Bank of Ghana Tightens Cybersecurity Rules Across Financial Sector

New Directive Targets System-Wide Digital Risk

The Bank of Ghana has introduced a revised Cyber and Information Security Directive (CISD), expanding its scope beyond banks to include fintechs, microfinance institutions, and other financial players.

Governor Dr. Johnson Pandit Asiama described the move as a shift toward protecting the entire digital financial ecosystem, warning that cyber threats now pose national security risks.

From IT Issue to Economic Security Priority

The updated directive replaces the 2018 framework and reflects a major policy shift:

  1. Cyber risks like ransomware and data breaches are now treated as systemic threats
  2. Focus moves from compliance to active cyber resilience
  3. Sector-wide coordination becomes mandatory

The initiative positions cybersecurity as central to financial stability in Ghana.

Key Reforms in the New Framework

The directive introduces stricter and more modern controls:

  1. AI governance rules for fraud detection and credit scoring
  2. Data sovereignty requirements, restricting sensitive data from being hosted outside Ghana
  3. Mandatory participation in the Financial Industry Command Security Operations Centre (FICSOC)
  4. Board-level accountability, requiring cybersecurity expertise in leadership

A proportional compliance model ensures rules scale with institutional size and risk.

Business Impact: Fintechs and Banks Face New Reality

For financial institutions, the directive means:

  1. Increased compliance costs and operational adjustments
  2. Tighter controls on cloud infrastructure and data management
  3. Greater collaboration across the financial ecosystem

However, it also:

  1. Strengthens consumer trust
  2. Reduces systemic vulnerabilities
  3. Supports long-term digital finance growth

Policy Backing and National Strategy

Chief of Staff Julius Debrah emphasized that innovation without protection creates risk, reinforcing the government’s stance that cybersecurity is integral to economic resilience.

The central bank is also exploring a shared funding model to sustain cybersecurity infrastructure like FICSOC.

Bottom Line

Ghana is raising the bar on financial cybersecurity. The new directive signals a clear message: As finance becomes digital, security becomes non-negotiable.

Read Previous

Damang Mine Handover on Track Ahead of April 2026 – Gold Fields

Read Next

African Entrepreneurship Academy Urges Entrepreneurs to Harness AI for Sales Growth

Leave a Reply

Your email address will not be published. Required fields are marked *