Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

The DOJ Goes Phishing: The Rise of False Claims Act Cybersecurity Litigation

By Annie Railton, James Gatta, Jud Welle and Emily Notini
March 01, 2022

This past October, Deputy Attorney General Lisa Monaco announced the launch of the Department of Justice's (DOJ) Civil Cyber-Fraud Initiative targeting entities and individuals that fail to follow government cybersecurity standards. Under the initiative, to be led by the Fraud Section of the Civil Division's Commercial Litigation Branch, the DOJ announced that it would utilize its powerful enforcement tool — the False Claims Act (FCA) — to pursue cybersecurity-related fraud by government contractors and grant recipients. Shortly after the announcement, in remarks at the Cybersecurity and Infrastructure Security Agency (CISA) 4th Annual National Cybersecurity Summit on Oct. 13, 2021, DOJ Civil Division acting Assistant Attorney General Brian Boynton described three "prime candidates" for potential FCA enforcement under the initiative: 1) providing products or services that fail to comply with cybersecurity standards; 2) misrepresenting security controls and practices; and 3) failing to timely report suspected cybersecurity breaches.

The DOJ's initiative comes alongside increased government activity to curb cybersecurity and government contractor risks. Earlier last year, emphasizing this new focus on cybersecurity and compliance, President Biden issued an Executive Order on Improving the Nation's Cybersecurity (EO 14028), which called for, among other things, federal agencies to adopt updated contractual requirements for information technology (IT) and operational technology (OT) contractors to share information about potential cyber threats. In January 2022, President Biden signed a National Security Memorandum to Improve the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems, calling out cybersecurity as a national security and economic security imperative for the administration. And on Feb. 9, 2022, the Securities and Exchange Commission (SEC) announced upcoming new rules requiring registrants to maintain cybersecurity polices and standards and report significant cyber incidents to the SEC, among other things.

While the DOJ Civil Cyber-Fraud Initiative is still in its early stages and cybersecurity regulations are evolving, whistleblower plaintiffs have already begun leveraging the FCA to pursue alleged noncompliance with government cybersecurity requirements.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Overview of Regulatory Guidance Governing the Use of AI Systems In the Workplace Image

Businesses have long embraced the use of computer technology in the workplace as a means of improving efficiency and productivity of their operations. In recent years, businesses have incorporated artificial intelligence and other automated and algorithmic technologies into their computer systems. This article provides an overview of the federal regulatory guidance and the state and local rules in place so far and suggests ways in which employers may wish to address these developments with policies and practices to reduce legal risk.

Is Google Search Dead? How AI Is Reshaping Search and SEO Image

This two-part article dives into the massive shifts AI is bringing to Google Search and SEO and why traditional searches are no longer part of the solution for marketers. It’s not theoretical, it’s happening, and firms that adapt will come out ahead.

While Federal Legislation Flounders, State Privacy Laws for Children and Teens Gain Momentum Image

For decades, the Children’s Online Privacy Protection Act has been the only law to expressly address privacy for minors’ information other than student data. In the absence of more robust federal requirements, states are stepping in to regulate not only the processing of all minors’ data, but also online platforms used by teens and children.

Revolutionizing Workplace Design: A Perspective from Gray Reed Image

In an era where the workplace is constantly evolving, law firms face unique challenges and opportunities in facilities management, real estate, and design. Across the industry, firms are reevaluating their office spaces to adapt to hybrid work models, prioritize collaboration, and enhance employee experience. Trends such as flexible seating, technology-driven planning, and the creation of multifunctional spaces are shaping the future of law firm offices.

From DeepSeek to Distillation: Protecting IP In An AI World Image

Protection against unauthorized model distillation is an emerging issue within the longstanding theme of safeguarding intellectual property. This article examines the legal protections available under the current legal framework and explore why patents may serve as a crucial safeguard against unauthorized distillation.