CSA fines ORC GHS 240,000 for unlicensed cybersecurity provider

    The Cyber Security Authority sanctioned the Office of the Registrar of Companies for violating directives on critical information infrastructure protection.

    2 min read3 min listen

    The Cyber Security Authority (CSA) has fined the Office of the Registrar of Companies (ORC) GHS 240,000 for engaging an unlicensed cybersecurity provider. This sanction occurred because the ORC failed to comply with cybersecurity directives. These directives require institutions designated as Critical Information Infrastructure (CII) to use only licensed Cybersecurity Service Providers.

    The CSA also fined Purpleline Solutions Limited Company GHS 120,000. Purpleline Solutions provided cybersecurity services without obtaining a license from the Authority. The ORC engaged Purpleline Solutions despite being directed to use a Tier 1 licensed Cybersecurity Service Provider. The CSA issued this directive on June 15, 2026, to strengthen the security of the ORC's Critical Information Infrastructure.

    This enforcement action highlights Ghana's commitment to securing its digital infrastructure. The Cybersecurity Act, 2020 (Act 1038), provides the legal framework for these regulations. Protecting CII is crucial for national security and economic stability. The ORC's non-compliance could have exposed sensitive company registration data to significant risks. This incident underscores the importance of adhering to regulatory standards in the rapidly evolving digital landscape.

    The CSA stated that the ORC failed to comply with two separate directives. This constitutes a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038). As a result, the ORC received a fine of 10,000 penalty units for each instance of non-compliance. This amounted to the total fine of GHS 240,000. The ORC must now comply with the outstanding directives within one month of receiving the sanction letter.

    Purpleline Solutions Limited Company was sanctioned for providing cybersecurity services without the required license. The company applied for a license on July 15, 2026. This was after the CSA determined that Purpleline was already providing services to the ORC. The Authority emphasized that submitting an application does not grant a license. It also does not authorize an entity to provide regulated cybersecurity services. Purpleline Solutions Limited Company received a fine of 10,000 penalty units, equivalent to GHS 120,000.

    This enforcement action sends a clear message to both public and private sector entities. All organizations must verify the licensing status of cybersecurity service providers before awarding contracts. The CSA will continue to monitor compliance across all sectors. It will take enforcement action against institutions that engage unlicensed providers. It will also act against companies providing services without the requisite license. This vigilance is essential for maintaining a secure and resilient digital environment in Ghana. Businesses and government agencies must prioritize compliance to avoid similar penalties and protect critical data.

    The implications extend beyond financial penalties. Non-compliance can lead to data breaches, reputational damage, and loss of public trust. The CSA's firm stance indicates a zero-tolerance policy for cybersecurity negligence. Decision-makers in other CII institutions will likely review their current cybersecurity contracts. They will ensure their providers are fully licensed and compliant. This incident serves as a critical reminder of the legal obligations under the Cybersecurity Act. It reinforces the need for robust cybersecurity governance across Ghana's economy.

    Comments

    More from StatsGH