
Ghana's Cyber Security Authority (CSA) has imposed significant financial penalties totaling GH¢360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited for violating national cybersecurity regulations. The sanctions follow a determination that the ORC engaged an unlicensed provider to manage critical components of its digital infrastructure, a move that directly contravenes the Cybersecurity Act, 2020. This enforcement action underscores the CSA’s commitment to securing Ghana’s digital landscape and ensuring that all institutions, especially those managing sensitive data, adhere to strict licensing protocols.
The Office of the Registrar of Companies was specifically fined GH¢240,000 for its failure to comply with multiple directives from the CSA. According to the regulator, the ORC had been instructed to engage only Tier 1 licensed Cybersecurity Service Providers (CSPs) to enhance and secure its Critical Information Infrastructure (CII). Despite these clear mandates, the ORC proceeded to contract Purpleline Solutions Limited, disregarding at least two separate directives to vet the licensing status of their chosen partner. The CSA noted that the ORC’s non-compliance posed a potential risk to the integrity of company registration data and national digital security.
Purpleline Solutions Limited was concurrently fined GH¢120,000 for operating as a cybersecurity service provider without the requisite legal authorization. The CSA revealed that the company provided professional services to a state-related entity before securing the necessary license, only submitting an application for licensure after it had already been engaged by the ORC. This attempt at post-engagement compliance was deemed insufficient to waive the penalties for the initial period of unlicensed operation. The regulator emphasized that cybersecurity service provision is a strictly regulated activity that requires prior verification to ensure practitioners meet the technical and ethical standards necessary to protect the public.
In a statement regarding the sanctions, the CSA warned all public and private institutions against the engagement of unlicensed cybersecurity providers. The Authority reiterated that organizations have a legal obligation to verify the credentials of their service providers through the CSA’s official registry to ensure they are working with accredited professionals. As Ghana continues to expand its digital economy, the CSA maintains that rigorous enforcement of the Cybersecurity Act is essential for building public trust and mitigating the growing threat of cyber-attacks on national infrastructure.
This story touches markets covered on Anansi Intelligence ↗.
Continue exploring similar stories