Michael G. Gruden is an associate in Crowell & Moring's Washington, D.C. office where he is a member of the firm’s Government Contracts and Privacy & Cybersecurity groups. He possesses real-world experience in the areas of federal procurement and data security, having worked as a Contracting Officer at both the U.S. Department of Defense (DoD) and the U.S. Department of Homeland Security (DHS) in the Information Technology, Research & Development, and Security sectors for nearly 15 years. Michael is also a Certified Information Privacy Professional with a U.S. government concentration (CIPP/G).
Michael’s legal practice covers a wide range of counseling and litigation engagements at the intersection of government contracts and cybersecurity. His government contracts endeavors include supply chain security counseling, contract disputes with federal entities, suspension and debarment proceedings, mandatory disclosures to the government, prime-subcontractor disputes, and False Claims Act investigations. His privacy & cybersecurity practice includes cybersecurity compliance reviews, risk assessments, data breaches, incident response, and regulatory investigations.
Government Contracts
Michael assists government contractors with federal contract compliance and administration matters throughout the contract lifecycle – from solicitation and award to audit, investigation, and termination. He advises clients on Federal Acquisition Regulations (FAR) provisions and clauses, as well as agency supplements such as the Defense Federal Acquisition Regulation Supplement (DFARS), Homeland Security Acquisition Regulations (HSAR), and others.
Michael has counseled clients on a variety of government contracts issues including, but not limited to:
- Conducted internal investigations of government contractors, addressing a variety of issues relating to government contracts and regulations.
- Prepared clients for supply chain management audits and assessments including Contractor Purchasing System Reviews (CPSR).
- Assisted clients in suspension and debarment matters and drafted comprehensive responses to notices of proposed debarment.
- Represented government contractors in bid protests before the Government Accountability Office (GAO).
- Advised government contractors regarding organizational conflicts of interest and post-government employment restrictions.
Cybersecurity
Michael has leveraged his procurement experience to advise numerous clients on DoD cybersecurity contract clauses. He has assisted clients in navigating the cybersecurity regulatory landscape by conducting compliance assessments, reviewing system security plans (SSPs) and plans of action and milestones (POAMs), and advising on Controlled Unclassified Information (CUI) marking guidance. Michael counsels clients on all aspects of cyber incident and data breach response, including working with forensic security consultants, conducting internal investigations, interacting with law enforcement, and complying with data breach notification laws. He also helps clients develop incident preparedness strategies and table-top exercises to assist companies in mitigating risks presented by data breach incidents.
Michael has counseled clients on a variety of data privacy and cybersecurity issues including, but not limited to:
- Engaged in longstanding partnerships with multiple defense contractors to devise compliance strategies for DFARS 252.204-7012, including routine gap assessments and subsequent remediation plans.
- Assisted major retailer with data breach notification reporting obligations and coordinated consumer and state notifications, as appropriate.
- Helped clients assess and comply with cyber incident reporting obligations under DFARS 252.204-7012.
- Conducted compliance assessments for clients and interpreted NIST SP 800-171 and NIST SP 800-53 regulatory requirements.
- Advised clients on cloud service provider requirements under DFARS 252.204-7012 and DFARS 252.239-7010.
- Counseled contractors regarding information security programs concentrating on Covered Defense Information (CDI), Controlled Unclassified Information (CUI), and Sensitive Security Information (SSI).
Government Experience
Michael’s extensive federal procurement experience allows him to uniquely counsel his clients with a real-world perspective concerning contract evaluation and administration, as well as cybersecurity compliance.
U.S. Department of Defense
- Branch Chief for Information Technology and Physical Security Acquisitions at Washington Headquarters Services (WHS), a 4th Estate DoD field activity responsible for the contracting needs of the Office of the Secretary of Defense (OSD) and the Pentagon Reservation. As an unlimited warrant Contracting Officer, Michael awarded, oversaw the award of or acted as the Source Selection Authority (SSA) of:
- $500M solicitation for information technology services spanning the entire Pentagon Reservation, where Michael worked with the Chief Information Officer and other Senior Executive Service members to develop the acquisition strategy and request for proposal (RFP).
- Courtroom technology contracts at Guantanamo Bay, Cuba for 9/11 detainee military tribunals.
- 24/7 global information technology support for the Office of the Secretary of Defense and their advance staff.
- Travel agreements for the Secretary of Defense’s OCONUS and all CONUS travel.
- Modernization of IT infrastructure for DoD’s primary alternate site, continuity of operations (COOP) facility.
- Satellite tower construction and information technology development in the Asian Pacific to landmark drug, human, and weapon trafficking in concert with U.S. partnering nations.
