CSA fines ORC and Purpleline Solutions
Analysis based on 9 articles · First reported Aug 12, 2026 · Last updated Aug 12, 2026
The sanctions reinforce regulatory oversight in Ghana's cybersecurity sector, potentially increasing compliance costs for designated institutions and service providers. The fines are modest and unlikely to significantly affect the broader market, but they signal stricter enforcement of licensing requirements.
The International — Cyber Security Authority (CSA) of Ghana sanctioned the United Kingdom — Company register (ORC) and Purpleline Solutions Limited for breaches of the Cybersecurity Act, 2020 (Act 1038). The ORC, designated as a Critical Information Infrastructure (CII) institution, was directed on June 15, 2026, to engage only Tier 1 licensed Cybersecurity Service Providers (CSPs) and to provide details of its cybersecurity service providers, terms of reference for a proposed Security Operations Centre, and Public Procurement Authority approvals. Despite these directives, the ORC engaged Purpleline Solutions, which was not licensed by the CSA. The CSA fined the ORC GH¢240,000 (10,000 penalty units for each of two instances of non-compliance) and directed it to comply within one month. Purpleline Solutions was fined GH¢120,000 for providing cybersecurity services without a licence, having applied for a licence only on July 15, 2026, after it had already been engaged. The CSA emphasized that applying for a licence does not authorize operation and warned institutions and providers to verify licensing status before engaging or providing services.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard