$2 Million DOJ Settlement Warns Contractors: Cybersecurity Compliance is a Contractual Accuracy Issue
The U.S. Department of Justice (DOJ) has announced a $2 million settlement with Honeywell Aerospace Inc., a company that provides aerospace products and solutions to government and commercial customers, over allegations that it failed to comply with cybersecurity requirements applicable to a Department of Defense contract.
According to the DOJ, from April 2020 through December 2023, a business unit of Honeywell International Inc. allegedly submitted claims for payment while failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) with respect to one of its networks.
The settlement is part of a growing body of cybersecurity-related False Claims Act (FCA) enforcement actions, with the DOJ recovering more than $52 million across nine such settlements in fiscal year 2025 alone.
Cybersecurity deficiencies can potentially become allegations concerning the accuracy of claims for government payment, and companies must ensure that there is no disconnect between what is stated to be implemented and what has actually been deployed.