- Wargaming, modeling, and simulation contracts in support of war planning directorate of OSD.
- Cooperative agreement for glass manufacturing facility in Afghanistan.
- Security installation and repair services for electronic security systems and infrastructure throughout Pentagon Reservation.
- Meteorological and laboratory services for Chemical, Biological, Radiological, Nuclear (CBRNE) defense.
- Michael was detailed for six months to the Office of the General Counsel, where he assisted attorneys in the defense of protests filed before the Government Accountability Office (GAO) and the U.S. Court of Federal Claims (COFC).
U.S. Department of Homeland Security
- Acquisition Professional at DHS Headquarters supporting Science & Technology (S&T) Directorate and Homeland Security Advanced Research Projects Agency (HSARPA), among others; Contracting Officer at Immigration and Customs Enforcement (ICE). Collectively, Michael worked to:
- Lead renovations for multiple DHS alternate site, continuity of operations facilities managing a suite of renovation construction contracts encompassing data centers, supervisory control and data acquisition (SCADA) systems, power grids, and water treatment facilities.
- Administer Broad Agency Announcement (BAA) solicitation encompassing all program missions within S&T. Engaged with industry regarding the BAA, liaised between industry, members of Congress, the Executive Director of S&T, and program offices.
- Award cybersecurity and CBRNE contracts for S&T and HSARPA.
- Partner with the Office of Security to award essential IT software and hardware contracts.
Michael earned his law degree from Georgetown University Law Center, where he was an editor of the Journal of National Security Law & Policy.
Affiliations
Admitted to practice: District of Columbia, New York
Speeches & Presentations
-
"Cutting Edge Cybersecurity Developments," North Alabama Federal Bar Association Acquisition and Employment Symposia
(November 12, 2019).
Presenter: Michael G. Gruden.
-
"DoD Cyber Regulations and the Rise of False Claims Act Cyber Liability," DHG Government Contracting Webinar
(October 23, 2019).
Presenter: Michael G. Gruden.
-
"Confronting the Challenges of Supply Chain Security," Crowell & Moring Webinar
(September 25, 2019).
Presenters: Adelicia R. Cliffe, Paul Freeman, Kate M. Growley, and Michael G. Gruden.
-
"Accounting Cost & Pricing Compliance and Pitfalls," Government Contracts Breakfast Series, Herndon, VA
(September 18, 2019).
Presenters: Nicole Owren-Wiest, Elizabeth Buehler, Charles Baek, Michael G. Gruden, and Catherine O. Shames.
-
"3D Printing in Government Contracts: What Contractors Need to Know Before Adopting This Innovation," Crowell & Moring Webinar
(November 8, 2018).
Speakers: Gail D. Zirkelbach, Mana Elihu Lombardo, and Michael G. Gruden.
-
"Under Scrutiny: Contractors and Cybersecurity," OOPS 2018, Crowell & Moring's 34th Annual Ounce of Prevention Seminar, Washington, D.C.
(May 17, 2018).
Presenters: Paul M. Rosen, Evan D. Wolff, David Z. Bodenheimer, and Michael G. Gruden.
Publications
-
"Defending Cybersecurity False Claims Act Allegations," Bloomberg Law
(September 18, 2019).
Authors: Jason M. Crawford, David B. Robbins, Kate M. Growley, and Michael G. Gruden.
-
"DoD Increases DCMA Cybersecurity Responsibilities: DCMA to Implement and Assess Company-Wide Cyber Compliance," Crowell & Moring's Government Contracts Legal Forum
(February 21, 2019).
Authors: Evan D. Wolff, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G, Payal Nanavati and Judy Choi.
-
"SEC Encourages Internal Accounting Controls to Guard Against Cyber Fraud ," Crowell & Moring's Data Law Insights
(November 8, 2018).
Authors: Paul M. Rosen, Daniel L. Zelenko, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G and Paul Mathis.
-
"NIST Offers Insight Into Updated Risk Management Framework," Crowell & Moring's Data Law Insights
(October 30, 2018).
Authors: Peter B. Miller, Kate M. Growley and Michael G. Gruden.
-
"Navy Boils The Ocean on Cyber," Crowell & Moring's Data Law Insights
(October 24, 2018).
Authors: Evan D. Wolff, Kate M. Growley and Michael G. Gruden.
-
"New Internet of Things (IoT) NIST Draft Publication Provides Welcomed Guidance," Crowell & Moring's Data Law Insights
(October 17, 2018).
Authors: Cheryl A. Falvey, Kate M. Growley and Michael G. Gruden.
-
"Finally, Cyber Help For Small Businesses Is On Its Way," Law360
(October 1, 2018).
