Cyber Security Authority Fines ORC and Purpleline Solutions GH¢360,000

Cyber Security Authority

The Cyber Security Authority has imposed penalties totaling GH¢360,000 on the Office of the Registrar of Companies and Purpleline Solutions Limited for breaching Ghana’s cybersecurity regulations.

The enforcement action, announced in mid-August 2026, followed findings that the Office of the Registrar of Companies engaged an unlicensed company to provide regulated cybersecurity services despite receiving explicit compliance directives from the Authority.

The ORC, which has been designated a Critical Information Infrastructure institution because of the sensitive corporate and business information under its control, was fined GH¢240,000, equivalent to 10,000 penalty units, for two separate compliance failures.

On June 15, 2026, the CSA directed the ORC to engage only a Tier 1 licensed Cybersecurity Service Provider to manage its cybersecurity operations. The state institution, however, appointed Purpleline Solutions Limited, which had not been licensed by the Authority.

The ORC also failed to comply with another directive requiring it to disclose information about its selected service provider. It was expected to submit the Terms of Reference for its proposed Security Operations Centre and provide the relevant approvals from the Public Procurement Authority.

According to the CSA, the requested documents were necessary to determine whether the procurement and implementation of the cybersecurity services complied with the applicable legal and regulatory requirements.

Purpleline Solutions was separately fined GH¢120,000 for providing regulated cybersecurity services without obtaining the required authorization.

Although the company submitted an application for a Cybersecurity Service Provider license on July 15, 2026, investigations reportedly established that it had already been engaged by the ORC before applying.

The Authority stressed that submitting a license application does not grant a company permission to begin providing regulated cybersecurity services. A service provider must complete the licensing process and receive formal authorization before commencing operations.

The penalties were imposed in line with Section 92 of the Cybersecurity Act, 2020 (Act 1038), which regulates the licensing of cybersecurity service providers in Ghana.

The CSA described licensing as an essential safeguard for determining whether companies possess the necessary personnel, technical capacity, governance structures and operational standards to protect sensitive digital systems.

“Cybersecurity licensing is a legal requirement, not an administrative formality,” the Authority cautioned.

It warned that allowing unlicensed or unverified companies to manage critical national systems could expose public institutions to data breaches, service disruptions and other cyber threats.

The enforcement action sends a broader warning to public institutions designated as Critical Information Infrastructure owners, as well as private companies offering regulated cybersecurity services. Both clients and service providers are required to verify that all necessary licenses and approvals are in place before entering into contracts or beginning operations.

The Office of the Registrar of Companies has been given one month to correct the identified breaches and comply fully with the CSA’s outstanding directives.

The Authority indicated that it would continue monitoring the institution’s response and enforcing the Cybersecurity Act to protect Ghana’s critical digital infrastructure and sensitive public information.

Source: Omanghana


About us

Omanghana is an online news portal that provides readers around the world with a greater focus on Ghana and other parts of Africa. Established in 2009, Omanghana regularly publishes articles related to News, Sports, and Entertainment.


CONTACT US