All insights

5 August 2026

Ghana's New Cyber Directive: A BFSI Compliance Guide

Ghana's new cybersecurity directive for banks and financial institutions brings mandatory incident reporting, resilience testing, and stricter third-party risk rules. Here's what CISOs need to know and how to align.

BOG Cybersecurity Directive -Axpert Cyber

Ghana's new cybersecurity directive for banks and financial institutions is a wake-up call. It moves beyond checkbox compliance to demand real, testable resilience. For CISOs in the region, it's a blueprint for what's coming elsewhere.

The directive, issued by the Bank of Ghana, applies to all banks, specialized deposit-taking institutions, and financial holding companies. It sets mandatory requirements for incident reporting, resilience testing, and third-party risk management. Non-compliance isn't just a regulatory issue—it's a license risk.

Key Clauses That Matter

Incident reporting is now non-negotiable. Institutions must report significant cyber incidents to the Bank of Ghana within 24 hours of detection, with a full report within 72 hours. This aligns with global norms but forces local banks to tighten their detection and escalation playbooks.

Resilience testing is another pillar. The directive mandates annual penetration testing and regular vulnerability assessments. It also requires business continuity and disaster recovery plans to be tested at least annually. This isn't just about ticking a box—it's about proving you can survive a real attack.

Third-party risk is a major focus. Banks must conduct due diligence on all vendors, especially cloud providers and fintech partners. They need to map data flows, assess security controls, and ensure contracts include audit rights. The directive effectively makes the bank accountable for its vendors' failures.

Mapping Your Compliance Program

The directive's clauses map neatly to a structured GRC program. Start with a gap assessment against the directive's requirements. This isn't a one-time exercise—it's a continuous cycle of assess, remediate, and validate.

For incident reporting, you need a clear internal escalation path. Define what constitutes a 'significant incident' and rehearse the reporting process. Your 24-hour clock starts when you detect it, not when you confirm it. That means investing in detection and response capabilities.

For resilience testing, schedule annual penetration tests and quarterly vulnerability scans. Use the results to drive remediation, not just to file reports. And when it comes to third parties, build a vendor risk management framework that includes security questionnaires, on-site assessments, and regular reviews.

What We Recommend

  • Run a gap assessment against the directive's requirements. Prioritize findings based on risk and regulatory impact.
  • Review your incident response plan. Ensure you can detect, report, and escalate within the 24-hour window. Test it with a tabletop exercise.
  • Map your third-party ecosystem. Identify critical vendors and start due diligence now. Don't wait for an audit to find gaps.

Ghana's directive is a signal for the region. If you're not already building this level of resilience, the clock is ticking. Axpert Cyber helps financial institutions across the GCC and MENA align with such regulatory demands—let's talk.

Share this insight

Next step

Need help applying this to your environment?

Our team helps organisations operationalise frameworks like ISO 27001, PCI DSS, NESA, SAMA CSF, and PDPL. Tell us what you are trying to achieve.