The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.
The administrative penalty follows what the CSA described as EY Ghana’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives from the Authority to comply with Ghana’s cybersecurity licensing requirements.
According to the CSA, EY Ghana was specifically directed in a letter dated March 20, 2026, to submit an application for a CSP licence within 15 days.
The Authority said EY Ghana subsequently failed to comply with three separate regulatory directives.
The conduct, according to the CSA, constitutes breaches of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which prohibit the provision of regulated cybersecurity services without the required licence and provide sanctions for failure to comply with directives issued by the Authority.
GH¢360,000 penalty
The CSA said it imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance.
This brings the total administrative penalty to GH¢360,000.
EY Ghana has been directed to pay the penalty within 14 calendar days from the date of the final enforcement directive.
Cease-and-desist order
In addition to the financial penalty, the CSA has ordered EY Ghana to immediately cease and desist from providing all regulated cybersecurity services without the requisite licence.
The directive includes Governance, Risk and Compliance (GRC) services.
EY Ghana has also been directed to provide written confirmation to the CSA that the affected services have ceased and complete the application process for a CSP licence.
The CSA stressed that submitting an application does not amount to obtaining a licence and does not authorise an entity to operate as a Cybersecurity Service Provider.
It said organisations must obtain the requisite licence before commencing regulated cybersecurity services.
Warning to service providers
The CSA has issued a strong warning to organisations and professionals providing regulated cybersecurity services without the required licence to stop such activities and regularise their operations immediately.
The Authority said compliance was particularly important where cybersecurity services were provided to owners of Critical Information Infrastructure because such systems are essential to Ghana’s national security, economy and the delivery of critical services.
It emphasised that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.
“All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” the Authority said.
The CSA also warned institutions that engage unlicensed cybersecurity providers that they could face enforcement action.
It said such action could include administrative sanctions, court proceedings and, where permitted by law, publication of the names of unlicensed service providers.
The Authority further urged organisations, particularly owners of Critical Information Infrastructure, to procure cybersecurity services only from appropriately licensed providers.
The CSA said cybersecurity licensing was a legal requirement rather than an administrative formality and reaffirmed its commitment to using its regulatory powers to protect Ghana’s digital ecosystem.
The statement was issued by the Cyber Security Authority in Accra on August 18, 2026.
Source: www.kumasimail.com





























































