CSA fines EY Ghana GH¢360,000 over unlicensed cybersecurity services
The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence. The authority said the penalty followed EY Ghana’s failure to comply with directives to regularise its operations under Ghana’s cybersecurity regulatory framework. The...

The Cyber Security Authority (CSA) has fined Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.
The authority said the penalty followed EY Ghana’s failure to comply with directives to regularise its operations under Ghana’s cybersecurity regulatory framework.
The CSA said it directed the company in March 2026 to apply for a cybersecurity service provider licence within fifteen days.
However, the authority said EY Ghana subsequently failed to comply with three separate directives.
The CSA has imposed 10,000 penalty units, equivalent to GH¢120,000, for each breach, bringing the total penalty to GH¢360,000.
EY Ghana has 14 calendar days from the date of the final enforcement directive to pay the penalty.
The company has also been ordered to stop providing regulated cybersecurity services until it obtains the required licence.
This includes governance, risk and compliance services.
The CSA said EY Ghana must also confirm in writing that it has stopped the affected services and complete the licensing process.
The authority stressed that submitting an application does not amount to authorisation to operate as a cybersecurity service provider.
It said entities must obtain the required licence before providing regulated cybersecurity services.
The CSA said the matter was particularly concerning because the services in question included work for owners of Critical Information Infrastructure, which it said are vital to Ghana’s national security, economy and essential services.
The authority has consequently warned all unlicensed cybersecurity service providers to stop operating and regularise their businesses.
It also warned organisations against engaging unlicensed providers, saying enforcement action could be taken against both sides.
The CSA said sanctions could include administrative penalties, court proceedings and, where legally permitted, publication of the names of unlicensed service providers.
The authority has urged organisations, particularly owners of Critical Information Infrastructure, to verify the licensing status of cybersecurity service providers before engaging them.