The Cyber Security Authority (CSA) has fined EY Ghana GH¢360,000 following alleged breaches of Ghana’s cybersecurity licensing requirements.
In a statement, the CSA said EY Ghana continued providing regulated cybersecurity services, including services to owners of Critical Information Infrastructure, without a valid Cybersecurity Service Provider (CSP) licence.
The Authority said it had directed EY Ghana, in correspondence dated March 20, 2026, to submit an application for a CSP licence within 15 days. It subsequently determined that the company had failed to comply with three separate regulatory directives.
Each instance attracted a penalty of 10,000 penalty units, equivalent to GH¢120,000, bringing the total administrative penalty to GH¢360,000. EY Ghana has 14 calendar days to pay the fine.
The CSA has also ordered EY Ghana to immediately cease providing regulated cybersecurity services without the required licence, including Governance, Risk and Compliance (GRC) services.
The company, it added, must also confirm in writing that the affected services have stopped and complete its CSP licence application.
The Authority stressed that submitting an application does not give an entity the right to provide regulated cybersecurity services.
“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate.”
The CSA further warned that no cybersecurity provider is exempt from the licensing regime because of its size, reputation, expertise or clientele.
It said, “The CSA hereby issues a strong warning to all organisations and professionals providing regulated cybersecurity services without the requisite licence to cease such services and regularise their operations immediately.”
The Authority said it would continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity.
Source: Starrfm.com.gh

