The Director-General of the Cyber Security Authority (CSA), Divine Selase Agbeti, has directed institutions to procure cybersecurity services only from service providers and professionals licensed or accredited by the Authority.
He said the directive was necessary to ensure that organisations engaging cybersecurity experts receive services from qualified and properly regulated professionals operating within Ghana’s cybersecurity regulatory framework.
Mr Agbeti made the remarks at the media launch of the 2026 National Cybersecurity Awareness Month, which will be observed from October 1 to 31 under the theme, “Securing Ghana’s Digital Finance Ecosystem: Building Trust Through Collaboration and Cyber Resilience.”
“Institutions must also know whom they are engaging,” he said, stressing the importance of verifying the regulatory status of cybersecurity service providers before engaging their services.
He warned organisations against relying on unverified individuals or companies for critical cybersecurity functions, particularly at a time when financial institutions and digital-commerce businesses are facing increasingly sophisticated cyber threats.
Under Ghana’s cybersecurity regulatory framework, the Cyber Security Authority is responsible for regulating cybersecurity activities in the country, including cybersecurity service providers, establishments and professionals.
The Authority has previously established licensing and accreditation requirements for cybersecurity industry players, covering areas including cybersecurity service provision and professional practice.
Mr Agbeti said the requirement formed part of efforts to strengthen Ghana’s cyber resilience and ensure that institutions entrusted with protecting sensitive systems and information engage competent and accountable professionals.
His warning is particularly significant for financial-sector and digital-commerce organisations, which increasingly depend on technology to provide services and process customer transactions.
He said organisations must strengthen their cybersecurity arrangements by improving identity and access management, enforcing multi-factor authentication, securing applications and APIs, and monitoring transactions and privileged activity in real time.
Institutions must also regularly assess vulnerabilities, conduct penetration testing, test their incident-response and business-continuity plans, protect customer data and assess cybersecurity risks associated with third-party and cloud-service providers, he added.
The CSA Director-General further urged organisations to train staff to identify phishing attempts and payment-diversion schemes, while ensuring that customers receive continuous cybersecurity education.
The call forms part of the Authority’s push to strengthen security across Ghana’s rapidly expanding digital finance ecosystem.
The CSA has also moved to enforce licensing and accreditation requirements more strictly. In January 2026, it announced that unlicensed cybersecurity service providers, establishments and professionals would face sanctions, including possible criminal prosecution and administrative penalties under the Cybersecurity Act, 2020 (Act 1038).
The Authority has urged organisations and individuals to verify the licensing or accreditation status of cybersecurity providers before engaging them, reinforcing the need for cybersecurity procurement to be treated as an important part of institutional risk management.
Mr Agbeti said the increasing sophistication of cyber threats makes it necessary for institutions to approach cybersecurity as a strategic responsibility rather than an expense to be considered only after an incident occurs.
The 2026 National Cybersecurity Awareness Month will seek to promote this approach as Ghana works to build greater trust, collaboration and resilience across its digital finance ecosystem.

