23.3 C
Accra
Friday, August 14, 2026

ORC Fined GH¢240,000 by CSA Over Unlicensed Cybersecurity Service Provider

The Authority has also fined Purpleline Solutions Limited Company GH¢120,000 for providing cybersecurity services without a licence.

According to the CSA, it directed the ORC on June 15, 2026, to engage a Tier 1 licensed Cybersecurity Service Provider to improve the security and protection of its Critical Information Infrastructure.

The ORC was also asked to submit information about its cybersecurity service providers, the Terms of Reference for its proposed Security Operations Centre (SOC), and the relevant Public Procurement Authority approvals.

However, the CSA said the ORC went ahead to engage Purpleline Solutions Limited Company even though the company was not licensed to provide cybersecurity services.

The Authority said the ORC failed to comply with two separate directives, which amounted to a violation of Section 92 of the Cybersecurity Act, 2020 (Act 1038).

As a result, the ORC was fined 10,000 penalty units for each violation. The two fines amounted to GH¢240,000.

The CSA has also directed the ORC to comply with the outstanding directives within one month of receiving the sanction letter.

Meanwhile, Purpleline Solutions Limited Company was also sanctioned for providing cybersecurity services without the required licence.

The CSA said Purpleline applied for a cybersecurity service provider licence on July 15, 2026, after the Authority had already determined that the company had been engaged by the ORC to provide cybersecurity services.

The Authority explained that applying for a licence does not mean that a company has been licensed or allowed to provide regulated cybersecurity services.

Purpleline Solutions Limited Company was therefore fined 10,000 penalty units, equivalent to GH¢120,000, for operating without the required licence.

The CSA has warned institutions and cybersecurity service providers to comply with the licensing requirements under the Cybersecurity Act.

It said public-sector organisations, CII institutions and other organisations covered by the law must check the licensing status and licence tier of cybersecurity service providers before awarding contracts or allowing them to begin work.

The Authority further warned organisations against engaging unlicensed providers and expecting them to obtain the required licence later.

The CSA said it will continue to monitor compliance and take action against institutions that engage unlicensed providers and companies that provide cybersecurity services without the required licence.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Stay Connected

0FansLike
0FollowersFollow
0SubscribersSubscribe
- Advertisement -spot_img

Latest Articles