Ghana's Cyber Security Authority (CSA) has imposed a total fine of GHS 360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited. This significant penalty addresses breaches of cybersecurity licensing regulations, highlighting the Authority's strict enforcement of the Cybersecurity Act, 2020 (Act 1038).
The ORC received a GHS 240,000 fine for failing to comply with directives to engage a Tier 1 licensed Cybersecurity Service Provider (CSP). Despite clear instructions, the ORC proceeded to contract Purpleline Solutions, which lacked the required license. Purpleline Solutions Limited was separately fined GHS 120,000 for providing cybersecurity services without proper authorization from the CSA. These sanctions emphasize the critical importance of adhering to regulatory frameworks designed to protect Ghana's digital infrastructure.
This enforcement action by the CSA fits into Ghana's broader strategy to strengthen its digital economy and protect critical national assets. The Cybersecurity Act, 2020, was enacted to create a secure digital environment, fostering trust and investment in technology. Ensuring compliance with licensing requirements for cybersecurity service providers is a cornerstone of this strategy, safeguarding sensitive data and preventing cyber threats that could impact economic stability. The CSA's proactive stance reflects a growing global trend towards robust cybersecurity governance.
The CSA stated that the ORC failed to comply with two separate directives, violating Section 92 of the Cybersecurity Act, 2020. Under Section 92(2) of the Act, the ORC was fined 10,000 penalty units for each instance of non-compliance. Purpleline Solutions Limited was fined 10,000 penalty units for operating without the required license. The Authority has warned all institutions against engaging unlicensed providers and cautioned companies against offering regulated cybersecurity services without proper authorization.
The immediate implication is that other institutions designated as Critical Information Infrastructure (CII) will likely face increased scrutiny regarding their cybersecurity service providers. The CSA has directed the ORC to comply with outstanding directives within one month, indicating a firm deadline for rectification. This move will compel organizations to verify the licensing status and appropriate tier of cybersecurity providers before awarding contracts. The market for licensed cybersecurity services is expected to see increased demand as institutions seek to avoid similar penalties and ensure compliance with the law.
The CSA's actions send a clear message to both public and private sector entities: cybersecurity licensing is a legal requirement, not merely an administrative formality. This enforcement will likely lead to a more regulated and secure cybersecurity landscape in Ghana. Decision-makers and market participants will be closely watching for further enforcement actions and increased compliance efforts across various sectors. The Authority will continue monitoring compliance and taking enforcement action against non-compliant entities.