No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Cybersecurity

Cybersecurity Threats Increase Civil and Criminal Liability for Government Contractors

Executives and board members should heed warnings of cases involving Uber, Verizon

by Jennie VonCannon and Isabella Ordorica
October 9, 2023
in Cybersecurity
glitchy image of data center

The risks faced by companies in light of new federal cybersecurity regulations are particularly acute for government contractors, who must also be aware of False Claims Act risks. Jennie VonCannon and Isabella Ordorica of Crowell & Moring break down the nuances for this subset of professionals.

The U.S. government is increasingly scrutinizing corporate cybersecurity programs, and companies face new risks of civil and criminal liability related to data breaches. These risks are particularly acute for government contractors, who face compounded exposure from the False Claims Act (FCA), 31 U.S.C. § 3729. 

And the specter of criminal liability looms large since the 2022 conviction of Uber’s chief security officer for actions related to his response to data breaches. All companies — especially government contractors — should consider mitigating risk by auditing their cybersecurity protocols and updating their incident response plans.

The False Claims Act

In October 2021, the DOJ announced the launch of its civil cyber-fraud initiative to combat cyber threats by leveraging civil FCA to prosecute government contractors who knowingly: (1) provide deficient cybersecurity products or services; (2) misrepresent their cybersecurity practices or protocols; or (3) violate obligations to monitor and report cybersecurity incidents and breaches.

The Defense Federal Acquisition Regulation Supplement (DFARS) is a set of cybersecurity regulations that defense contractors and their suppliers must follow in order to be awarded new contracts from the DoD, any number of which could serve as the potential basis for a potential FCA enforcement action. These include, among many others, FAR 52.204-21, requiring protection of federal contract information residing on contractor information systems and timely identification of flaws; and DFARS 252.204.7012, requiring safeguard of covered defense information and imposing a 72-hour incident reporting period.

An FCA whistleblower — typically a former employee — would likely allege that a contractor’s cybersecurity protocols or response are out of FAR/DFAR compliance. A whistleblower can show that the company (or an individual) acted knowingly by: (1) having actual knowledge of the information; (2) acting in deliberate ignorance of the truth or falsity of the information; or (3) acting with reckless disregard of the truth of the claim.

The FCA does not require specific intent to defraud, but it does require some intent or knowledge of wrongdoing (scienter). Courts have generally held that statements made with reckless disregard, no objectively reasonable interpretation or authoritative guidance (Proctor v. Safeway Inc.) or no facts to infer good faith, (McGrath v. Microsemi Corp.), support such a finding. On June 1, the U.S. Supreme Court clarified in Schutte v. Supervalu that scienter in FCA cases turns on the defendant’s knowledge and subjective beliefs at the time the claim was made. Within the Supreme Court’s framework, the scienter standard is generally industry-specific.

The default measure of damages under the FCA is the benefit the government received under the contract less the amount paid. In addition to monetary damages, (Feldman v. van Gorp), a company may be liable for treble or multiplied damages to compensate the government for the costs, delays and inconveniences caused by the fraudulent claims, calculated before deduction fixes entitled to the defrauder, (U.S. v. Bornstein); thousands of dollars in penalties per claim, adjusted for inflation; and attorneys’ fees. An individual or company found liable under the FCA may also face suspension and debarment, preventing the organization or individual from entering into contracts with the government for a time.

In September 2023, the DOJ announced that Verizon Business Network Services agreed to pay over $4 million to settle FCA allegations regarding Verizon’s failure to satisfy certain cybersecurity controls in connection with an information technology service provided to federal agencies. Of note is Verizon’s proactive approach to the case — including conducting an independent investigation and compliance review and self-reporting — which earned Verizon cooperation credit with the DOJ, resulting in a reduction in the settlement amount.

emblem on sec building
Cybersecurity

Deloitte Survey: 26% of Orgs Have Yet to Begin Preparing for SEC Cybersecurity Rules

by Staff and Wire Reports
October 3, 2023

Nearly 2 in 3 execs say companies will beef up programs to comply with regulations

Read moreDetails

The SEC cybersecurity rule

While the SEC cybersecurity rule applies only to publicly traded companies, private companies would benefit from heeding the new standard of reasonableness that will likely be relied upon by the plaintiffs’ bar and regulators alike. 

