ORC Challenges Cybersecurity Sanction, Cites Procedural Unfairness

    The Office of the Registrar of Companies disputes a penalty from the Cyber Security Authority, arguing its procurement process predated new directives.

    3 min read5 min listen

    The Office of the Registrar of Companies (ORC) has formally challenged a cybersecurity sanction imposed by the Cyber Security Authority (CSA). The ORC argues that the penalty was premature and procedurally unfair, stemming from a dispute over its procurement of a Network Operations Centre (NOC) and Security Operations Centre (SOC).

    This challenge follows a CSA statement announcing sanctions against the ORC and Purpleline Solutions Limited for alleged cybersecurity non-compliance. The ORC insists its procurement process for the NOC/SOC was substantially completed before the CSA directed Critical Information Infrastructure (CII) institutions to engage Tier One licensed cybersecurity service providers. This timeline discrepancy forms the core of the ORC's objection to the sanction.

    This incident fits into Ghana's broader push to strengthen its digital infrastructure and cybersecurity defenses, a critical component for economic stability and investor confidence. The government has been investing in digital transformation, making robust cybersecurity regulations essential for protecting national data and financial systems. However, the implementation of these regulations must navigate existing procurement processes and institutional timelines to avoid unintended disruptions or legal challenges.

    The ORC stated, "The procurement and contract were already in place before the CSA issued directives requiring CII institutions, including the ORC, to engage Tier One cybersecurity companies." This statement underscores the ORC's position that it could not have complied with a requirement that had not yet been communicated during its procurement phase. The ORC also cited Articles 23 and 296 of the 1992 Constitution, emphasizing that public administrative bodies must exercise their powers fairly and reasonably.

    The dispute's resolution will have significant implications for how regulatory bodies enforce new directives, especially when they intersect with ongoing public sector procurement. Decision-makers in both the CSA and the Attorney-General's Office will need to consider the legal and reputational ramifications. This case could set a precedent for how other CII institutions manage compliance with evolving cybersecurity standards, potentially influencing future regulatory frameworks and enforcement strategies.

    The ORC's principal argument centers on the timing of the CSA's directives. The Ministry of Finance issued a Commitment Authorisation for the NOC/SOC project on November 28, 2025. The ORC then advertised the procurement in the Daily Graphic and on the Public Procurement Authority's GHANEPS platform on December 4, 2025. Bids closed on December 19, 2025, and Purpleline Solutions was recommended for the contract after an evaluation on December 22, 2025. The Central Tender Review Committee of the Ministry of Finance approved the procurement on December 31, 2025.

    The contract was eventually awarded to Purpleline Solutions and executed on February 11, 2026. The ORC highlights that the relevant CSA directives, requiring engagement with Tier One cybersecurity companies, were issued much later, specifically on May 20 and June 15, 2026. This timeline shows a gap of several months between the completion of the ORC's procurement and the issuance of the new regulatory requirements. The ORC contends that applying these subsequent directives to an already concluded procurement would amount to an unfair retrospective application of the requirement.

    Furthermore, the ORC challenges the timing of the CSA's enforcement action itself. The Authority had initially given the ORC 90 days to rectify identified cybersecurity deficiencies. The ORC claims it had already begun implementing corrective measures, resolving some issues and working on others. The ORC engaged the CSA, explaining its procurement timeline. Despite this, the CSA announced the sanction on August 12, 2026, only 57 days into the 90-day compliance period. This left 33 days before the deadline expired, which the ORC argues deprived it of the full opportunity to complete corrective measures and submit a comprehensive response.

    The public announcement of the penalty, according to the ORC, has caused reputational damage. It also argues that the CSA's public statement did not adequately reflect crucial facts, including the procurement's timing, prior approvals, and ongoing corrective actions. The ORC is seeking administrative redress, including intervention from the Attorney-General's Office. It also calls for the CSA to issue a public clarification and apology regarding the premature publication of the penalty. The ORC maintains its commitment to Ghana's cybersecurity laws and cooperation with the CSA on legitimate concerns.

    Comments

    More from StatsGH