Cybersecurity Enforcement: The More Things Change, The More They Stay the Same

Cohen Seglias Pallas Greenhall & Furman PC
Contact

MORSECORP’s Compliance History

In January 2021, MORSECORP entered a summary-level assessment score of 104 into the Supplier Performance Risk System (SPRS) as to its implementation of the security controls of NIST SP 800-171. Assessment scores can range from a low of -203 to a high of 110. In May 2022, MORSECORP engaged an outside cybersecurity consultant to perform a gap analysis of the company’s cybersecurity implementation. The consultant scored MORSECORP’s system -142 and proposed dozens of plans and milestones for the company to comply with NIST SP 800-171. Despite this, MORSECORP did not update its compliance score in SPRS for nearly a year, until June 15, 2023, when the company submitted a third-party score of 57. This was three months after the DOJ had served a subpoena on the company its cybersecurity practices. Notably, there was no indication that any protected information was compromised due to the company’s deficient cybersecurity.

Admission of Responsibility

Based on the above-described conduct, the government asserted that between January 2021 and the end of February 2023, claims for payment under Army and Air Force contracts were false or fraudulent. MORSECORP ultimately agreed to pay $4.6 million to resolve the allegations brought forward by the company’s head of security and facility security officer under the qui tam provisions of the False Claims Act.

Lessons from the Enforcement

This is yet another reminder that cybersecurity remains a paramount concern to the government and that it remains committed to ensuring contractors comply with the cybersecurity obligations.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Cohen Seglias Pallas Greenhall & Furman PC

Written by:

Cohen Seglias Pallas Greenhall & Furman PC
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Cohen Seglias Pallas Greenhall & Furman PC on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide