Registrar of Companies fined GHS 240,000 for cybersecurity breach

    The Cyber Security Authority sanctioned the ORC for engaging an unlicensed cybersecurity provider, highlighting strict compliance requirements.

    2 min read3 min listen

    The Office of the Registrar of Companies (ORC) has received a GHS 240,000 fine from the Cyber Security Authority (CSA). This sanction occurred because the ORC engaged an unlicensed cybersecurity service provider, Purpleline Solutions Limited. The ORC failed to comply with directives requiring it to use only appropriately licensed providers for its critical information infrastructure.

    The CSA determined the ORC violated Section 92 of the Cybersecurity Act, 2020 (Act 1038). The ORC, designated as a Critical Information Infrastructure (CII) institution, was specifically directed on June 15, 2026, to engage Tier 1 licensed Cybersecurity Service Providers (CSPs). Despite these clear instructions, the ORC proceeded to contract Purpleline Solutions Limited, which did not hold the required license.

    This enforcement action highlights Ghana's increasing focus on digital security and regulatory compliance. The nation is actively building its cybersecurity framework to protect vital digital assets and services. Incidents like this demonstrate the government's resolve to ensure all institutions, especially those managing critical data, adhere to established cybersecurity protocols. This aligns with broader efforts to enhance Ghana's digital economy and protect against cyber threats.

    The CSA stated that the ORC failed to comply with two separate directives. Consequently, the ORC received a fine of 10,000 penalty units for each instance of non-compliance, totaling GHS 240,000. The Authority also sanctioned Purpleline Solutions Limited, fining the company GHS 120,000 for providing cybersecurity services without a license. Purpleline applied for a license on July 15, 2026, only after the CSA identified its engagement with the ORC.

    This development sends a strong message to both public and private sector entities. Institutions must verify the licensing status and appropriate tier of cybersecurity service providers before awarding contracts. The CSA has warned that an application for a license does not authorize a company to operate as a CSP. This strict stance aims to prevent future breaches and ensure the integrity of Ghana's digital infrastructure. Decision-makers and market participants will closely watch how other institutions respond to these heightened compliance expectations.

    The CSA will continue to monitor compliance and take enforcement action against non-compliant entities. Cybersecurity licensing is a legal requirement, not merely an administrative formality, according to the Authority. This regulatory push is crucial for Ghana's economic stability and its ambition to become a digital hub. Protecting critical systems and sensitive information is paramount for national security and economic growth.

    The fines imposed reflect the seriousness with which the CSA views these infractions. Each penalty unit is equivalent to a specific monetary value, ensuring a consistent application of sanctions. The ORC has one month to comply with the outstanding directives from the CSA. This timeline puts pressure on the ORC to quickly rectify its non-compliance and secure its systems appropriately. This incident serves as a critical reminder for all organizations handling sensitive data in Ghana.

    Comments

    More from StatsGH