The Cyber Security Authority (CSA) has fined EY Ghana GH¢360,000 for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.
According to the CSA, EY Ghana continued providing cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite repeated directives to comply with Ghana’s cybersecurity licensing requirements.
The Authority said it directed EY Ghana in March 2026 to submit an application for a CSP licence within 15 days but subsequently found the company had failed to comply with three separate regulatory directives.
The three breaches attracted a penalty of 10,000 penalty units each, equivalent to GH¢120,000 per violation, bringing the total administrative penalty to GH¢360,000. EY Ghana has been given 14 calendar days to pay the fine.
The CSA has also ordered the company to immediately stop providing regulated cybersecurity services without the required licence.
The directive covers Governance, Risk and Compliance (GRC) services, among others. EY Ghana is also required to confirm in writing that the affected services have ceased and complete the process of obtaining a CSP licence.
The Authority stressed that merely applying for a licence does not authorise an organisation to provide regulated cybersecurity services.
“The message is clear: cybersecurity licensing is a legal requirement, not an administrative formality. Institutions must comply, and service providers must be licensed before they operate.”
The CSA further warned that the size, reputation or expertise of a service provider does not exempt it from Ghana’s cybersecurity laws.
It said it would continue monitoring compliance and take enforcement action against both organisations that engage unlicensed providers and entities that provide cybersecurity services without the required licence. Such action, where necessary, could include administrative sanctions, court proceedings and publication of the names of unlicensed providers.
The Authority has also urged owners of Critical Information Infrastructure and other organisations to ensure that cybersecurity services are procured only from appropriately licensed providers.


































