The Cyber Security Authority (CSA) has imposed a GHS 360,000 administrative penalty on Ernst & Young (EY) Ghana. This penalty stems from EY Ghana providing regulated cybersecurity services without the necessary licence. The firm also failed to comply with multiple regulatory directives.
EY Ghana continued offering cybersecurity services, including to owners of Critical Information Infrastructure (CII). The CSA had directed EY Ghana on March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days. However, the firm did not regularise its operations despite these directives.
This enforcement action fits into Ghana's broader push to strengthen its digital infrastructure and protect sensitive information. The Cybersecurity Act, 2020 (Act 1038) governs cybersecurity services and outlines sanctions for non-compliance. The CSA's firm stance underscores the importance of regulatory adherence for all service providers. This includes large, reputable firms operating within Ghana's economy.
The CSA stated that EY Ghana's conduct breached Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038). The Authority imposed a penalty of 10,000 penalty units for each of three instances of non-compliance. Each unit is equivalent to GHS 12, bringing the total fine to GHS 360,000. The CSA emphasised that merely applying for a licence does not grant permission to operate.
EY Ghana must pay the GHS 360,000 penalty within 14 calendar days. The firm must also immediately cease providing all regulated cybersecurity services without a licence. This includes Governance, Risk and Compliance (GRC) services. The CSA has also ordered EY Ghana to provide written confirmation of compliance and complete its licence application process. This action sends a clear message to other unlicensed operators in Ghana's growing digital economy. The Authority will continue monitoring compliance and take enforcement action against both unlicensed providers and institutions that engage them. This could include administrative sanctions and court proceedings. Organisations, especially CII owners, must procure cybersecurity services only from licensed providers. The CSA stressed that cybersecurity licensing is a legal requirement, not a mere formality. This ensures the integrity and security of Ghana's critical digital assets and financial systems. The Authority's actions protect national security, the economy, and the delivery of essential services. This regulatory enforcement is crucial for maintaining trust and stability in Ghana's digital landscape.