CSA Fines EY Ghana GHS 360,000 for Unlicensed Cybersecurity Services

    Major accounting firm penalized for operating without required regulatory approval despite multiple directives from the Cyber Security Authority.

    2 min read3 min listen
    CSA Fines EY Ghana GHS 360,000 for Unlicensed Cybersecurity Services

    The Cyber Security Authority (CSA) has imposed a GHS 360,000 administrative penalty on Ernst & Young (EY) Ghana. This significant fine addresses the firm's provision of regulated cybersecurity services without possessing a valid license.

    EY Ghana continued offering these services despite receiving three distinct directives from the CSA. These directives explicitly required the company to obtain a Cybersecurity Service Provider (CSP) license. The penalty reflects a clear breach of regulatory requirements designed to safeguard Ghana's digital infrastructure and data integrity.

    This enforcement action by the CSA fits into Ghana's broader strategy to strengthen its digital economy and regulatory framework. The nation has seen rapid growth in digital services, necessitating robust oversight. The Cybersecurity Act, 2020 (Act 1038) established the CSA to regulate and promote cybersecurity development. This incident underscores the Authority's commitment to enforcing these critical regulations across all sectors, including professional services.

    The CSA stated that EY Ghana incurred a penalty of 10,000 penalty units for each of the three instances of non-compliance. This amounts to GHS 120,000 per instance, totaling the GHS 360,000 fine. This structured penalty system ensures accountability for repeated regulatory breaches.

    The immediate implications are clear for EY Ghana. The CSA has ordered the firm to cease providing all regulated cybersecurity services, including Governance, Risk and Compliance (GRC) services. This directive remains in effect until the company secures the necessary license. EY Ghana must pay the GHS 360,000 penalty within 14 calendar days. The firm also needs to confirm to the CSA that it has discontinued the affected services. This swift action ensures immediate compliance and prevents further unauthorized operations.

    This development sends a strong message to all entities operating within Ghana's digital space. The CSA has publicly warned other unlicensed cybersecurity providers to regularize their operations promptly. Failure to comply will result in similar enforcement actions. This regulatory push aims to create a secure and trustworthy digital environment for businesses and citizens alike. Investors and businesses must closely monitor these regulatory developments. Compliance with local laws, especially in critical sectors like cybersecurity, is paramount for operational continuity and reputation. The CSA's firm stance indicates a zero-tolerance approach to regulatory evasion. This will likely lead to increased scrutiny and compliance efforts across the industry. The Authority's actions reinforce Ghana's position as a leader in digital governance within the West African region. It also highlights the growing importance of cybersecurity in national economic stability. Businesses must prioritize obtaining all requisite licenses to avoid significant financial penalties and operational disruptions.

    Comments

    More from StatsGH