{"id":242173,"date":"2025-05-14T21:59:00","date_gmt":"2025-05-14T21:59:00","guid":{"rendered":"https:\/\/peraltafinancing.com\/accounting\/the-high-stakes-of-cybersecurity-false-claims\/"},"modified":"2025-05-14T21:59:00","modified_gmt":"2025-05-14T21:59:00","slug":"the-high-stakes-of-cybersecurity-false-claims","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=242173","title":{"rendered":"The High Stakes of Cybersecurity False Claims"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<h2>The cost of cybersecurity noncompliance<\/h2>\n<p>As the Department of Defense (DoD) continues its focus on securing the defense industrial base, cybersecurity compliance has not only left contractors scrambling to get compliant before CMMC regulations are included in their contracts, but it also has them on edge because of the wave of recent multimillion dollar False Claims Act (FCA) settlements with the Department of Justice (DoJ). What many contractors don\u2019t realize is that whistleblowers can be financially rewarded for reporting cybersecurity noncompliance, turning missteps that are only internally known into personal paydays.<\/p>\n<h3>Recent Settlements: Warning Signs for the Industry<\/h3>\n<p>In the last six months, the DoJ has publicized several significant settlements it has reached with DoD contractors that violated cybersecurity regulations, to include:<\/p>\n<ul>\n<li><strong>Pennsylvania State University<\/strong>. In October 2024, the university agreed to pay $1.25 million to settle allegations that it failed to comply with cybersecurity requirements in 15 contracts or subcontracts involving the DoD or NASA. The case was initiated through a whistleblower.<\/li>\n<li><strong>Health Net Federal Services (HNFS)<\/strong>. In February 2025, the company agreed to pay $11.25 million to settle allegations that it falsely certified compliance with federal contractor cybersecurity requirements.<\/li>\n<li><strong>MORSE Corp<\/strong>. In March 2025, the company agreed to pay $4.6 million to settle allegations that it failed to comply with cybersecurity requirements in its contracts with the Departments of the Army and Air Force. The case was initiated through a whistleblower.<\/li>\n<li><strong>Raytheon Company, RTX Corporation, and Nightwing Group<\/strong>. In May 2025, the companies agreed to pay $8.3 million to settle allegations that Raytheon failed to comply with contractually mandated cybersecurity standards. The case was initiated through a whistleblower.<\/li>\n<\/ul>\n<h3>Why the Increase in False Claims Act Settlements Related to Cybersecurity<\/h3>\n<p>The False Claims Act holds individuals and companies liable for defrauding governmental programs. Since the Department of Justice launched its Civil Cyber-Fraud Initiative in 2021, the FCA has become a potent tool for pursuing contractors that:<\/p>\n<ul>\n<li>Misrepresent their cybersecurity posture;<\/li>\n<li>Falsely certify compliance with DFARS\/CMMC requirements; or<\/li>\n<li>Fail to report breaches and security control failures.<\/li>\n<\/ul>\n<h3>How DoJ Is Pursuing Cybersecurity FCA Cases<\/h3>\n<p>The DoJ\u2019s Civil Cyber-Fraud Initiative focuses on the intersection of cybersecurity compliance and procurement fraud. Enforcement is being driven by:<\/p>\n<ul>\n<li><strong>Whistleblower (Qui Tam) Lawsuits<\/strong>. As you can see from the above settlements, many cases begin with insiders \u2014 such as former CISOs or other IT management \u2014 who report misrepresentations via FCA whistleblower provisions. In addition to protecting themselves, whistleblowers can receive 15\u201330% of the recovered funds, which can make it attractive.<\/li>\n<li><strong>Increased Oversight of DFARS Compliance<\/strong>. The DoJ is now routinely investigating whether companies are complying with DFARS 252.204-7012 and the CMMC model \u2014 and whether any statements about compliance were false certifications. A company that has posted a perfect score in SPRS system for several years and then significantly revised its score could be a red flag that the DoJ could use to identify FCA violations.<\/li>\n<\/ul>\n<h3>Best Practices for DoD Contractors<\/h3>\n<p>To avoid costly fines\/penalties, reputational damage, or loss of contracts, DoD contractors should:<\/p>\n<ul>\n<li>Ensure scores in the SPRS system accurately reflect the Company\u2019s current cybersecurity practices.<\/li>\n<li>If your IT team is indicating that cybersecurity practices are not meeting NIST 800-171 requirements, take actions to update SPRS scores, create POA&amp;Ms, and begin remediation efforts to resolve gaps.<\/li>\n<li>If you have performed the company\u2019s self-assessment internally without any outside assistance, you should consider having an independent party (e.g., RPO or C3PAO) perform a gap assessment to confirm the company meets the NIST SP 800-171 cybersecurity requirements.<strong> In fact, in a recent webinar with three C3PAOs that are performing CMMC assessments, they indicated that contractors who performed their NIST 800-171 assessment internally were far more likely to fail a CMMC assessment.<\/strong> Unless you have gone through the trainings required to become a Registered Practitioner (RP), Registered Practitioner Advanced (RPA), CMMC Certified Professional (CCP), and CMMC Certified Assessor (CCA), it is difficult to understand what will be required to meet each of the required 110 cybersecurity practices during a CMMC assessment.<\/li>\n<\/ul>\n<h3>Conclusion: Cybersecurity Missteps Can Cost Millions<\/h3>\n<p>False Claims Act fines\/penalties related to cybersecurity are on the rise. The DoJ has made it clear: If you certify compliance with cybersecurity requirements and fail to uphold them, you may be held accountable \u2014 financially and legally.<\/p>\n<p>With whistleblower provisions incentivizing insiders to come forward and DoJ actively pursuing violations, defense contractor executives need to be vigilant and ensure that their cybersecurity statements are accurate and can be supported under the scrutiny of a cybersecurity assessment.