Office of Registrar of Companies and service provider fined GH¢360,000 for cybersecurity breaches
Featured

Office of Registrar of Companies and service provider fined GH¢360,000 for cybersecurity breaches

The Office of the Registrar of Companies (ORC) and a cybersecurity service provider, Purpleline Solutions Limited, have been fined a total of GH¢360,000 for reported breaches of Ghana’s cybersecurity requirements.

The Cyber Security Authority (CSA), in sanctioning the two organisations, said the ORC, contrary to cybersecurity regulations, engaged a service provider that was not licensed. 

The ORC, it said, had flaunted two directives requiring it, as a designated critical information infrastructure (CII) institution, to engage only appropriately licensed cybersecurity service providers (CSPs).

For disregarding the directive, the ORC has been fined 10,000 penalty units for non-compliance, amounting to GH¢240,000,

Maame Samma Peprah - Registrar of Companies

Offence

In a statement, the Cyber Security Authority (CSA) on June 15, 2026, directed the Office of the Registrar of Companies to engage Tier 1 licensed CSPs to strengthen the security and resilience of its critical information infrastructure.

Additionally, as part of the requirements to engage a service provider, the ORC was also to provide details of its cybersecurity service providers, the terms of reference (TOR) for its proposed security operations centre (SOC), and relevant Public Procurement Authority (PPA) approvals.


However, despite this important directive, the CSA said the ORC ignored specific advice to engage a Tier 1 licensed CSP and rather secured the services of Purpleline Solutions Limited Company, which was not licensed by the authority, which constituted a breach of Section 92 of the Cybersecurity Act, 2020 (Act 1038).

The fine is thus the sanction for that breach as well as the second directive for the ORC to provide all the details of the service provider as required by the PPA regulations. 

The CSA has also further directed the ORC to comply with the outstanding directives within one month of receiving the sanction letter.

“The Authority determined that the ORC failed to comply with two separate directives issued by the CSA.

Consequently, pursuant to Section 92(2) of Act 1038, the ORC has been fined Ten Thousand (10,000) penalty units for each instance of non-compliance, standing at GH₵240,000.00, and directed to comply with the outstanding directives within one month of receiving the CSA’s sanction letter,” the statement read.

Purpleline fined GH¢120,000

Purpleline Solutions Limited Company on the other hand, was fined for providing cybersecurity services without the required license.

It was slapped with a fine of 10,000 penalty units, equivalent to GH¢120,000, after the CSA determined that it had provided cybersecurity services without first obtaining the necessary license.

The authority noted that Purpleline applied for a cybersecurity service provider license on July 15, 2026, but investigations determined that it applied for the licence after it had already been engaged by the ORC.

It stressed that an application for a license does not authorise a company to operate as a Cybersecurity Service Provider.

“Entities are required to obtain the requisite license before commencing the provision of regulated cybersecurity services,” the statement read.

Warning

The CSA reminded both organisations and service providers about the risk of engaging unlicensed cybersecurity service providers, while also cautioning the service providers against operating without the appropriate license.

It stressed that organisations could engage an unlicensed provider and subsequently then expect the provider to regularise its status.

“An application for a license is not the same as holding a license and does not authorise an entity to commence regulated cybersecurity operations,” the Authority emphasised in the statement.

It encouraged all designated CII institutions, public-sector organisations and other entities covered by the Cybersecurity Act to verify both the licensing status and appropriate license tier of cybersecurity service providers before awarding contracts or allowing them to commence work.

The authority further said it would continue with its monitoring to ensure compliance and take enforcement action against institutions that engage unlicensed providers as well as companies that provide cybersecurity services without the requisite license.

“Cybersecurity licensing is a legal requirement, not an administrative formality,” the Authority said, adding that it will use its regulatory powers to ensure organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations.


Our newsletter gives you access to a curated selection of the most important stories daily. Don't miss out. Subscribe Now.

Connect With Us : 0242202447 | 0551484843 | 0266361755 | 059 199 7513 |