The Cyber Security Authority (CSA) has imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.
The penalty follows what the Authority described as EY Ghana’s continued provision of cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives to comply with Ghana’s cybersecurity licensing regime.
According to the CSA, EY Ghana was directed in correspondence dated March 20, 2026, to submit an application for a CSP licence within 15 days. The Authority subsequently determined that the firm had failed to comply with three separate regulatory directives.
The CSA said the conduct constitutes breaches of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which prohibit the provision of regulated cybersecurity services without the requisite licence and provide sanctions for failure to comply with directives issued by the Authority.
Under Sections 49(2), 92(2), and 93 of Act 1038, the CSA imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance.
This brings the total administrative penalty to GH¢360,000, which EY Ghana has been directed to pay within 14 calendar days from the date of the final enforcement directive.
The Authority has also issued an immediate cease-and-desist directive requiring EY Ghana to stop providing all regulated cybersecurity services without the requisite licence, including Governance, Risk and Compliance (GRC) services.
The firm has further been directed to provide written confirmation to the CSA that the affected services have ceased and to complete the application process for a CSP licence.
The CSA stressed that submitting a licence application does not authorise an entity to operate as a cybersecurity service provider.
“An application for a licence does not confer a licence to operate as a Cybersecurity Service Provider. Entities are required to obtain the requisite licence from the CSA before commencing the provision of regulated cybersecurity services,” the Authority said.
The enforcement action forms part of a broader regulatory push by the CSA to ensure that organisations providing cybersecurity services in Ghana meet statutory licensing requirements, particularly where those services involve critical infrastructure.
The Authority said compliance is especially important when cybersecurity services are provided to owners of Critical Information Infrastructure because the security and resilience of such systems have direct implications for national security, the economy, and the delivery of essential services.
“The Authority therefore makes clear that the size, reputation, expertise, or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws. All Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under Act 1038 and directives issued by the CSA,” the CSA said.
The warning extends beyond EY Ghana to other firms and professionals operating in the cybersecurity space without the required licence.
The CSA urged all organisations and professionals providing regulated cybersecurity services without a licence to immediately cease such activities and regularise their operations.
It also warned that enforcement action could be taken against both unlicensed service providers and institutions that engage them.
“The Authority will continue to monitor compliance and take enforcement action against both institutions that engage unlicensed providers and entities that provide cybersecurity services without the requisite licence,” it said.
“Where necessary, such action may include administrative sanctions, court proceedings and publication of the names of unlicensed service providers, as permitted by law,” the Authority added.
The CSA also called on organisations, particularly owners of Critical Information Infrastructure, to ensure that cybersecurity services are procured only from appropriately licensed providers.
“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate,” the Authority said.
The Authority said it would continue to use its regulatory powers to ensure that organisations entrusted with critical systems and sensitive information meet their cybersecurity obligations.
It has urged organisations seeking clarification on licensing requirements or the scope of regulated cybersecurity services to contact the Cyber Security Authority.
