Office of Registrar of Companies and Service Provider Fined GH¢360,000 Over Cybersecurity Breaches

    0
    19

    The Office of the Registrar of Companies (ORC) and cybersecurity service provider Purpleline Solutions Limited have been fined a combined GH¢360,000 by Ghana’s Cyber Security Authority (CSA) for breaching cybersecurity requirements, after the ORC engaged a service provider that was not licensed to provide regulated cybersecurity services. The sanctions, announced on August 12, 2026, follow the CSA’s determination that the ORC failed to comply with two separate directives issued to strengthen the security of its critical information infrastructure.

    The ORC, which is classified as a Critical Information Infrastructure (CII) institution, has been fined GH¢240,000, while Purpleline Solutions Limited has been fined GH¢120,000 for providing cybersecurity services without the required licence from the CSA.

    cybersecurity

    The sanctions have brought renewed attention to the importance of cybersecurity compliance among public institutions and private companies providing regulated digital security services.

    ORC fined GH¢240,000

    According to the CSA, the ORC was directed on June 15, 2026, to engage a Tier 1 licensed Cybersecurity Service Provider (CSP) to strengthen the security and resilience of its critical information infrastructure.

    cybersecurity

    The directive formed part of measures intended to ensure that institutions whose systems are considered critical to national operations have adequate cybersecurity protection and are supported by properly licensed professionals.

    In addition to engaging an appropriately licensed service provider, the ORC was required to provide the CSA with details of its cybersecurity service providers, the terms of reference for its proposed Security Operations Centre (SOC) and relevant approvals from the Public Procurement Authority (PPA).

    However, the CSA said the ORC proceeded to engage Purpleline Solutions Limited despite the directive to use a Tier 1 licensed provider.

    The Authority said Purpleline was not licensed to provide cybersecurity services at the time it was engaged by the ORC. The decision by the ORC therefore amounted to non-compliance with the CSA’s directives and constituted a breach of Section 92 of the Cybersecurity Act, 2020 (Act 1038).

    The CSA determined that the ORC had failed to comply with two separate directives. Under Section 92(2) of Act 1038, the Authority imposed 10,000 penalty units for each instance of non-compliance, bringing the total penalty against the ORC to GH¢240,000.

    The Authority has also directed the ORC to comply with the outstanding directives within one month of receiving the sanction letter.

    Purpleline Solutions fined GH¢120,000

    cybersecurity

    Purpleline Solutions Limited was separately sanctioned for providing cybersecurity services without the licence required by law.

    The CSA said the company had applied for a cybersecurity service provider licence on July 15, 2026, but the application was made after the company had already been engaged by the ORC.

    The Authority stressed that merely applying for a licence does not amount to being licensed and does not authorise a company to provide regulated cybersecurity services.

    Consequently, Purpleline Solutions was fined 10,000 penalty units, equivalent to GH¢120,000, for operating without the requisite licence.

    The case highlights the legal distinction between submitting an application for a licence and actually obtaining regulatory approval. Businesses operating in regulated cybersecurity fields are required to secure the appropriate licence before providing services, rather than beginning operations and subsequently attempting to regularise their status.

    The Cyber Security Authority has used the sanctions to issue a broader warning to public institutions, businesses and cybersecurity service providers.

    The Authority said institutions must not engage cybersecurity service providers that have not obtained the appropriate licence, while companies must not provide regulated cybersecurity services unless they have first secured the required authorisation.

    The CSA also cautioned organisations against engaging a service provider first and expecting the company to obtain its licence afterwards.

    cybersecurity
    cybersecurity

    According to the Authority, such an approach does not satisfy Ghana’s cybersecurity requirements because an application for a licence does not confer permission to operate.

    The CSA said the enforcement action demonstrates that cybersecurity licensing requirements are mandatory and will be enforced where institutions and service providers fail to comply.

    The sanctions come at a time when Ghana is strengthening measures to protect critical digital systems from cyber threats.

    Institutions designated as Critical Information Infrastructure have a heightened responsibility because disruption, compromise or destruction of their systems could affect essential public services, economic activity or national interests.

    The ORC plays a central role in Ghana’s corporate regulatory system, maintaining information on registered businesses and providing services that support the country’s business environment. Ensuring that its digital systems are adequately protected is therefore important for the security and integrity of corporate information.

    The CSA’s action reinforces the principle that institutions responsible for critical systems must comply with cybersecurity directives and engage properly licensed professionals.

    For Purpleline Solutions, the sanction also demonstrates that cybersecurity companies cannot provide regulated services while their licence applications are still pending.

    cybersecurity

    The ORC has been given one month from the date it receives the CSA’s sanction letter to comply with the outstanding directives.

    The government cybersecurity regulator’s enforcement action therefore extends beyond the financial penalties. The ORC is expected to address the specific compliance gaps identified by the CSA, including requirements relating to its cybersecurity service provider, proposed Security Operations Centre and procurement documentation.

    The combined GH¢360,000 sanction serves as a warning to institutions and cybersecurity firms that Ghana’s cybersecurity licensing and compliance framework carries financial and regulatory consequences for non-compliance.

    The CSA has maintained that the engagement and provision of cybersecurity services without the appropriate licence will not be tolerated, signalling a tougher enforcement approach as Ghana seeks to strengthen the protection of critical information infrastructure and digital services nationwide.

    Author