The Cyber Security Authority (CSA) and EY Ghana have successfully resolved regulatory issues concerning the licensing requirements for providing cybersecurity services. This resolution comes after constructive discussions between the two parties. It follows a fine of GH¢360,000 imposed by the CSA on EY Ghana for offering regulated cybersecurity services without a valid license.
In a joint statement issued on Tuesday, August 18, the CSA and EY Ghana announced that discussions were held to clarify and address concerns related to license fees and administrative requirements. “Subsequently, regulatory issues between the CSA and EY Ghana have been satisfactorily resolved,” the statement read.
The penalty stemmed from the CSA’s identification of EY Ghana’s failure to comply with repeated directives to regularise its operations under the Cybersecurity Act, 2020 (Act 1038). Despite being instructed to obtain the necessary license, EY Ghana continued to provide cybersecurity services, including those for owners of Critical Information Infrastructure (CII).
The CSA stated that in a letter dated March 20, 2026, it instructed EY Ghana to submit an application for a Cybersecurity Service Provider (CSP) license within 15 days. The Authority said the subsequent engagement between the two institutions had resulted in the clarification and resolution of the regulatory issues.
The CSA reiterated that its mandate was not only to enforce compliance but also to support organisations in understanding and meeting their regulatory obligations.
It said it remained committed to building a secure, resilient and trusted digital ecosystem through effective regulation, responsible industry participation and strong enforcement of Ghana’s cybersecurity laws.
The CSA and EY Ghana also expressed their commitment to supporting Ghana’s cybersecurity regulatory framework and welcomed the collaborative approach that led to the resolution of the matter.
Also read..
Source: Leticia Osei

