The Cyber Security Authority (CSA) has sanctioned the Office of the Registrar of Companies (ORC) for failing to comply with directives requiring institutions designated as Critical Information Infrastructure (CII) to engage appropriately licensed cybersecurity service providers. The CSA has also fined Purpleline Solutions Limited Company for providing cybersecurity services without a licence from the Authority. The CSA said the sanction against the ORC followed its determination that the institution engaged Purpleline Solutions, despite being directed to use a Tier 1 licensed Cybersecurity Service Provider (CSP). According to the CSA, the ORC nevertheless proceeded to engage Purpleline Solutions, which was not licensed to provide cybersecurity services. The CSA also determined that Purpleline Solutions Limited provided cybersecurity services without the required licence.