Tuesday, August 18, 2026
spot_img
HomenewsEY Ghana fines GHc360,000 for unlicensed cybersecurity services;CSA warns big four reputation...

EY Ghana fines GHc360,000 for unlicensed cybersecurity services;CSA warns big four reputation no shield

The Cyber Security Authority (CSA) has slapped global professional services firm Ernst & Young (EY) Ghana with a GH¢360,000 administrative penalty for providing regulated cybersecurity services without a valid operating licence, in what marks one of the heaviest fines levied against a multinational corporation under the country’s landmark digital security laws.

In a firm enforcement directive issued on August 18, the CSA revealed that EY Ghana continued to offer regulated services—including critical Governance, Risk and Compliance (GRC) advisory—to owners of Critical Information Infrastructure (CII), despite receiving repeated instructions to regularise its operations. The Authority noted that the firm had been issued a directive on March 20, 2026, demanding it submit a Cybersecurity Service Provider (CSP) licence application within 15 days. However, subsequent investigations showed that EY failed to comply with three separate regulatory directives, demonstrating a persistent disregard for statutory obligations.

The Legal Framework and Penalty Breakdown

The offences constitute direct breaches of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which govern the provision of cybersecurity services and outline sanctions for non-compliance. Under Sections 49(2), 92(2) and 93 of the Act, the Authority imposed a penalty of 10,000 penalty units for each of the three instances of non-compliance. With the current statutory value of a penalty unit pegged at GH¢12.00 in Ghana, each infraction attracts a GH¢120,000 fine, culminating in the total GH¢360,000 liability.

Strict Directives to Cease Operations

The CSA has ordered EY Ghana to settle the penalty within 14 calendar days from the date of the final enforcement directive. Furthermore, the firm has been directed to immediately cease providing all regulated cybersecurity services—particularly GRC services—without the requisite licence. The Authority has further commanded EY to provide written confirmation of the cessation of these services while simultaneously completing the formal application process for a CSP licence.

In a sharp clarification, the CSA underscored that an application is not a substitute for authorisation, warning: “An application for a licence does not confer a licence to operate.” Service providers must obtain explicit approval before offering regulated cybersecurity services.

Critical Information Infrastructure at Risk

The enforcement action carries significant national security implications. The CSA specifically highlighted the firm’s provision of services to owners of Critical Information Infrastructure—systems covering essential sectors such as banking, telecommunications, energy, healthcare, and government networks. Disruption to these systems could cripple the economy and compromise national security, making compliance in this area paramount.

Global Reputation No Exemption

In a pointed rebuke to the “Big Four” accounting giant, the CSA stated unequivocally that neither brand size, global reputation, technical expertise, nor high-profile clientele offers immunity from Ghanaian law. “The size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws,” the Authority declared.

Industry-Wide Warning

The CSA has extended the warning to the broader cybersecurity ecosystem in Ghana, directing all unlicensed operators to immediately cease regulated services and regularise their operations. The Authority has put both unlicensed providers and the institutions that engage them on notice, threatening administrative sanctions, court proceedings, and the public publication of offenders’ names where legally permissible.

“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality,” the CSA stated. “Institutions must comply, and service providers must be licensed before they operate.”

Context and Implications

The penalty comes as the CSA intensifies its regulatory oversight of Ghana’s rapidly growing digital security landscape. Act 1038 was enacted to establish a robust legal framework to protect the nation’s digital infrastructure. For EY Ghana, this regulatory setback raises potential reputational and contractual risks, as CII owners are now urged—and likely compelled by internal compliance policies—to sever ties with unlicensed vendors immediately.

The Authority has made it clear that it will continue rigorous monitoring, warning that failure to comply by EY or any other party could escalate beyond administrative fines to include criminal prosecution and public blacklisting.

Try our mobile app

Never miss an update. Read anytime, anywhere with our mobile app.

ios
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -spot_img

Most Popular