List your product on Stack Search

Get in front of thousands of GRC decision-makers

Honeywell Aerospace to Pay $2 Million to Settle Cybersecurity False Claims Act Allegations

Honeywell Aerospace to Pay $2 Million to Settle Cybersecurity False Claims Act Allegations

By
Key Takeaways
  • Honeywell Aerospace Settles for $2 Million: Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations involving cybersecurity requirements under a U.S. Department of Defense contract.
  • NIST Cybersecurity Requirements at Issue: Prosecutors alleged that a Honeywell business unit failed to comply with requirements specified in NIST SP 800-171 for one of its networks between April 2020 and December 2023.
  • Contract Compliance Created False Claims Act Exposure: The government alleged the business unit submitted false claims for payment while failing to satisfy cybersecurity requirements imposed by the contract and regulation.
  • Whistleblower to Receive $375,823: Former Honeywell employee Rachel Tenney brought the underlying qui tam lawsuit and will receive a share of the settlement.
Deep Dive

Honeywell Aerospace has agreed to pay more than $2 million to settle allegations that a business unit failed to meet cybersecurity requirements attached to a U.S. Department of Defense contract, turning what might otherwise have remained a problem of technical compliance into a False Claims Act case.

The $2,042,518 settlement, announced Tuesday by the Justice Department, resolves allegations concerning one of Honeywell’s networks between April 2020 and December 2023. Federal prosecutors alleged that the business unit submitted false claims for payment while failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology Special Publication 800-171, or NIST SP 800-171, as required by the contract and regulation.

At the time, the business was part of Honeywell International Inc. Honeywell Aerospace became a standalone public company on June 29 and is headquartered in Phoenix.

The settlement resolves the government’s allegations without a determination of liability. But the case rests on an increasingly consequential premise for federal contractors: a cybersecurity requirement written into a government contract is not simply an instruction for the security team. When payment depends on compliance, the government can treat a failure to meet that requirement as a potential fraud matter.

“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division said. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.”

NIST SP 800-171 establishes requirements for protecting controlled unclassified information in nonfederal systems and organizations. The Defense Department has incorporated those protections into its contracting framework, giving requirements that can appear deeply technical a direct connection to the government’s decisions about whom it pays and on what terms.

That connection is what gives the Honeywell settlement its significance beyond the size of the payment. The Justice Department did not allege merely that a network fell short of a preferred security standard. It alleged that the company sought federal payment while failing to satisfy cybersecurity requirements imposed by its contract and regulation.

For companies doing business with the federal government, that distinction matters. Cybersecurity controls may be implemented by specialists, but representations about those controls can carry consequences far beyond the security function.

“Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data,” U.S. Attorney Russ Ferguson for the Western District of North Carolina said. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”

The case also followed a route that has long made the False Claims Act one of the federal government’s most formidable enforcement tools.

Rachel Tenney, a former Honeywell employee, brought the underlying lawsuit under the law’s qui tam provisions, which allow private individuals to sue on behalf of the United States and receive a portion of money recovered by the government. Tenney will receive $375,823 from the settlement.

The whistleblower mechanism is particularly potent in cybersecurity cases because the gap between what a contractor says about its controls and what actually exists inside its systems may be difficult to see from outside the organization. Employees can see both.

Honeywell Aerospace provides aerospace products and solutions to government and commercial customers. Before its separation this summer, it operated as a business segment of Charlotte, North Carolina-based Honeywell International.

For defense contractors, the lesson emerging from cases like this one is less about any single NIST control than about the boundary that has disappeared around cybersecurity compliance. A deficient control can begin as a technical problem. Once that control is promised to the government as part of a federal contract, however, the problem can acquire another identity entirely, one that belongs as much to legal, compliance and contracting teams as it does to cybersecurity.

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

🔒
Cancel anytime
Full archive access
Custom alerts

Oops! Something went wrong