CSA EY Ghana Slapped With GH₵360,000 Fine
Regulator accuses EY of ignoring three separate directives to get licensed, orders immediate halt to all unauthorized services

Ghana’s Cyber Security Authority (CSA) has imposed a GH₵360,000 administrative penalty on Ernst & Young (EY) Ghana after finding that the professional services giant had been offering cyber security services, including work for operators of the country’s critical information infrastructure, without holding a valid Cyber security Service Provider licence. In a press release dated August 18, 2026, the Authority said EY Ghana pressed ahead with regulated cyber security work even after being repeatedly told to comply with the licensing regime set out under the Cyber security Act, 2020 (Act 1038).
According to the CSA, it first wrote to EY Ghana on March 20, 2026, giving the firm fifteen days to apply for a Cyber security Service Provider licence. The Authority said EY Ghana did not comply, and went on to disregard two further directives on the same matter, bringing the total number of breaches to three. The regulator said this pattern of non-compliance violated Sections 49 and 92 of Act 1038, provisions that bar the supply of regulated cyber security services without a licence and set out penalties for ignoring directives issued by the Authority. Citing Sections 49(2), 92(2) and 93 of the Act, the CSA fined EY Ghana 10,000 penalty units — equivalent to GH₵120,000 — for each of the three breaches, adding up to the GH₵360,000 total. The firm has fourteen calendar days from the date of the final enforcement directive to settle the penalty.
Beyond the fine, the CSA ordered EY Ghana to immediately stop providing any regulated cyber security services it is not licensed for, including governance, risk and compliance (GRC) work. The firm must also give the Authority written confirmation that it has ceased the affected services and complete the process of applying for a Cyber security Service Provider licence. The Authority stressed that submitting an application is not the same as being licensed, and that firms must have the licence in hand before offering regulated services.
The CSA also used the announcement to issue a broader caution to companies and professionals across the sector. It said compliance is especially important where services touch critical information infrastructure, given the stakes for national security, the economy and delivery of essential services. Neither the size, reputation nor client list of a service provider exempts it from the law, the Authority said, adding that every cyber security service provider operating in Ghana is bound by the same rules under Act 1038. The CSA said it would keep monitoring compliance and would act against both institutions that hire unlicensed providers and firms that offer services without the required licence. Possible sanctions, it noted, could extend to administrative penalties, court action and the public naming of unlicensed providers.
It further urged organizations, particularly those running critical information infrastructure, to procure cyber security services only from properly licensed providers, and invited firms with questions about licensing rules to reach out directly to the Authority. The action against EY Ghana follows a pattern of recent CSA enforcement, after the regulator fined a state agency and a separate service provider a combined GH₵360,000 earlier this month over similar licensing breaches — signalling a tightening crackdown on unlicensed cyber security practice across both public and private sectors.
By: Joyce Owusu