Authors: Evan D. Wolff, Paul M. Rosen, Kate M. Growley, and Michael Gruden.
-
"Colorado’s New Data Privacy Bill Increases Notification and Safeguarding Requirements," Crowell & Moring's Data Law Insights
(July 17, 2018).
Authors: Evan D. Wolff, Maida Oringher Lerner, Matthew B. Welling and Michael G. Gruden.
-
"How Quickly Should Contractors Report Data Breaches? GAO Denies Protest Finding 12 Hours Is Not Fast Enough," Crowell & Moring's Government Contracts Legal Forum
(May 7, 2018).
Authors: Christian N. Curran and Michael G. Gruden.
-
"New Draft NIST Guidance on Systems Security Engineering," Crowell & Moring's Government Contracts Legal Forum
(April 24, 2018).
Authors: Evan D. Wolff, Peter B. Miller, Maida Oringher Lerner, Kate M. Growley, Judy Choi, Michael G. Gruden and Payal Nanavati.
-
"Is Government Data at Risk? Study Finds Industry Cybersecurity Lagging Government," Crowell & Moring's Data Law Insights
(February 26, 2018).
Authors: Paul M. Rosen, Kate M. Growley and Michael G. Gruden.
-
"National Archives Issues New, But Limited, CUI Contract Guidance," Crowell & Moring's Data Law Insights
(February 8, 2018).
Authors: Kate M. Growley and Michael G. Gruden.
-
"U.K. Announces Fines Up To $24M For Cyber Noncompliance," Crowell & Moring's Data Law Insights
(January 31, 2018).
Authors: Maida Oringher Lerner, Maarten Stassen and Michael G. Gruden.
-
"New GDPR Guidance from EU Commission," Crowell & Moring's Data Law Insights
(January 25, 2018).
Authors: Maarten Stassen and Michael G. Gruden.
-
"FERC Proposes to Require Expanded Cyber Security Incident Reporting," Crowell & Moring's Data Law Insights
(January 17, 2018).
Authors: Evan D. Wolff, Maida Oringher Lerner, Deborah A. Carpentier, Matthew B. Welling and Michael G. Gruden.
Client Alerts & Newsletters
-
"Supply Chain Perspectives — Connecting the Dots on Supply Chain Security and Risk Management,"
Government Contracts Bullet Points
(December 2, 2019).
Contacts: Peter Eyre, Adelicia R. Cliffe, Kate M. Growley, CIPP/G, CIPP/US, Judy Choi, Nicole Owren-Wiest, Paul Freeman, Michael G. Gruden, CIPP/G
-
"Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates,"
Government Contracts Bullet Points
(November 13, 2019).
Contacts: Evan D. Wolff, Maida Oringher Lerner, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"Zero Hour: Contractors Face Increased FCA Exposure for Cybersecurity Noncompliance,"
False Claims Bullet Points
(September 25, 2019).
Contacts: David B. Robbins, Evan D. Wolff, Kate M. Growley, CIPP/G, CIPP/US, Jason M. Crawford, Michael G. Gruden, CIPP/G
-
"Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification,"
Government Contracts Bullet Points
(September 10, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"Supply Chain Perspectives — Connecting the Dots on Supply Chain Security and Risk Management,"
Government Contracts Bullet Points
(August 22, 2019).
Contacts: Peter Eyre, Adelicia R. Cliffe, Kate M. Growley, CIPP/G, CIPP/US, Judy Choi, Paul Freeman, Michael G. Gruden, CIPP/G
-
"Under the Wire: FAR Council Announces Interim Rule to Implement NDAA Procurement Ban on Huawei and Other Chinese Telecommunications Equipment,"
Government Contracts Bullet Points
(August 13, 2019).
Contacts: Adelicia R. Cliffe, Paul Freeman, Alan W. H. Gourley, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"Uncontrolled Information: DoD Audit Finds Contractor Lapses in Protecting Controlled Unclassified Information ,"
Government Contracts Bullet Points
(August 2, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"DCMA Revises Cyber Supply Chain Review: Updated Guidebook Modifies Audit Standards,"
Government Contracts Bullet Points
(July 16, 2019).
Contacts: Evan D. Wolff, Nicole Owren-Wiest, Maida Oringher Lerner, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"These Are a Few of Our Favorite IoT: NIST Finalizes Internet of Things Cyber Guidance,"
Government Contracts Bullet Points
(July 2, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Cheryl A. Falvey, Evan D. Wolff, Peter B. Miller, CIPP/G/US/E, CIPM, CIPT, Michael G. Gruden, CIPP/G
-
"Double Whammy: NIST Unveils Draft Enhanced Security Requirements and Revisions to NIST SP 800-171,"
Government Contracts Bullet Points
(June 21, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"DoD Previews New Third-Party Cyber Certification Requirements,"
Government Contracts Bullet Points
(June 17, 2019).
