Bank of Ghana rolls out sweeping cyber directive to reset financial sector security

Bank of Ghana rolls out sweeping cyber directive to reset financial sector security

The Bank of Ghana has introduced a far-reaching regulatory overhaul aimed at strengthening cybersecurity across Ghana’s financial sector, signalling a decisive shift in how institutions manage digital risk. Launched in Accra, the Cyber and Information Security Directive (CISD) 2026 replaces the country’s 2018 framework...

Winifred Lartey
Apr 15
Bank of Ghana rolls out sweeping cyber directive to reset financial sector security

The Bank of Ghanahas introduced a far-reaching regulatory overhaul aimed at strengthening cybersecurity across Ghana’s financial sector, signalling a decisive shift in how institutions manage digital risk.

Launched in Accra, the Cyber and Information Security Directive (CISD) 2026 replaces the country’s 2018 framework, which regulators say has been overtaken by rapid technological change and evolving cyber threats.

Governor Dr. Johnson Pandit Asiama made the rationale clear at the launch, warning that existing rules were no longer adequate for the current threat environment.

“A framework designed for the challenges of 2018 cannot adequately solve the problems of 2026,” he said.

The directive applies to a broad range of institutions, including commercial banks, microfinance companies, fintech firms, and payment service providers, bringing the entire financial ecosystem under a unified cybersecurity regime.

A key feature of the new framework is the expanded role of the Financial Industry Command Security Operations Centre (FICSOC), established under the Cybersecurity Act 2020. The centre will now extend its oversight to non-bank financial institutions, closing regulatory gaps previously exploited by cybercriminals.

CISD 2026 is built around six strategic pillars designed to move the sector beyond basic compliance toward what regulators describe as “active and collective cyber resilience.”

The directive introduces governance requirements for artificial intelligence and machine learning systems used in areas such as fraud detection and credit scoring, ensuring they are secure, transparent, and fair.

It also imposes strict rules on cloud computing, allowing only non-sensitive operations to be hosted externally. Core systems and critical customer data must remain within Ghana, in line with provisions in the Data Protection Act 2012.

This data localisation requirement is expected to pose challenges for institutions that have migrated infrastructure to global providers such as Amazon Web Services, Microsoft Azure, and Google Cloud, which currently operate data centres outside Ghana.

The directive also elevates cybersecurity oversight to the highest levels of corporate governance, requiring boards to take direct responsibility for cyber risk rather than delegating it solely to IT departments.

To address disparities in capacity, the framework introduces a proportional approach, tailoring compliance requirements to the size and risk exposure of institutions, particularly smaller lenders and fintech startups.

Industry stakeholders have broadly welcomed the move. Chief Executive Officer of the Ghana Association of Banks, John Awuah, stressed the importance of closing systemic vulnerabilities.

“In cybersecurity, one small broken chain can be the entry route for a cyber miscreant to gain access to the bigger architecture,” he said.

Despite support for the directive, concerns remain about the cost of implementation, particularly for smaller institutions operating on limited budgets.

The Bank of Ghana has already absorbed the initial costs of establishing FICSOC, but industry players are expected to contribute to its long-term sustainability as the system expands.

Beyond financial implications, institutions will need to undertake significant operational adjustments, including restructuring IT systems, reviewing data storage practices, and strengthening internal cyber expertise.

While the directive has been welcomed as a necessary step, the real test lies in execution.

Financial institutions must now assess their current systems, especially those reliant on offshore cloud infrastructure, and align them with the new requirements.

At the governance level, boards will need to build capacity to manage cyber risk effectively, while the broader ecosystem integrates into FICSOC’s expanded framework.

The directive represents Ghana’s most comprehensive attempt in nearly a decade to future-proof its financial system against cyber threats — a move regulators believe is essential as digital finance continues to expand.

Whether the sector can adapt quickly enough to meet the new standards will determine the success of the overhaul.

Comments

Join the conversation.

Log in to join the conversation.

No comments yet. Be the first to start the discussion.

Trending Now