Accra: The Cyber Security Authority (CSA) has imposed a penalty of GHS360,000 on Ernst and Young (EY) Ghana for delivering regulated cybersecurity services without a valid licence. The decision comes after EY Ghana continued to provide cybersecurity services, notably to owners of Critical Information Infrastructure (CII), without adhering to the licensing requirements stipulated by Ghana's cybersecurity regulations.
According to Ghana Web, the CSA had previously directed EY Ghana, in a correspondence dated March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days. However, the company failed to meet the compliance requirements, resulting in three separate regulatory breaches. These actions are seen as violations of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which necessitate that all providers of regulated cybersecurity services obtain the necessary licences and adhere to the directives issued by the Authority.
The GHS360,000 fine was calculated by imposing GHS120,000 for each of the three instances of non-compliance. The CSA has mandated that EY Ghana settle the penalty within 14 days from the final enforcement directive. Additionally, EY Ghana has been ordered to cease offering all regulated cybersecurity services without a licence, including Governance, Risk, and Compliance (GRC) services, and to provide written confirmation that such services have been halted. The company is also required to finalize its application for a CSP licence.
The CSA emphasized that the application process itself does not grant the right to operate as a Cybersecurity Service Provider and reiterated that all entities must acquire the necessary licence before offering regulated cybersecurity services. Moreover, the Authority stated that a service provider's size, reputation, or client base does not exempt it from complying with national cybersecurity laws.
The CSA will continue to monitor compliance and take necessary actions against institutions that engage unlicensed providers, as well as those offering cybersecurity services without the requisite licence. Enforcement measures may include administrative sanctions, legal proceedings, and public disclosure of unlicensed service providers' names where legally permissible.
The Authority has also urged organizations, particularly those managing Critical Information Infrastructure, to ensure they procure cybersecurity services exclusively from licensed providers. It emphasized that cybersecurity licensing is a legal obligation, not merely an administrative procedure, and all institutions and service providers must comply with this requirement to operate within the legal framework.