to GH¢360,000.

The firm has been directed to pay the penalty within 14 calendar days from the date of the final enforcement directive.

The CSA has also directed EY Ghana to immediately cease providing all regulated cybersecurity services without the required licence.

The directive specifically includes Governance, Risk and Compliance (GRC) services.

EY Ghana has further been ordered to provide written confirmation to the CSA that the affected services have ceased and complete the application process for a CSP licence.

The Authority stressed that merely applying for a licence does not authorise a service provider to operate.

“An application for a licence does not confer a licence to operate,” the CSA said, emphasising that providers must obtain the requisite licence before offering regulated cybersecurity services.

The enforcement action has also been accompanied by a warning to other cybersecurity service providers operating in Ghana without the required licence.

The CSA said compliance was particularly important where cybersecurity services are provided to owners of Critical Information Infrastructure, whose systems are essential to national security, the economy and the delivery of critical services.

“The Authority therefore makes clear that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws,” the statement said.

The Authority said all cybersecurity service providers are subject to the same regulatory requirements under Act 1038 and its directives.

It has therefore directed unlicensed operators to cease providing regulated services and regularise their operations.

The CSA also warned that it would continue monitoring compliance and take enforcement action against both unlicensed service providers and institutions that engage them.

Such action, it said, could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers where permitted by law.

The Authority urged organisations, particularly owners of Critical Information Infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed providers.

“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate,” the CSA said.

The latest enforcement action forms part of the Authority’s broader regulatory efforts to strengthen cybersecurity compliance and protect Ghana’s digital infrastructure and sensitive information.

Leave a Reply

*