EY Ghana Fined GH₵360,000 for Unlicensed Cybersecurity Services
Translated from English, summarized and contextualized by DistantNews.
At a glance
- Ernst & Young (EY) Ghana has been fined GH₵360,000 by the Cyber Security Authority (CSA) for operating without a license.
- The company continued to provide cybersecurity services, including to critical infrastructure, despite repeated directives to obtain a license.
- EY Ghana failed to comply with three separate regulatory directives, breaching cybersecurity laws.
The Cyber Security Authority (CSA) has imposed a significant administrative penalty of GH₵360,000 on Ernst & Young (EY) Ghana. The fine was levied because the company provided cybersecurity services without possessing the required valid license.
This action stems from EY Ghana's persistent provision of cybersecurity services, notably including services to owners of Critical Information Infrastructure (CII). This occurred despite the CSA issuing multiple directives mandating compliance with the licensing regime established under the Cybersecurity Act, 2020 (Act 1038).
Specifically, the CSA had formally directed EY Ghana on March 20, 2026, to submit an application for a Cybersecurity Service Provider (CSP) license within fifteen days. The Authority later determined that EY Ghana failed to adhere to three distinct regulatory directives. This non-compliance constitutes a violation of Sections 49 and 92 of Act 1038, which prohibit unlicensed cybersecurity services and outline sanctions for failing to follow CSA directives.
The enforcement action underscores the CSA's commitment to regulating the cybersecurity sector and ensuring that all providers meet the necessary legal and operational standards to protect critical national infrastructure and sensitive data.
Originally published by Daily Graphic in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.