The Cyber Security Authority (CSA) has imposed a combined fine of GH₵360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for severe breaches of the country’s cybersecurity licensing and compliance regulations. The sanctions, announced in a press release dated August 12, 2026, underscore the Authority’s growing determination to enforce the Cybersecurity Act, 2020 (Act 1038), particularly concerning the protection of state critical information infrastructure.
Two Entities, Two Violations
The ORC, a key state agency responsible for the registration and regulation of businesses in Ghana, has been fined GH₵240,000—equivalent to 10,000 penalty units for each of two separate instances of non-compliance. The CSA found that the ORC failed to abide by two distinct directives requiring it to engage a Tier One licensed Cybersecurity Service Provider to safeguard its Critical Information Infrastructure (CII). As a designated CII operator, the ORC is legally obligated to implement robust security measures to protect its digital systems from cyber threats, data breaches, and potential disruptions.
Instead of following the law, the ORC contracted Purpleline Solutions Limited, a company that was not licensed by the CSA to provide cybersecurity services. This engagement, the Authority stated, was in direct contravention of Section 66(1) of Act 1038, which mandates that any entity providing cybersecurity services must be duly registered and licensed.
Purpleline’s Belated Application
In a further revelation, the CSA disclosed that Purpleline Solutions Limited only applied for a cybersecurity service licence on July 15, 2026—well after it had already been engaged by the ORC. The company’s failure to secure a licence before offering its services constitutes a separate and serious offence. Consequently, Purpleline has been fined GH₵120,000, representing 5,000 penalty units for operating without the required authorisation.
The CSA noted that the licence application was submitted only after the Authority had already initiated its compliance review, suggesting an attempt to retroactively legitimise an ongoing breach.
The Legal Framework and Penalties
Under the Cybersecurity Act, 2020, the CSA is empowered to issue directives, conduct audits, and impose penalties for non-compliance. Each penalty unit is currently valued at GH₵12, as prescribed by law, meaning the ORC’s fine of 10,000 units per breach totals 20,000 units, or GH₵240,000. Purpleline’s fine of 5,000 units equals GH₵120,000.
The sanctions serve as a stark warning to all public institutions and private firms: the CSA will not tolerate the use of unlicensed service providers, especially when handling systems designated as critical infrastructure. The designation of CII applies to entities whose disruption could have a significant impact on national security, public safety, or economic stability—and the ORC, with its vast database of company registrations and financial filings, clearly falls into that category.
A Broader Context of Accountability
The fines come at a time when the CSA has been stepping up its oversight activities across both public and private sectors. In recent months, the Authority has issued compliance notices to several financial institutions, telecommunications companies, and government agencies, demanding they upgrade their cyber defences and use only accredited vendors.
Separately, the CSA is also handling a petition from businessman George Essandoh, who has accused unnamed parties of publishing false and defamatory content about him on digital platforms. While unrelated to the ORC case, that petition highlights the Authority’s dual mandate: regulating cybersecurity service providers and addressing online content violations.
Implications for Public Trust
The ORC’s breach is particularly concerning given its role as the custodian of Ghana’s corporate registry. A cyberattack on its systems could compromise the integrity of business records, facilitate fraudulent company registrations, and expose sensitive taxpayer data. By outsourcing its security to an unlicensed firm, the ORC not only violated the law but also potentially placed the entire business registration ecosystem at risk.
Both entities have been given the opportunity to pay the fines within the stipulated timeframe. Failure to do so, the CSA warned, could lead to further legal action, including criminal prosecution for directors and officers involved.
A Call for Vigilance
The CSA has reiterated that all designated CII operators must immediately review their cybersecurity service contracts to ensure their vendors are properly licensed. The Authority has also published a list of accredited Tier One service providers on its official website to guide institutions in making compliant choices.
As Ghana continues its digital transformation journey, the enforcement of cybersecurity laws becomes ever more critical. The sanctions against the ORC and Purpleline Solutions Ltd send a clear message: shortcuts in cyber defence will be met with heavy penalties, and the era of impunity in digital governance is coming to an end.




