Government contractors have paid more than $81 million in settlements since the Department of Justice’s Civil Cyber-Fraud Enforcement program launched in 2021 — and the number is only going to go up. Companies that work with the U.S. Government will want to take another look at their cybersecurity systems (and those of any subcontractors they employ), especially with the Trump administration announcing its continued focus on cybersecurity enforcement in 2026.
The tremendous success of the Civil Cyber-Fraud Enforcement program is stamped across its 16 existing settlements — all brought under the False Claims Act (“FCA”). Government contractors are likely familiar with FCA investigations rooting out fraud, but the highly publicized cybersecurity attack on SolarWinds in 2020 prompted higher scrutiny on whether contractors are potentially compromising Government networks. The DOJ is paying particular attention to whether a contractor:
- Has provided a deficient cybersecurity product or service,
- Has misrepresented its cybersecurity practices or protocols, or
- Is violating its obligations to monitor and report cybersecurity incidents.
FCA investigations into cybersecurity fraud impact any industry with Government contracts, including defense contractors, broadband providers, and healthcare companies charged with safeguarding protected health information (“PHI”). In today’s age, most critical functions happen in the virtual world, making protection of those processes and data increasingly critical. The DOJ is specifically targeting cases where a company demonstrated a reckless disregard for federal cyber rules and regulations.
The cases that have emerged so far show a pattern of companies falling for the same system or procedural vulnerabilities over and over, including failures to:
- Implement proper cybersecurity controls,
- Restrict access to sensitive databases,
- Promptly report security incidents,
- Install or run anti-virus tools while performing sensitive research,
- Sufficiently secure medical devices, or
- Check the qualifications of cyber workers performing on Government contracts.
Under the FCA, the Government does not need to prove intent to commit fraud — only that an entity acted with a reckless disregard of the applicable regulations. Ignorance is not an acceptable excuse here. The Government is paying its contractors to provide services or products that follow certain regulations. Taking money from the Government while not providing the service or product as requested is fraudulent, intentional, or otherwise.
It is incumbent upon any government contractor to be aware of and to understand any rules dictating how they should perform their work under the contract, no matter how complicated they may be.
Corporations required to sign certifications of compliance with Cybersecurity Maturing Model Certification (“CMMC”) standards, for example, need to understand what those standards call for. What are companies obliged to do under those rules, and is their company capable of meeting those expectations? The same is true for any other federal regulations incorporated into a contract.
For some courts, a failure to understand and follow the regulations constitutes gross negligence on the part of the company. All you need to do is look at the DOJ’s successful settlements to realize that the Government will capitalize on that notion. And if your company signs a certification that misrepresents your compliance? That is intentional fraud, not a mistake.
It’s important to also ensure that any subcontractors are following the regulations. Perhaps you’re confident in your company’s cybersecurity practices. But how confident are you that all of the subcontractors you work with apply the same high standards? One of your subcontractors may be failing to meet the standards agreed to in the contract, which may result in a false claim submitted to the Government. It may not have been your company’s direct actions, but as the prime contractor, you can still be held liable for a subcontractor’s potential fraud.
Keep in mind that cyberfraud can go beyond civil liability. A civil settlement with the DOJ does not release a party from administrative or criminal liability, and the Government has been pursuing cybersecurity regulation violations criminally as well. The criminal cases have resulted in suspension and debarment for involved individuals as well as their companies (see FAR 9.400, et seq). The Federal Acquisition Regulations (“FAR”) outline seventeen factors that are considered before debarment, however, including voluntary disclosure, cooperation, and resolution with the DOJ or affiliated agency (see FAR 9.406-1).
Self-disclosure with the assistance of legal counsel is the best policy if a corporation believes it has run afoul of cybersecurity rules. The DOJ Justice Manual, Section 4-4.000 (specifically Section 4.112) shows that the Government will take into account a corporation’s self-disclosure, cooperation, and remediation when considering an FCA settlement. These actions can save a company significantly with the possibility of reduced civil penalties or the Government declining to pursue the case further.
The DOJ’s recently announced corporate enforcement policy (“CEP”) created some uniformity in how the DOJ handles cooperation in both civil and criminal matters. Companies under investigation for criminal matters are now similarly incentivized to cooperate, self-disclose, and remediate any issues if they want benefits, such as potential penalties being reduced by 50-75%.
However, companies should still operate with caution prior to self-disclosure and take actions such as conducting a rigorous internal investigation to determine the full scope of exposure, preserving privilege for investigations, and strategizing to navigate its disclosure requirements. Corporations should also seek counsel to assist in managing whistleblower actions and Government investigations.
This alert is part three of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the previous alert in the series here.
Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.