The Ghana Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited have been jointly fined GH¢240,000 for serious breaches of Ghana’s cybersecurity requirements, stemming from reported vulnerabilities within the country’s critical information infrastructure.
The Cyber Security Authority (CSA) initiated sanctions against both organizations, citing a failure to adhere to cybersecurity regulations and a violation of the Cybersecurity Act, 2020 (Act 1038).
The ORC, designated a critical information infrastructure institution, was instructed to only engage licensed cybersecurity service providers (CSPs), a directive disregarded by the CSA, which subsequently sanctioned Purpleline Solutions Limited, a provider not authorized by the ORC. This breach constitutes a direct violation of Section 92 of the Cybersecurity Act, 2020.
The CSA issued a penalty of 10,000 penalty units per instance of non-compliance, totaling GH₵ 240,000.00, and demanded the immediate resumption of the required cybersecurity service provider details, including TORs for SOC operations and PPA approvals.
Furthermore, the CSA directed the ORC to conduct a thorough investigation and comply with the outstanding directives within one month of receiving the sanction letter. The authority determined that the ORC failed to comply with two separate directives issued by the CSA, resulting in this substantial financial penalty.
In response, Purpleline Solutions Limited was slapped with a fine of 10,000 penalty units, equivalent to GH₵ 120,000.00, for providing cybersecurity services without the necessary license. This fine follows a previous investigation into Purpleline’s application for a cybersecurity service provider license, which the authority determined to have occurred after it had already been engaged by the ORC.
The CSA emphasized that cybersecurity licensing is a legal requirement, not an administrative one, and that entities must obtain the requisite license before commencing regulated cybersecurity services. They cautioned against engaging unlicensed providers and stressed the importance of verifying licensing status and appropriate license tiers.
The Authority further stated that it would continue monitoring compliance and taking enforcement action against institutions that engage unlicensed providers and those providing cybersecurity services without the requisite license.
This incident underscores the critical importance of robust cybersecurity practices and the potential consequences of non-compliance with cybersecurity regulations within Ghana. The CSA’s directive to ensure the full compliance of the entities is a direct response to the risk to Ghana’s critical systems and sensitive information.
Watch Related Video
Source: Graphic Online




















