Ghana Cyber Security Authority Fines EY Ghana GH¢360,000 for Unlicensed Services
According to the Authority, EY Ghana was specifically directed in correspondence dated 20 March 2026 to apply for a CSP licence within 15 days.
Ghana’s Cyber Security Authority (CSA) has imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.
The CSA said the action followed EY Ghana’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives to comply with licensing requirements under the Cybersecurity Act, 2020 (Act 1038).
According to the Authority, EY Ghana was specifically directed in correspondence dated 20 March 2026 to apply for a CSP licence within 15 days. The company subsequently failed to comply with three separate regulatory directives issued by the CSA.
The Authority said the conduct constitutes breaches of Sections 49 and 92 of Act 1038, which prohibit the provision of regulated cybersecurity services without the required licence and provide sanctions for failure to comply with directives issued by the CSA.
Under the administrative penalty, EY Ghana was fined GH¢120,000 for each of three instances of non-compliance, resulting in a total penalty of GH¢360,000. The company has been directed to pay the amount within 14 calendar days of the final enforcement directive.
The CSA has also ordered EY Ghana to immediately cease and desist from providing regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services. The company must provide written confirmation that the affected services have ceased and complete the application process for a CSP licence.
The Authority stressed that applying for a licence does not authorise an entity to operate as a Cybersecurity Service Provider. Companies must obtain the requisite licence from the CSA before commencing regulated cybersecurity services.
The CSA also issued a broader warning to institutions and service providers, stressing that compliance is particularly important where cybersecurity services are provided to owners of Critical Information Infrastructure because the security and resilience of such systems are considered essential to Ghana’s national security and economy.
The Authority said the reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws. It warned organisations and professionals providing regulated cybersecurity services without the required licence to cease such activities immediately.
The CSA said it will continue monitoring compliance and taking enforcement action against unlicensed providers. Such action could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers where necessary.
The Authority urged organisations, particularly owners of Critical Information Infrastructure, to obtain cybersecurity services only from appropriately licensed providers and reiterated that cybersecurity licensing is a legal requirement rather than an administrative formality.

