The Cyber Security Authority (CSA) has levied a GH¢360,000 administrative penalty on Ernst & Young (EY) Ghana for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence – a significant blow to the company’s operations and raising serious questions about compliance within Ghana’s digital landscape. The CSA issued this directive following a letter from the Cybersecurity Act, 2020 (Act 1038), which mandated EY Ghana to apply for a CSP licence within 15 days. The CSA’s statement, dated August 18, 2026, detailed a series of violations stemming from EY Ghana’s continued provision of cybersecurity services, particularly to critical infrastructure owners, despite directives from the Authority to comply with licensing requirements. The CSA has outlined three separate infractions, each resulting in a substantial financial penalty of GH¢120,000, representing 10,000 penalty units – equivalent to GH¢120,000 in total.
Watch Related Video
Source: Adom Online























