The Cyber Security Authority (CSA) has imposed a GH¢360,000 administrative penalty on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid licence, after what the regulator describes as repeated failures to comply with its directives.
In an enforcement action announced on August 18, 2026, the CSA also ordered EY Ghana to immediately cease providing regulated cybersecurity services, including Governance, Risk and Compliance (GRC) services, until it obtains the required Cybersecurity Service Provider (CSP) licence.
According to the Authority, EY Ghana continued to provide cybersecurity services, including to owners of Critical Information Infrastructure (CII), despite directives requiring the company to comply with the licensing regime established under the Cybersecurity Act, 2020 (Act 1038).
The CSA said it formally directed EY Ghana on March 20, 2026, to submit an application for a CSP licence within 15 days. It subsequently established that the company had failed to comply with three separate regulatory directives.
For each instance of non-compliance, the Authority imposed 10,000 penalty units, equivalent to GH¢120,000, bringing the total administrative penalty to GH¢360,000. EY Ghana has been given 14 calendar days from the date of the final enforcement directive to pay the amount.
Beyond the financial sanction, the company has been ordered to provide written confirmation that the affected services have stopped and to complete the application process for a Cybersecurity Service Provider licence.
The CSA stressed that merely applying for a licence does not authorise a company to operate, insisting that service providers must obtain the requisite approval before offering regulated cybersecurity services in Ghana.
The regulator used the action against EY Ghana to issue a wider warning to cybersecurity companies and professionals, declaring that corporate size, reputation, expertise or clientele does not place any service provider above Ghana’s cybersecurity laws.
It said compliance is particularly important where services involve Critical Information Infrastructure because of the potential implications for national security, the economy and the delivery of essential services.
The CSA further warned that enforcement could extend beyond unlicensed providers to institutions that engage their services. Possible measures include administrative sanctions, court action and the publication of names of unlicensed providers where permitted by law.
The Authority consequently urged organisations, particularly operators of Critical Information Infrastructure, to verify the licensing status of cybersecurity firms before engaging them.
It maintained that cybersecurity licensing is a legal obligation rather than an administrative formality, warning that it will continue using its regulatory powers against institutions and service providers that fail to comply with the law.








