1. Home
  2. |Insights
  3. |An Opening Salvo for Cybersecurity FCA Cases

An Opening Salvo for Cybersecurity FCA Cases

Client Alert | 1 min read | 08.06.19

On July 31, 2019, Cisco Systems agreed to pay $8.6 million to settle allegations in United States ex rel Glenn, et al v. Cisco Systems, Inc. that the company violated the False Claims Act (FCA) by selling video surveillance systems to state and federal agencies that contained software flaws enabling those agencies to be hacked. An employee of one of Cisco’s resellers filed the suit in 2011 after discovering the alleged security weakness that could permit a cyber intruder to obtain administrative access to the software that managed video feeds.

The cybersecurity specialist alleged in his complaint that the company violated the FCA by (1) failing to inform government agencies that the software did not comply with the standards imposed by the Federal Information Security Management Act (FISMA) and (2) by providing a product that was worthless due to the security flaws in the software. Although this settlement marks the first time that a cybersecurity related qui tam has ended in a recovery through a settlement or judgment, it appears to be a sign of the times. As more such cases—alleging noncompliance with the DFARS Safeguarding Rule or FedRAMP requirements— are investigated and proceed through the courts, Glenn could be the first of many such recoveries.  

Insights

Client Alert | 5 min read | 08.21.26

FTC Proposes Enforcement Policy Statement on Personalized Pricing: What Businesses Need to Know

On August 19, 2026, the Federal Trade Commission (FTC) announced a proposed Enforcement Policy Statement on personalized pricing — the practice of companies using consumers’ personal data to set individualized prices, discounts, coupons, or other incentives. The proposed statement, which is open for public comment for 30 days following publication in the Federal Register, marks a major step up in the FTC’s focus on data-driven pricing strategies and puts businesses across industries on notice that undisclosed or inadequately disclosed personalized pricing will not be tolerated. Importantly, while the proposed statement is not a binding legal requirement and does not create new legal obligations, it serves as an enforcement warning that the FTC is prepared to use its existing enforcement authority under Section 5 of the FTC Act (Section 5) and is also a potential harbinger of rulemaking. Businesses that engage in — or are considering — personalized pricing should carefully assess their disclosure practices and data collection procedures against the standards articulated in this statement....