Cybersecurity threats are exposing the vulnerability of systems that keep essential services running, prompting Ghana to push for stronger protection of the operational technology underpinning critical infrastructure.
The Minister for Communication, Digital Technology and Innovations, Samuel Nartey George, said cybersecurity efforts must extend beyond conventional information technology (IT) networks to operational technology (OT) systems that control physical infrastructure.
“When an I.T. system is compromised, we may lose data. When an operational technology system is compromised, we may lose power, water and, in the worst cases, lives,” he said.
The Minister was speaking at a Cyber Security Authority workshop in Accra on Critical Information Infrastructure Resilience Beyond I.T.: Securing Ghana’s Operational Technology Ecosystem.
Operational technology includes industrial control systems, supervisory control and data acquisition (SCADA) platforms, sensors and field devices used to monitor and manage industrial processes. An attack on these systems could interrupt production, disrupt supply chains and increase operating costs for businesses dependent on reliable electricity, water and transport services.
Sam George said Ghana must prioritise cyber resilience, enabling critical institutions to withstand attacks, restore essential services quickly and adapt to emerging threats.

“We must move from asking, ‘How do we protect our critical systems?’ to asking, ‘How do we ensure that Ghana continues to function when our critical digital systems come under attack?’” he said.
Compliance and Accountability
The Minister disclosed that Ghana has 13 designated critical information infrastructure sectors, with approximately 200 institutions identified as owners of critical information infrastructure.
He stressed that compliance with cybersecurity requirements is mandatory and called for stronger implementation and accountability. The government, he said, would continue supporting the Cyber Security Authority’s regulatory and enforcement mandate, strengthen collaboration with sector regulators and develop the national cybersecurity workforce.
He also emphasised that responsibility for cyber resilience must extend beyond technical teams and reach senior management.
“Cyber resilience must be a whole-of-organisation responsibility, led from the top,” he said.
Businesses and public institutions must ensure their cybersecurity measures can protect essential operations and support rapid recovery when attacks occur. The government’s approach places operational continuity alongside prevention, recognising that disruptions to critical infrastructure can have consequences far beyond compromised computer networks.
