Just in Time for Halloween: DOJ Launches Cyber Enforcement Initiative Using False Claims Act
Client Alert | 1 min read | 10.08.21
On October 7, 2021, the Department of Justice (DOJ) announced its new Civil Cyber-Fraud Initiative, focused on civil enforcement against government contractors that fail to follow cybersecurity contract requirements. The Initiative, led by the Civil Division’s Commercial Litigation Branch and Fraud Section, will utilize the False Claims Act to combat cyber threats to sensitive information and critical systems by enforcing the government’s contractual cybersecurity standards. The Initiative will hold accountable contractors that knowingly: 1) provide deficient cybersecurity products or services; 2) misrepresent cybersecurity compliance; or 3) fail to monitor and report cybersecurity incidents in accordance with contract requirements.
In addition to contractor accountability, the benefits of the new Initiative are intended to include:
- Building broad resiliency against cybersecurity intrusions across the public and private sectors;
- Ensuring contractors that meet cybersecurity requirements are not at a competitive disadvantage;
- Reimbursing government and taxpayer losses incurred when contractors fail to satisfy their cybersecurity obligations; and
- Supporting efforts to timely issue patches for vulnerabilities in information technology products and services.
The Initiative formalizes what has for several years now been a stated priority area by DOJ for False Claims Act enforcement, as we have previously reported. In accord with the new Initiative, we expect to see an uptick in False Claims Act investigations, settlements, and litigation concerning cybersecurity issues, increased coordination among government agencies, and increased interest by those in the relator’s bar for qui tam actions.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 7 min read | 12.17.25
After hosting a series of workshops and issuing multiple rounds of materials, including enforcement notices, checklists, templates, and other guidance, the California Air Resources Board (CARB) has proposed regulations to implement the Climate Corporate Data Accountability Act (SB 253) and the Climate-Related Financial Risk Act (SB 261) (both as amended by SB 219), which require large U.S.-based businesses operating in California to disclose greenhouse gas (GHG) emissions and climate-related risks. CARB also published a Notice of Public Hearing and an Initial Statement of Reasons along with the proposed regulations. While CARB’s final rules were statutorily required to be promulgated by July 1, 2025, these are still just proposals. CARB’s proposed rules largely track earlier guidance regarding how CARB intends to define compliance obligations, exemptions, and key deadlines, and establish fee programs to fund regulatory operations.
Client Alert | 1 min read | 12.17.25
Client Alert | 7 min read | 12.17.25
Executive Order Tries to Thwart “Onerous” AI State Regulation, Calls for National Framework
Client Alert | 4 min read | 12.17.25
The new EU Bioeconomy Strategy: a regulatory framework in transition




