CSA fines EY Ghana GH₵360,000 for providing cybersecurity services without licence
Featured

CSA fines EY Ghana GH₵360,000 for providing cybersecurity services without licence

The Cyber Security Authority (CSA) has imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.

The action follows EY Ghana’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives from the CSA requiring compliance with the licensing regime under the Cybersecurity Act, 2020 (Act 1038).

In a press release dated August 18, 2026, the CSA indicated it had specifically directed EY Ghana, by correspondence dated March, 20, 2026, to submit an application for a CSP licence within 15 days.

It said the Authority subsequently determined that EY Ghana had failed to comply with three separate regulatory directives.

The CSA said the conduct constituted breaches of Sections 49 and 92 of Act 1038, which prohibit the provision of regulated cybersecurity services without the requisite licence and provide sanctions for failure to comply with directives issued by the Authority.

GH¢360,000 penalty

Under Sections 49(2), 92(2) and 93 of Act 1038, the CSA imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance.


The three penalties brought the total administrative penalty against EY Ghana to GH¢360,000.

The company has been directed to pay the penalty within 14 calendar days from the date of the final enforcement directive.

The CSA has also issued an immediate cease-and-desist directive against EY Ghana.

Under the directive, the company is required to stop providing all regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services.

EY Ghana is also required to provide written confirmation to the CSA that the affected services have ceased and complete the application process for a CSP licence.

The Authority stressed that submitting an application for a licence did not authorise an entity to operate as a Cybersecurity Service Provider.

It said entities were required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services.

CSA warning

The CSA said the enforcement action against EY Ghana was accompanied by a warning to organisations and professionals providing regulated cybersecurity services without the requisite licence.

It said compliance was particularly important where cybersecurity services were provided to owners of Critical Information Infrastructure, whose security and resilience were linked to Ghana’s national security, economy and delivery of essential services.

The Authority said the size, reputation, expertise or clientele of a service provider did not exempt it from Ghana’s cybersecurity laws.

It said all Cybersecurity Service Providers operating in Ghana were subject to the same regulatory requirements under Act 1038 and directives issued by the CSA.

The CSA has, therefore, directed all organisations and professionals providing regulated cybersecurity services without the requisite licence to cease those services and regularise their operations immediately.

It warned that it would continue to monitor compliance and take enforcement action against institutions that engage unlicensed providers and entities that provide cybersecurity services without a licence.

According to the Authority, such enforcement action could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, where permitted by law.

The CSA also urged organisations, particularly owners of Critical Information Infrastructure, to procure cybersecurity services only from appropriately licensed service providers.

It said cybersecurity licensing was a legal requirement and not merely an administrative formality.

The Authority said it would use its regulatory powers to protect Ghana’s digital ecosystem and require organisations entrusted with critical systems and sensitive information to meet their cybersecurity obligations.


Our newsletter gives you access to a curated selection of the most important stories daily. Don't miss out. Subscribe Now.

Connect With Us : 0242202447 | 0551484843 | 0266361755 | 059 199 7513 |