CSA fines EY Ghana for unlicensed cybersecurity
Analysis based on 10 articles · First reported Aug 18, 2026 · Last updated Aug 18, 2026
On August 18, 2026, Ghana's International — Cyber Security Authority (CSA) imposed an administrative penalty of GH¢360,000 on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence. The CSA had directed EY Ghana in a letter dated March 20, 2026, to apply for a CSP licence within 15 days, but the company failed to comply with three separate regulatory directives. The penalty, calculated at 10,000 penalty units (GH¢120,000) per instance, was imposed under Sections 49(2), 92(2) and 93 of the Cybersecurity Act, 2020 (Act 1038). The CSA also issued an immediate cease-and-desist order, requiring EY Ghana to stop providing all regulated cybersecurity services, including Governance, Risk and Compliance (GRC) services, until it obtains the requisite licence. EY Ghana must pay the penalty within 14 days and provide written confirmation that the affected services have ceased. The CSA warned that the size, reputation, or clientele of a service provider does not exempt it from Ghana's cybersecurity laws, and it will continue to monitor compliance and take enforcement action against unlicensed providers.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard