The Cyber Security Authority (CSA) has fined accounting and business consulting firm Ernst & Young (EY) Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.
The penalty follows what the Authority described as EY Ghana’s failure to comply with repeated directives to regularise its operations under the Cybersecurity Act, 2020 (Act 1038).
In a statement issued on Tuesday, August 18, the CSA said EY Ghana continued providing cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite being directed to obtain the required licence.
The Authority said it wrote to EY Ghana on March 20, 2026, instructing the company to submit an application for a Cybersecurity Service Provider (CSP) licence within 15 days.
However, the CSA said the company failed to comply with three separate regulatory directives.
According to the Authority, the breaches contravene Sections 49 and 92 of Act 1038, which prohibit the provision of regulated cybersecurity services without the required licence and empower the CSA to sanction entities that fail to comply with its directives.
The CSA said it imposed a penalty of 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance, bringing the total administrative penalty to GH¢360,000.
EY Ghana has been given 14 calendar days from the date of the final enforcement directive to pay the penalty.
Beyond the financial sanction, the CSA has directed EY Ghana to immediately stop providing all regulated cybersecurity services without a licence, including Governance, Risk and Compliance (GRC) services and other regulated activities.
The company has also been ordered to provide written confirmation that the affected services have been discontinued and complete the process of obtaining a CSP licence.
The CSA stressed that submitting a licence application does not constitute authorisation to operate.
The Authority reiterated that cybersecurity service providers must obtain the appropriate licence before commencing regulated cybersecurity activities.
Source: citinews
