EY Ghana Cybersecurity Fine. The Cyber Security Authority (CSA) has fined EY Ghana GH¢360,000 for providing regulated cybersecurity services without a valid licence.
The penalty, announced on Tuesday, August 18, 2026, follows the Authority’s finding that EY Ghana failed to comply with three separate regulatory directives requiring the company to regularise its operations under Ghana’s cybersecurity licensing regime.
Why EY Ghana was fined GH¢360,000
According to the CSA, EY Ghana was directed on March 20, 2026, to submit an application for a Cybersecurity Service Provider (CSP) licence within 15 days.
However, the Authority said the company continued providing regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII).
The CSA subsequently determined that EY Ghana had failed to comply with three separate regulatory directives.
The Authority said the conduct amounted to breaches of Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038).
For each of the three instances of non-compliance, the CSA imposed a penalty of 10,000 penalty units, equivalent to GH¢120,000.
The three penalties resulted in a total administrative penalty of GH¢360,000.
EY Ghana ordered to stop cybersecurity services
The financial penalty is not the only action taken against EY Ghana.
The CSA has issued an immediate cease-and-desist directive, ordering the company to stop providing regulated cybersecurity services without the required licence.
The directive includes Governance, Risk and Compliance (GRC) services.
EY Ghana has also been instructed to provide written confirmation to the Authority that the affected services have stopped and to complete the process of obtaining the appropriate CSP licence.
The company has 14 calendar days from the date of the final enforcement directive to pay the GH¢360,000 penalty.
The CSA also made an important clarification: applying for a cybersecurity licence does not mean a company is licensed to operate.
According to the Authority, providers must obtain the required licence before commencing regulated cybersecurity activities.
CSA warns other cybersecurity service providers
The enforcement action against EY Ghana is also a warning to other companies and professionals operating in Ghana’s cybersecurity sector.
The CSA said the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.
All cybersecurity service providers operating in Ghana are expected to comply with the requirements of the Cybersecurity Act, 2020 (Act 1038) and directives issued by the Authority.
The Authority has therefore directed unlicensed providers to stop offering regulated cybersecurity services and regularise their operations.
It also warned that organisations that engage unlicensed providers could face enforcement action.
Such action could include administrative sanctions, court proceedings and publication of the names of unlicensed service providers where permitted by law.
Why the cybersecurity licence matters
The issue goes beyond a company’s paperwork.
Ghana’s digital economy increasingly depends on secure information systems, while organisations responsible for critical services hold large amounts of sensitive information.
The CSA has placed particular emphasis on Critical Information Infrastructure, whose systems are important to Ghana’s national security, economy and the delivery of essential services.
For these organisations, using properly licensed cybersecurity service providers is therefore an important part of managing cyber risks.
The Authority has urged organisations, particularly owners of Critical Information Infrastructure, to ensure that cybersecurity services are obtained only from appropriately licensed providers.
What the EY Ghana case means for businesses
The GH¢360,000 penalty sends a strong message to businesses operating in Ghana’s cybersecurity space.
Companies cannot assume that experience, reputation or the size of their clients allows them to operate outside the country’s cybersecurity regulatory framework.
The case also shows that the CSA is prepared to take enforcement action where organisations fail to comply with licensing requirements and regulatory directives.
For businesses looking to hire cybersecurity professionals or companies, checking whether the service provider has the appropriate CSA licence is becoming increasingly important.
CSA steps up cybersecurity regulation in Ghana
Ghana has been strengthening its cybersecurity regulatory environment as threats to businesses, government institutions and individuals continue to evolve.
The latest action against EY Ghana demonstrates that cybersecurity regulation is not limited to responding to cyberattacks.
It also involves ensuring that companies providing cybersecurity services meet the required professional and regulatory standards.
The CSA says it will continue monitoring compliance and taking action against entities that provide regulated cybersecurity services without the necessary licence, as well as organisations that engage unlicensed providers.
The Authority’s message is clear: cybersecurity licensing is a legal requirement, not simply an administrative formality.
Key facts at a glance
- Company: EY Ghana
- Regulator: Cyber Security Authority (CSA)
- Penalty: GH¢360,000
- Reason: Providing regulated cybersecurity services without the required licence
- Number of breaches: Three
- Penalty per breach: GH¢120,000
- Payment deadline: 14 calendar days
- Licence involved: Cybersecurity Service Provider (CSP) licence
- Law: Cybersecurity Act, 2020 (Act 1038)
EY Ghana Cybersecurity Fine
The enforcement action is expected to draw further attention to cybersecurity compliance among companies operating in Ghana and reinforce the need for organisations to work with properly licensed cybersecurity service providers.

