EY Ghana was fined GH¢360,000 (approximately US$32,300) by Ghana’s Cyber Security Authority for providing cybersecurity services without the required licence, before the regulator and the Big Four firm announced later the same day that their regulatory issues had been “satisfactorily resolved”.
The Cyber Security Authority (CSA) announced the administrative penalty on 18 August, saying Ernst & Young Ghana had continued to provide regulated cybersecurity services without a valid Cybersecurity Service Provider licence, including services to owners of Critical Information Infrastructure — systems considered essential to Ghana’s national security or economic and social well-being.
According to the regulator, it had written to EY Ghana on 20 March 2026, directing the firm to submit an application for a licence within 15 days. The CSA subsequently determined that EY had failed to comply with three separate regulatory directives.
The regulator imposed a penalty of 10,000 penalty units — equivalent to GH¢120,000 — for each of the three instances of non-compliance, bringing the total to GH¢360,000. EY Ghana was directed to pay within 14 calendar days, immediately cease providing regulated cybersecurity services without the required licence, confirm in writing that the affected services had stopped, and complete the licensing process.
Significantly, for the professional services firm, the CSA said the restriction extended to Governance, Risk and Compliance (GRC) services, rather than applying only to technical activities such as penetration testing. The CSA’s licensing framework expressly lists cybersecurity Governance, Risk and Compliance alongside vulnerability assessment and penetration testing, digital forensics, managed cybersecurity services and cybersecurity training.
Under section 49 of Ghana’s Cybersecurity Act 2020, a person may not provide a cybersecurity service without obtaining a licence from the CSA. The regulator began implementing its licensing regime for Cybersecurity Service Providers in 2023.
The CSA also stressed that simply applying for a licence did not authorise a provider to operate and said a company’s size, reputation, expertise or clientele did not exempt it from Ghana’s cybersecurity laws.
But the position changed rapidly.
In a joint statement issued later on 18 August, the CSA and EY Ghana said they had held constructive discussions on the licensing requirements, including licence fees and associated administrative requirements.
The parties said they had taken steps to clarify and address the matters and that, as a result, “regulatory issues between the CSA and EY Ghana have been satisfactorily resolved.” Contemporary reporting said the joint statement came only hours after the enforcement action had become public.
The statement did not explain what happened to the GH¢360,000 penalty. It did not say whether the fine had been paid, withdrawn, reduced or otherwise dealt with, nor did it specify whether EY Ghana had by then obtained a Cybersecurity Service Provider licence. It also did not expressly retract the CSA’s earlier findings about unlicensed services and non-compliance with its directives.
The Ghana licensing action is separate from the cybersecurity incidents that have recently brought scrutiny to EY’s own handling of sensitive information.
In July, EY US disclosed that an unauthorised party had accessed a third-party IT service-management platform used by its technology personnel to support teams performing tax-related work. Documents downloaded during the intrusion contained client tax, personal and financial information. The incident has since resulted in a proposed US class action, while the ShinyHunters cyber-extortion group has claimed responsibility for the breach. EY has not publicly confirmed ShinyHunters’ attribution or the group’s wider claims concerning access to additional EY systems.
Those incidents are unrelated to the Ghana licensing action. But together they illustrate how cybersecurity is becoming an increasingly significant issue for the Big Four from two directions: as an operational risk to firms entrusted with large volumes of sensitive client information, and as a growing professional-services business that can itself be subject to specialist regulation and licensing requirements.
Want to stay up to date on all things Big Four around the world?
Check out the News section and subscribe to Big4News for weekly deep dives and briefings.



