…State institution hired unlicensed firm despite clear directive
…CSA slams GH¢360,000 in fines for flagrant licence violations
TNR Files
The Cyber Security Authority (CSA) has dropped a bombshell on the Office of the Registrar of Companies (ORC) and its technology partner, Purpleline Solutions Limited, slapping both with hefty fines for what it calls “blatant and reckless” breaches of Ghana’s cybersecurity laws.
In a stinging statement issued Wednesday, August 12, 2026, the CSA revealed that the ORC a key state institution entrusted with corporate records had deliberately ignored a formal directive to engage only licensed Tier 1 cybersecurity providers. Instead, the Registrar went ahead and hired Purpleline, a company that had no licence whatsoever to offer regulated security services.
The price of that defiance: GH¢240,000 for the ORC (10,000 penalty units for each of two separate non-compliances), and GH¢120,000 for Purpleline a combined GH¢360,000 penalty that sends an unmistakable message to all public bodies.
What the CSA discovered. According to the Authority, the ORC had been directed on June 15, 2026, to engage only Tier 1 licensed providers and to submit full documentation, including the Terms of Reference for its proposed Security Operations Centre (SOC) and Public Procurement Authority approvals. The ORC never complied. Instead, it quietly brought Purpleline on board a company that, at that point, had no authorisation from the CSA.
But the plot thickens. The CSA notes that Purpleline applied for a licence on July 15, 2026 a full month after the ORC had already engaged it. The regulator was quick to shut down any suggestion that a pending application equals a green light. “Applying for a licence does not amount to being licensed,” the CSA stressed, adding that no company may commence regulated cybersecurity operations without prior authorisation.
A dangerous precedent. The Authority’s warning is stark: do not hire first and regularise later. It is a practice the CSA calls “unacceptable” and “a direct invitation to systemic vulnerability.” For a state institution like the ORC designated as Critical Information Infrastructure (CII) the failure to secure properly vetted, licensed partners is not merely an administrative lapse; it is a national security risk.
The deeper concern. This is not the first time the CSA has had to flex its enforcement muscles. But the targeting of a high-profile public office, coupled with a private firm caught operating in the grey zone, raises troubling questions about how many other state agencies are cutting corners. The CSA has vowed to “continue monitoring and take enforcement action” against any institution or company that flouts the Cybersecurity Act, 2020 (Act 1038).
For now, the ORC has one month to comply with all outstanding directives – or face further sanctions. Purpleline, meanwhile, must either secure its licence or cease operations entirely.
The bottom line: A state body entrusted with the nation’s corporate data chose expediency over legality. A private firm chose to operate without a licence. The CSA has drawn a line in the sand. But the real test will be whether other CII institutions and their directors take heed before the next scandal erupts.
