CSA fines EY Ghana GH¢360,000 over licence breach
Ghana's Cyber Security Authority says EY Ghana provided regulated cybersecurity services without the required licence, including services to organisations responsible for critical national infrastructure.
Ghana's Cyber Security Authority (CSA) has fined Ernst & Young Ghana (EY Ghana) GH¢360,000 for providing regulated cybersecurity services without a valid licence.
The regulator said the company continued to provide cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives to comply with Ghana's cybersecurity licensing requirements.
The penalty was imposed under the Cybersecurity Act, 2020 (Act 1038).
The CSA said the action followed several attempts to get EY Ghana to regularise its operations.
What did EY Ghana do?
According to the CSA, it wrote to EY Ghana on March 20 2026, directing the company to submit an application for a Cybersecurity Service Provider (CSP) licence within 15 days.
The regulator said EY Ghana subsequently failed to comply with three separate regulatory directives.
It said the conduct amounted to breaches of sections 49 and 92 of the Cybersecurity Act.
Section 49 prohibits the provision of regulated cybersecurity services without the required licence, while section 92 provides sanctions for failing to comply with directives issued by the CSA.
The regulator has now imposed three separate penalties.
Each amounts to 10,000 penalty units, equivalent to GH¢120,000, bringing the total to GH¢360,000.
EY Ghana ordered to stop services
The CSA has also issued an immediate cease-and-desist directive against the company.
EY Ghana has been ordered to stop providing regulated cybersecurity services without the required licence.
The directive includes Governance, Risk and Compliance (GRC) services, according to the regulator.
The company must also provide written confirmation to the CSA that the affected services have stopped and complete the application process for a CSP licence.
The penalty must be paid within 14 calendar days of the final enforcement directive.
The CSA stressed that simply applying for a licence does not authorise an organisation to operate as a cybersecurity service provider.
Companies must first obtain the licence before providing regulated cybersecurity services.
Why the regulator says the case matters
The CSA said its action was particularly important because some of the services provided by EY Ghana involved organisations designated as owners of Critical Information Infrastructure.
These include systems and services considered important to Ghana's national security, economy and delivery of essential services.
The regulator said organisations operating in this area needed to ensure that cybersecurity providers met the country's licensing requirements.
It warned that the size, reputation or expertise of a company did not exempt it from the law.
"All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements," the CSA said.
Warning to other cybersecurity providers
The action against EY Ghana comes with a wider warning from the regulator.
The CSA has directed organisations and professionals providing regulated cybersecurity services without a valid licence to stop doing so and regularise their operations.
It said it would continue monitoring compliance and take enforcement action against companies that provide regulated cybersecurity services without the required licence.
Possible sanctions include administrative penalties, court proceedings and publication of the names of unlicensed service providers, where permitted by law.
The regulator has also urged organisations, particularly owners of Critical Information Infrastructure, to obtain cybersecurity services only from providers that are properly licensed.
What is the cybersecurity licensing system?
Ghana's Cybersecurity Act, 2020 established a regulatory framework for cybersecurity services and gave the CSA powers to license and supervise providers operating in the sector.
The licensing system is intended to ensure that organisations handling cybersecurity work meet prescribed professional and regulatory requirements.
The CSA says licensing should not be treated simply as an administrative procedure.
It is intended to help ensure that organisations responsible for sensitive systems and information receive services from providers that meet Ghana's legal requirements.
The enforcement action against EY Ghana therefore goes beyond the financial penalty.
It signals that the regulator intends to apply the licensing requirements to established international professional-services firms as well as smaller cybersecurity providers.