EY Ghana Penalized GHS360,000 For Offering Unlicensed Cybersecurity Services

Accra: The Cyber Security Authority (CSA) has imposed a fine of GHS360,000 on Ernst and Young (EY) Ghana for delivering regulated cybersecurity services without possessing a valid licence. The Authority indicated that despite directives to adhere to Ghana's cybersecurity licensing requirements, the company continued to provide services to owners of Critical Information Infrastructure (CII).

According to Ghana Web, the CSA released a statement on Tuesday, August 18, 2026, clarifying that EY Ghana was instructed in a correspondence dated March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days. The statement highlighted that EY Ghana's failure to comply with three distinct regulatory directives led to the penalty.

The CSA underscored that the actions of EY Ghana contravene Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038). These sections mandate that providers of regulated cybersecurity services obtain the necessary licence and adhere to directives from the Authority. The penalty of GHS360,000 was calculated at GHS120,000 for each of the three non-compliance instances.

The CSA has mandated that EY Ghana settle the penalty within fourteen calendar days from the date of the final enforcement directive. Additionally, EY Ghana must cease offering all regulated cybersecurity services without a licence, including Governance, Risk and Compliance (GRC) services, and provide written confirmation of the cessation. They are also required to complete the application for a CSP licence.

The Authority stressed that merely applying for a licence does not permit an entity to operate as a Cybersecurity Service Provider. Obtaining the requisite licence from the CSA is a prerequisite before commencing the provision of regulated cybersecurity services.

The CSA emphasized that the size, reputation, or client base of a provider does not grant immunity from Ghana's cybersecurity laws. All Cybersecurity Service Providers in Ghana must adhere to the same regulatory requirements under Act 1038 and CSA directives.

The CSA will continue to monitor compliance and take action against institutions that engage unlicensed providers and entities that offer cybersecurity services without the required licence. Enforcement measures could include administrative sanctions, court proceedings, and potential publication of the names of unlicensed service providers, where allowed by law.

The Authority has called on organizations, particularly owners of Critical Information Infrastructure, to ensure that cybersecurity services are procured only from licensed providers. It reiterated that obtaining a cybersecurity licence is a legal obligation, not merely an administrative formality. Institutions and service providers must comply with licensing requirements before commencing operations.