EY Ghana Fined GHS 360,000 for Cybersecurity Licensing Breaches

    Cyber Security Authority imposes penalty on global firm for operating without required licence, affecting critical infrastructure.

    2 min read3 min listen
    EY Ghana Fined GHS 360,000 for Cybersecurity Licensing Breaches

    The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GHS 360,000 for providing regulated cybersecurity services without a valid licence.

    This significant penalty follows EY Ghana's continued provision of cybersecurity services, including to owners of Critical Information Infrastructure (CII), despite regulatory directives. The CSA had directed EY Ghana on March 20, 2026, to apply for a Cybersecurity Service Provider (CSP) licence within 15 days. However, the company failed to comply with three separate directives issued by the Authority.

    This enforcement action highlights Ghana's commitment to strengthening its digital infrastructure and regulatory oversight in the technology sector. The Cybersecurity Act, 2020 (Act 1038), forms a crucial part of Ghana's broader economic strategy to foster a secure digital economy. Robust cybersecurity measures are essential for attracting foreign investment and ensuring the stability of financial markets and essential services. The CSA's firm stance underscores the importance of compliance for all entities operating within this critical domain.

    The CSA stated that the breaches fell under Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038). These sections prohibit providing regulated cybersecurity services without a licence and outline sanctions for failing to comply with CSA directives. The Authority imposed 10,000 penalty units, equivalent to GHS 120,000, for each of the three instances of non-compliance, totalling GHS 360,000.

    EY Ghana must pay the penalty within 14 calendar days of the final enforcement directive. The company has also been ordered to immediately cease providing regulated cybersecurity services without the required licence. This includes Governance, Risk and Compliance (GRC) services. The CSA will monitor compliance closely, with potential for further administrative sanctions or court proceedings against non-compliant entities. This action signals a clear message to all market participants that regulatory adherence is non-negotiable, impacting investor confidence and operational stability for businesses in Ghana's digital landscape.

    The CSA stressed that merely submitting a licence application does not authorise an entity to operate as a CSP. Providers must obtain the requisite licence before commencing regulated cybersecurity services. This requirement is particularly important for services provided to owners of CII. These systems are essential to national security, the economy, and the delivery of essential services. The Authority reiterated that the size, reputation, expertise, or clientele of a service provider does not exempt it from Ghana's cybersecurity laws. All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA. The CSA urges organisations, especially owners of CII, to procure cybersecurity services only from licensed providers. This ongoing enforcement will protect critical systems and sensitive information across the nation.

    Comments

    More from StatsGH