US Defence Contractor Fined 4.6 Million For Failing To Meet Cyber Security Requirements.

Share post:

A U.S. defence contractor, MORSE Corp, has agreed to pay $4.6 million to settle allegations of failing to meet cyber security requirements in its military contracts and knowingly submitting false claims for payment.

Based in Massachusetts, MORSE Corp specializes in developing guidance and navigation technology for military vehicles. The company’s cyber security shortcomings were brought to light through a whistleblower lawsuit filed by its former head of security under the False Claims Act.

Federal prosecutors outlined several cybersecurity failures by MORSE, including:

  • Cloud Security Missteps: Since 2018, MORSE utilized a third-party email hosting provider without ensuring the vendor met the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline, as required by their contracts. Additionally, the contractor failed to confirm the email provider adhered to Pentagon rules for incident reporting, malware handling, forensic access, and media preservation.
  • Non-Compliance with NIST Standards: MORSE neglected to fully implement all required National Institute of Standards and Technology (NIST) cybersecurity controls, including measures critical to preventing network exploitation or the exfiltration of controlled defence information.
  • Inaccurate Compliance Reporting: In January 2021, MORSE reported a compliance score of 104 out of 110 for its implementation of NIST Special Publication 800-171 security controls. However, a third-party cybersecurity consultant later assessed the company’s score at -142, indicating significant non-compliance.

As part of the settlement, MORSE will pay $4.6 million but does not admit liability. The resolution underscores the government’s commitment to enforcing cybersecurity standards among defence contractors to protect sensitive military information.

This case highlights the critical importance of stringent cybersecurity practices and accurate compliance reporting within the defence industry. It serves as a cautionary tale for contractors about the potential legal and financial repercussions of failing to adhere to mandated cybersecurity protocols.

 

SUBSCRIBE NOW

Related articles

Sleeper Supply Chain Attack Activates After 6 Years

A coordinated supply chain attack has compromised between 500 and 1,000 e-commerce websites by exploiting vulnerabilities in 21...

Russian-Controlled Open Source Tool Raises Alarms Over U.S. Cybersecurity

A widely used open-source Go library, easyjson, used in healthcare, finance and even defence has come under scrutiny...

Signal Archiving Tool Used By Trump Admin Is Breached, Raising Alarms Over Messaging Security (EDITORIAL)

(EDITORIAL) A messaging tool used by Trump administration officials to archive encrypted Signal messages has been hacked —...

Anthropic Warns: AI “Virtual Employees” Could Pose Security Risks Within a Year

Anthropic, a leading artificial intelligence company, anticipates that AI-powered virtual employees could begin operating within corporate networks as...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways