Audio By Carbonatix
The Office of the Registrar of Companies (ORC) has challenged a cybersecurity sanction imposed by the Cyber Security Authority (CSA), arguing that the penalty was premature and procedurally unfair.
The ORC says the sanction relates to its procurement of a Network Operations Centre (NOC) and Security Operations Centre (SOC), a process it insists was substantially completed before the CSA directed Critical Information Infrastructure (CII) institutions to engage Tier One licensed cybersecurity service providers.
The dispute follows a CSA statement announcing sanctions against the ORC and Purpleline Solutions Limited for alleged cybersecurity non-compliance.
The ORC has rejected what it says is the impression created by some reports that it deliberately engaged an unlicensed cybersecurity provider.
According to the ORC, the Ministry of Finance issued a Commitment Authorisation for the NOC/SOC project on November 28, 2025.
The Office subsequently advertised the procurement in the Daily Graphic and on the Public Procurement Authority's GHANEPS platform on December 4, 2025, with December 19 set as the deadline for bids.
Two companies submitted bids, after which an evaluation conducted on December 22 recommended Purpleline Solutions for the contract.
The procurement was subsequently reviewed by the Central Tender Review Committee of the Ministry of Finance, which approved it on December 31, 2025.
The ORC said the project was subsequently incorporated into its 2026 work plan, with the contract eventually awarded to Purpleline Solutions and executed on February 11, 2026.
The ORC's principal argument is that the procurement and contract were already in place before the CSA issued directives requiring CII institutions, including the ORC, to engage Tier One cybersecurity companies.
The Office says the relevant directives were issued on May 20 and June 15, 2026, several months after the procurement process had been completed and the contract awarded.
It therefore argues that it could not reasonably have been expected to comply during the procurement process with a requirement that had not yet been communicated.
The ORC further contends that applying the subsequent directive to an already-concluded procurement would amount to retrospective application of the requirement.
The Office is also challenging the timing of the CSA's enforcement action.
It says the Authority had given it 90 days to rectify identified cybersecurity deficiencies and that it had already begun implementing corrective measures.
According to the ORC, some of the identified issues had been resolved while work on others was ongoing.
The Office says it engaged the CSA and explained that the NOC/SOC procurement arrangements had been initiated and completed before the Tier One directives were issued.
It was therefore surprised when the CSA announced the sanction on August 12, 2026.
The ORC argues that the announcement came 57 days into the 90-day compliance period, leaving 33 days before the deadline expired.
It consequently contends that the sanction deprived it of the full opportunity to complete the corrective measures and submit a comprehensive response.
The ORC has also raised concerns about the manner in which the sanction was imposed and publicly announced.
It has cited Articles 23 and 296 of the 1992 Constitution, arguing that public administrative bodies are required to exercise their powers fairly, reasonably and without arbitrariness.
The Office says the public announcement of the penalty before the expiry of its compliance period has caused reputational damage and could potentially expose the institution to additional cybersecurity risks.
It further argues that the CSA's public statement did not sufficiently reflect what it considers important facts, including the timing of the procurement, the prior approval and award of the contract, and corrective measures already underway.
The petition is seeking administrative redress over what the ORC considers an unfair and premature enforcement action.
Among other requests, the Office is seeking the intervention of the Attorney-General's Office over the circumstances surrounding the sanction.
It is also calling on the CSA to issue a public clarification and apology over what it describes as the premature publication of the penalty.
The ORC, however, says its challenge should not be interpreted as a rejection of Ghana's cybersecurity requirements.
It maintains that it remains committed to complying with the country's cybersecurity laws and cooperating with the CSA to address legitimate cybersecurity concerns.
The dispute now centres on whether the CSA was entitled to sanction and publicly name the ORC before the expiration of the 90-day compliance period, particularly given the Office's claim that the procurement at the heart of the matter was initiated, evaluated and approved months before the Tier One requirement was communicated.
Latest Stories
-
Ghana hosts Kenya, Netherlands, South Africa for talks on turning climate plans into action
12 minutes -
‘Now it’s action, no talking’ – Rent Control cracks whip on hostel operators
15 minutes -
GACC, Save Our Environment Foundation train Tano South residents on corruption and accountability
17 minutes -
MOGMusic to headline Ransomed Ministries Ghana’s Total Worship 2026
21 minutes -
Multimedia Group pays courtesy call on Petrosol ahead of GSE listing
30 minutes -
Gov’t acknowledges unresolved grievances over mining damage, displacement
31 minutes -
Joy FM to host maiden Back-to-School PrayerFest ahead of new academic year
34 minutes -
Ghana must legislate minimum community development obligations for mining companies – Mireku Duker
44 minutes -
GoldBod costs could have been minimised with better planning – Prof. Bokpin
45 minutes -
GoldBod operations imposing losses on BoG balance sheet – Prof Bokpin
49 minutes -
Mining must improve lives in host communities, not just national figures – Presidency
57 minutes -
Nigeria influencer arrested after seizure of cocaine worth $28m destined for the UK
1 hour -
Gender Minister inspects nutrition training for School Feeding caterers in Northern Region
1 hour -
GoldBod to fund rehabilitation of six water treatment plants affected by mining
1 hour -
ORC challenges CSA cybersecurity sanction, says penalty was premature and procedurally unfair
1 hour