Government contractors assessing their risk profiles should note that, among other things, the SEC cybersecurity rule now requires disclosure of any cybersecurity incident determined to be material and describe material aspects of the reported incident within four business days of that determination. This determination must be made “without unreasonable delay” and be “consistent with the standard set out in the cases addressing materiality in the securities laws”; i.e., “there is a substantial likelihood that a reasonable shareholder would consider [the information] important in making an investment decision, or if it would have ‘significantly altered the ‘total mix’ of information made available.” 

Public companies must also now describe annually to their shareholders their boards’ oversight of risks arising from cybersecurity threats, as well as management’s cybersecurity expertise and role in assessing and managing such material risks. 

Criminal liability

The 2022 criminal conviction of Uber’s former CSO by a federal jury in San Francisco for obstruction of justice and failure to report knowledge of the commission of a felony for his “attempted cover-up of a 2016 hack of Uber” has further raised the stakes. Although no similar criminal prosecution related to the handling of a cybersecurity incident has occurred since then, corporate executives are acutely aware that criminal prosecution is another dimension of liability they must weigh among the other risks inherent to cybersecurity incidents.

Conclusion

Given the U.S. government’s increasingly complex and broad enforcement regime and increased risk of civil and criminal liability to businesses and their leadership, companies need to keep in mind their broad obligations to be transparent to myriad constituencies — including customers, investors and law enforcement and regulators. For government contractors, such obligations are heightened given the possibility of FCA liability. 
Critical to safeguarding against FCA liability is implementing a robust cybersecurity compliance program, regular training and risk assessments.

Warrington Parker and Laura Schwartz contributed to this report.

Tags: DOJFalse Claims Act (FCA)SEC
Previous Post

Advent of New State Data Privacy Laws Is the Perfect Time to Revisit Your Contracts

Next Post

Seeing Green: Balancing Safety & Compliance as Support Grows for Legal Marijuana

Jennie VonCannon and Isabella Ordorica

Jennie VonCannon and Isabella Ordorica

Jennie Wang VonCannon is a partner in the Los Angeles office of Crowell. She is trial lawyer and adviser with a proven track record of success in both the courtroom and the boardroom, with extensive experience and deep understanding of corporate defense in both criminal and civil contexts, cybersecurity and intellectual property matters. She served for over 11 years as a federal prosecutor, culminating in her selection to serve with distinction as the deputy chief of the cyber and IP crimes section of the National Security Division of the U.S. Attorney’s Office for the Central District of California.
Isabella Ordorica is an associate in the Orange County, Calif., office of Crowell. Her practice focuses on complex antitrust litigation, including class actions and on white-collar and investigation matters. Isabella’s antitrust practice includes representing companies that are plaintiffs in complex pharmaceutical price-fixing litigation. She also provides counsel on class-action litigation involving healthcare companies. In her white-collar practice, Isabella advises clients on a range of issues, including government investigations, such as those that go before the SEC.

Related Posts

doj sign and sculpture

DOJ’s New CEP Proposes Guaranteed Declination for Some Self-Reporters

by Jennifer L. Gaskin
May 13, 2025

The Trump Administration continues reshaping its approach to corporate crime, with the DOJ issuing major revisions of its corporate enforcement...

sec building sign

What to Expect From Atkins-Led SEC

by Jaclyn Jaeger
May 6, 2025

Former Bush-era commissioner returns with mission to streamline regulations and enhance capital markets

doj building sign with flags

‘Reasonable Steps’: What the DOJ Expects From Your Bulk Data Transfer Compliance Program

by Alexandra P. Moylan, Alisa L. Chestler and Michael J. Halaiko
May 5, 2025

Sample provisions offer blueprint for compliant data brokerage with foreign entities

data security program concept cameras

Your Sensitive Data Is Now a National Security Matter: The DOJ’s New Data Security Program

by Randall Cook, Vince Mekles and Rachel Woloszynski
April 29, 2025

90-day implementation window closing on regulations affecting companies with genomic, biometric, health and other personal information

Next Post
sign in front of weed dispensary

Seeing Green: Balancing Safety & Compliance as Support Grows for Legal Marijuana

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights