Cyber Security Authority fines ORC and Purpleline GH¢360,000 over breaches

The ORC was fined GH¢240,000 for failing to comply with two directives requiring it to use a properly licensed cybersecurity service provider. Purpleline received a GH¢120,000 fine for providing cybersecurity services without a licence from the Authority.

Is allowance instantly strangers applauded

The Cyber Security Authority (CSA) has imposed fines totalling GH¢360,000 on the Office of the Registrar of Companies (ORC) and Purpleline Solutions Limited Company for breaches of Ghana’s cybersecurity licensing requirements.

The ORC was fined GH¢240,000 for failing to comply with two directives requiring it to use a properly licensed cybersecurity service provider. Purpleline received a GH¢120,000 fine for providing cybersecurity services without a licence from the Authority.

According to a statement issued by the CSA on August 12, the regulator directed the ORC on June 15, 2026, to engage a Tier 1 licensed Cybersecurity Service Provider to strengthen the security and resilience of its Critical Information Infrastructure.

The ORC was also asked to submit information about its cybersecurity service providers, the terms of reference for its proposed Security Operations Centre and the relevant approvals from the Public Procurement Authority.

However, the CSA said the ORC subsequently engaged Purpleline, which was not licensed to provide cybersecurity services.

The Authority found that the ORC had failed to comply with two separate directives, constituting a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038). It consequently imposed a fine of 10,000 penalty units for each breach, amounting to GH¢240,000.

The ORC has also been directed to comply with the outstanding requirements within one month of receiving the sanction letter.

In Purpleline’s case, the CSA said the company had already been engaged to provide cybersecurity services before applying for a service provider licence on July 15, 2026.

The regulator stressed that submitting a licence application did not authorise a company to begin providing regulated cybersecurity services. It therefore fined Purpleline 10,000 penalty units, equivalent to GH¢120,000.

The CSA warned public-sector organisations, institutions designated as Critical Information Infrastructure and other entities governed by the Cybersecurity Act to verify the licence status and authorised tier of service providers before awarding contracts or permitting work to begin.

It also cautioned service providers that they must obtain the appropriate licence before commencing operations, adding that organisations could not bypass the requirement by engaging an unlicensed provider and seeking to regularise its status later.

The Authority said it would continue monitoring compliance and taking enforcement action against both institutions that hire unlicensed providers and companies that offer cybersecurity services without regulatory approval.