Contacts: Evan D. Wolff, Maida Oringher Lerner, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"It All Adds Up: What’s New with DCAA (May 2019),"
Podcast: It All Adds Up
(May 7, 2019).
Contacts: Elizabeth Buehler, Charles Baek, Nicole Owren-Wiest, Michael G. Gruden, CIPP/G, Catherine O. Shames
-
"Navy Identifies Defense Industrial Base Cyber Shortcomings in New Report,"
Government Contracts Bullet Points
(March 22, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"DCMA’s Cybersecurity Oversight Takes Shape: Revised CPSR Guidebook Outlines DFARS Safeguarding Clause Audit Standards,"
Government Contracts Bullet Points
(March 6, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Christopher D. Garcia, Nicole Owren-Wiest, Michael G. Gruden, CIPP/G
-
"Upping the Cyber Oversight Ante: DoD Deploys DCMA to Audit Contractor Supply Chain Compliance,"
Government Contracts Bullet Points
(January 28, 2019).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Nicole Owren-Wiest, Michael G. Gruden, CIPP/G
-
"DoD's Own Cyber Monday Deal: Releasing DFARS Cyber Enhancement Guidance,"
Government Contracts Bullet Points
(November 27, 2018).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"Navy Makes Waves By Increasing Cybersecurity Requirements for Select Defense Industrial Base Contractors,"
Government Contracts Bullet Points
(November 1, 2018).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Michael G. Gruden, CIPP/G
-
"New National Cyber Strategy Outlines President's Cyber Agenda,"
Privacy Law Alert
(October 5, 2018).
Contacts: Evan D. Wolff, Paul M. Rosen, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G, Lee Matheson, CIPP/US/E/A, CIPM, PCIP
-
"Finally Heard – Cyber Help for Small Businesses is on Its Way,"
Government Contracts Bullet Points
(August 22, 2018).
Contacts: Evan D. Wolff, Paul M. Rosen, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"FY 2019 NDAA – Cyber Focus,"
Government Contracts Bullet Points
(August 20, 2018).
Contacts: Evan D. Wolff, Paul M. Rosen, Maida Oringher Lerner, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"A New Privacy and Data Control Framework in California,"
Privacy Law Alert
(June 29, 2018).
Contacts: Jeffrey L. Poston, Christopher A. Cole, Evan D. Wolff, Paul M. Rosen, Robert Holleyman, Maya Uppaluru, Maarten Stassen, Michael G. Gruden, CIPP/G
-
"NIST Offers a Two-for-One Special on Cybersecurity Updates,"
Government Contracts Bullet Points
(June 20, 2018).
Contacts: Paul M. Rosen, Evan D. Wolff, Maida Oringher Lerner, Kate M. Growley, CIPP/G, CIPP/US, Michael G. Gruden, CIPP/G
-
"Forget The Showers. April Brings Flurry of New Cyber Guidance.,"
Government Contracts Bullet Points
(May 1, 2018).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"Final Draft of NIST SP 800-171A Gives Contractors Something to Sample,"
Government Contracts Bullet Points
(March 1, 2018).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Maida Oringher Lerner, Michael G. Gruden, CIPP/G
-
"National Archives Issues Non-FAR-Based Guidance for Controlled Unclassified Information,"
Government Contracts Bullet Points
(February 13, 2018).
Contacts: Michael G. Gruden, CIPP/G, Evan D. Wolff, Paul M. Rosen, Kate M. Growley, CIPP/G, CIPP/US
-
"Uncooperative: Court Holds That Cooperative Agreement is Not a Contract,"
Government Contracts Bullet Points
(December 14, 2017).
Contacts: Stephen J. McBrady, Skye Mathieson, Monica DiFonzo Sterling, Michael G. Gruden, CIPP/G
-
"No Post-Thanksgiving Break for Cyber – DoD and NIST Publish New Guidance,"
Government Contracts Bullet Points
(December 1, 2017).
Contacts: Kate M. Growley, CIPP/G, CIPP/US, Evan D. Wolff, Paul M. Rosen, Michael G. Gruden, CIPP/G
-
"To Disclose or Not To Disclose: Federal Government & Cybersecurity Vulnerabilities,"
Government Contracts Bullet Points
(November 16, 2017).
Contacts: Matthew B. Welling, Peter B. Miller, CIPP/G/US/E, CIPM, CIPT, Paul M. Rosen, David Baron, Michael G. Gruden, CIPP/G, Evan D. Wolff
Firm News & Announcements