The Department of Justice announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations arising from alleged noncompliance with cybersecurity requirements in a Department of Defense contract. The settlement is notable because the government framed the alleged falsity around payment requests submitted during periods of asserted cybersecurity noncompliance, rather than around a publicly identified data breach or compromise.The settlement resolves allegations and does not itself establish that Honeywell violated the False Claims Act. It nevertheless illustrates the enforcement theory DOJ is prepared to pursue.
What DOJ Alleged
According to DOJ, from April 2020 through December 2023, a Honeywell business unit submitted claims for payment while allegedly failing to comply with NIST SP 800-171 requirements applicable to a DoD contract and the network used to perform that work. DOJ alleged deficiencies involving malicious-code protection, access controls, monitoring, incident-response testing, and cyber-incident reporting practices.
DOJ’s public announcement does not identify a confirmed compromise of covered information as the basis for liability. Instead, the settlement reflects DOJ’s position that requests for payment may support False Claims Act liability when a contractor knowingly bills while materially failing to satisfy cybersecurity obligations tied to contract performance or payment.
Why the Covered System or Enclave Matters
The Honeywell matter highlights the importance of defining the particular system, enclave, or network used to perform covered work. A contractor does not necessarily avoid False Claims Act risk merely because its broader enterprise network is compliant. The relevant question may be whether the environment that stores, processes, or transmits controlled unclassified information for the contract satisfied the applicable requirements.
That scoping issue matters for businesses that segregate DoD work into discrete enclaves, use inherited cloud controls, or rely on multiple teams to maintain technical, compliance, and contracts records. The practical risk lies in a material disconnect between actual security practices and statements or submissions concerning those practices, particularly where those submissions bear on contract eligibility, continued performance, or payment.
Whistleblower and Knowledge Risk
The allegations were pursued through a qui tam action filed by a former employee, who received $375,823 as her share of the settlement. The qui tam posture demonstrates how personnel familiar with control deficiencies, delayed remediation, system boundaries, or incident handling may become important sources of information concerning what the contractor knew when it submitted claims for payment.
Practical Takeaways
Contractors performing DoD work should consider the following immediate steps:
- Confirm which systems, enclaves, cloud services, administrators, and subcontractors store, process, or transmit controlled unclassified information for each covered contract.
- Validate that implemented controls match written descriptions in system security plans, supplier flowdowns, internal assessments, and external submissions bearing on contract eligibility, continued performance, or payment.
- Preserve contemporaneous evidence showing how controls operate in practice, including logs, privileged-access reviews, malware defenses, incident-response exercises, remediation records, and reporting decisions.
- With appropriate legal oversight, assess whether claims for payment, certifications, or eligibility submissions overlapped with known material control deficiencies and whether those deficiencies were accurately disclosed and addressed.
- Strengthen internal escalation and anti-retaliation channels for cybersecurity and compliance concerns raised by information-technology, security, contracts, or program personnel.
Bottom Line
The Honeywell settlement demonstrates that DOJ may pursue cybersecurity-related False Claims Act allegations without identifying a successful intrusion or confirmed loss of controlled information. The central risk is the asserted disconnect between required controls, actual conditions on the system performing the contract, and the contractor’s continued requests for payment.