<\/p>\n<p>Keiter\u2019s\u00a0<a href=\"https:\/\/keitercpa.com\/services\/consulting-advisory\/cybersecurity-services\/\" target=\"_blank\" rel=\"noopener\">Cybersecurity<\/a>\u00a0team will continue to monitor the rollout of the CMMC program and update you on new information and changing requirements for DoD contractors.<\/p>\n<p>If you want to work with consultants with knowledge of NIST, CMMC framework, and hold <a href=\"https:\/\/cyberab.org\/Member\/RP-2877-Mcauliffe-Scott\" target=\"_blank\" rel=\"noopener\">Registered Practitioner (RP) status<\/a>,\u00a0<a href=\"https:\/\/keitertechnologies.com\/services\/innovative-data-solutions\/cybersecurity\/\" target=\"_blank\" rel=\"noopener\">Keiter\u2019s team of cybersecurity specialists<\/a>\u00a0can help you.\u00a0<a href=\"https:\/\/keitercpa.com\/contact\/\" target=\"_blank\" rel=\"noopener\">Email<\/a>\u00a0| Call: 804.747.0000.<\/p>\n<p><a href=\"https:\/\/keitertechnologies.com\/blog\/\" target=\"_blank\" rel=\"noopener\">Access all of our CMMC resources and insights.<\/a><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>The cost of cybersecurity noncompliance As the Department of Defense (DoD) continues its focus on securing the defense industrial base, cybersecurity compliance has not only left contractors scrambling to get compliant before CMMC regulations are included in their contracts, but it also has them on edge because of the wave of recent multimillion dollar False [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11759],"tags":[11693,15439,3534,1521,26493],"dealstore":[],"offerexpiration":[],"class_list":["post-242173","post","type-post","status-publish","format-standard","hentry","category-accounting","tag-claims","tag-cybersecurity","tag-false","tag-high","tag-stakes"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The High Stakes of Cybersecurity False Claims - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=242173\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The High Stakes of Cybersecurity False Claims - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"The cost of cybersecurity noncompliance As the Department of Defense (DoD) continues its focus on securing the defense industrial base, cybersecurity compliance has not only left contractors scrambling to get compliant before CMMC regulations are included in their contracts, but it also has them on edge because of the wave of recent multimillion dollar False [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=242173\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-14T21:59:00+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=242173#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=242173\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"The High Stakes of Cybersecurity False Claims\",\"datePublished\":\"2025-05-14T21:59:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=242173\"},\"wordCount\":815,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"keywords\":[\"claims\",\"Cybersecurity\",\"False\",\"High\",\"Stakes\"],\"articleSection\":[\"Accounting\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=242173#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=242173\",\"url\":\"https:\/\/fivemor.com\/?p=242173\",\"name\":\"The High Stakes of Cybersecurity False Claims - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"datePublished\":\"2025-05-14T21:59:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=242173#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=242173\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=242173#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The High Stakes of Cybersecurity False Claims\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"The High Stakes of Cybersecurity False Claims - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=242173","og_locale":"en_US","og_type":"article","og_title":"The High Stakes of Cybersecurity False Claims - Som2ny Network","og_description":"The cost of cybersecurity noncompliance As the Department of Defense (DoD) continues its focus on securing the defense industrial base, cybersecurity compliance has not only left contractors scrambling to get compliant before CMMC regulations are included in their contracts, but it also has them on edge because of the wave of recent multimillion dollar False [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=242173","og_site_name":"Som2ny Network","article_published_time":"2025-05-14T21:59:00+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=242173#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=242173"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"The High Stakes of Cybersecurity False Claims","datePublished":"2025-05-14T21:59:00+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=242173"},"wordCount":815,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"keywords":["claims","Cybersecurity","False","High","Stakes"],"articleSection":["Accounting"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=242173#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=242173","url":"https:\/\/fivemor.com\/?p=242173","name":"The High Stakes of Cybersecurity False Claims - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"datePublished":"2025-05-14T21:59:00+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=242173#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=242173"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=242173#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"The High Stakes of Cybersecurity False Claims"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/242173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=242173"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/242173\/revisions"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=242173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=242173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=242173"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=242173"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=242173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}