--°C
News

Cybersecurity Licensing Dispute Between CSA and EY Ghana Resolved

The CSA and EY Ghana have resolved their cybersecurity licensing dispute following talks over licence fees and administrative requirements.

News Desk
|
Wednesday, 19 August 2026
Share:
Cybersecurity Licensing Dispute Between CSA and EY Ghana Resolved

The cybersecurity licensing dispute between the Cyber Security Authority and Ernst & Young Ghana has been resolved following discussions over licence fees and administrative requirements.

A joint statement issued on August 18, 2026, said both institutions had taken steps to clarify the issues surrounding the provision of regulated cybersecurity services in Ghana.

“Subsequently, regulatory issues between the CSA and EY Ghana have been satisfactorily resolved,” the statement said.

Both sides described the discussions as constructive and reaffirmed their support for Ghana’s cybersecurity regulatory framework. The short statement settled the immediate disagreement. It left some important questions unanswered.

Settlement terms remain private

Neither the CSA nor EY Ghana disclosed the financial terms, compliance measures or administrative adjustments that produced the settlement.

There was also no confirmation of whether EY Ghana paid, contested or secured a review of the GH¢360,000 administrative penalty earlier announced by the regulator.

The penalty followed three alleged instances of noncompliance, with the CSA imposing GH¢120,000 for each breach. The Authority had accused the firm of providing regulated cybersecurity services without a valid licence.

EY Ghana was reportedly directed in March to apply for a Cybersecurity Service Provider licence and halt affected services until it had secured the required authorisation.

The joint statement did not say whether the firm has now obtained a licence, completed its application or discontinued any part of its cybersecurity advisory work.

That silence matters. The resolution applies specifically to the issues between the two institutions and should not be read as a revision of the licensing framework for other service providers.

CSA promises support alongside enforcement

The regulator used the settlement to explain that its mandate extends beyond sanctions.

“The Cyber Security Authority reiterates that its objective is not only to enforce compliance but also to support organisations in understanding and meeting their regulatory obligations,” the joint statement said.

The CSA also renewed its commitment to building a secure, resilient and trusted digital ecosystem through effective regulation, responsible participation by industry and enforcement of Ghana’s cybersecurity laws.

The language suggests that dialogue, rather than prolonged litigation or further enforcement action, brought the parties to an agreement.

For regulated companies, however, the message is still firm. Cybersecurity licensing is becoming an operational requirement, particularly for firms handling sensitive systems or advising institutions responsible for critical information infrastructure.

Ghana’s expanding use of digital payments, cloud computing, financial technology and artificial intelligence has placed more responsibility on companies providing cyber risk and information security services.

Professional services firms now operate in a space where cybersecurity is both a commercial advisory service and a regulated activity. Licence classifications and administrative procedures can therefore affect how firms design, market and deliver services to clients.

Predictable regulation will be crucial. Companies need to know which services require licensing, what fees apply and how long approvals should take. The regulator, on the other hand, must be able to act when providers operate outside the law.

Wider industry takes notice

The settlement removes an immediate uncertainty surrounding EY Ghana’s cybersecurity operations, although the precise conditions remain undisclosed.

For other providers, it is a reminder that reputation, technical expertise or international standing does not remove the obligation to comply with Ghanaian law.

Clearer guidance could prevent similar disagreements, especially as more consulting, technology and financial firms enter areas now classified as regulated cybersecurity activity.

The dispute has ended quietly. The bigger challenge has not. Ghana must enforce credible cybersecurity standards without creating a licensing system so uncertain that compliance itself becomes difficult.

READ ALSO: Rethink the Social Licence to Operate: GoldBod CEO Challenges Mining Industry

Comments

0/2000

Loading comments...

More in News