This is closer to what predictable enforcement should look like. The cybersecurity requirements were written into the contract before liability attached, and the consequence is a civil corporate settlement — not a prosecutor building a case against an individual security executive after the fact, as in the Sullivan and Brown prosecutions. Contractors could know the rules in advance; Honeywell allegedly didn't meet them and is paying $2,042,518 for it. The advice doesn't split by size: the False Claims Act doesn't scale down for headcount, and defense subcontractors of every size sign the same attestations. If you certify cybersecurity compliance to win a federal contract, treat that certification like a financial statement — someone can, and increasingly will, hold you to it.
Sources (2)
- doj_press · doj_press
- databreaches · databreaches