Jessica R. Chao
Overview
Jessica advises clients on a wide range of internal and government-facing investigations, with a specialized focus on navigating the challenges arising at the intersection of government contracts and cybersecurity. She also supports clients with general compliance in government contract transactions, developing corporate policies, procedures, and governance, and conducting cybersecurity compliance reviews. Her practice also includes assisting clients with due diligence in transactions.
Career & Education
- University of Denver Sturm College of Law, J.D., Corporate and Commercial Law Certificate and Workplace Law Certificate
- Pepperdine University, B.A., cum laude
- Colorado
- Appellate Judicial Clerk to the Honorable Lino S. Lipinsky de Orlov, Colorado Court of Appeals
- Colorado Bar Association
- American Bar Association
-
-
- Young Lawyers Division
- Public Contract Law
-
-
- Colorado Asian Pacific American Bar Association
-
-
- Board of Directors
- Co-chair, Community Outreach Committee
- Member, Mentorship Committee
-
-
- Korean
Jessica's Insights
Client Alert | 4 min read | 09.21.26
In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality
In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
Client Alert | 2 min read | 09.11.26
New ISOO Guidance Directs Federal Agencies to Provide More CUI Guidance to Contractors
Client Alert | 5 min read | 07.21.26
Insights
Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review
|07.22.26
Crowell & Moring's Government Contracts Legal Forum
Logged Out: How LOGZONE’s DIBCAC Challenges Put It Squarely in DOJ’s Crosshairs
|07.13.26
Crowell & Moring's Government Contracts Legal Forum
FedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures
|04.22.26
Crowell & Moring’s Government Contracts Legal Forum
FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment
|01.26.26
Crowell & Moring’s Government Contracts Legal Forum
FedRAMP Proposes Updates to Authorization Process—Six New RFCs Released for Public Comment
|01.22.26
Crowell & Moring’s Government Contracts Legal Forum
An ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.
|12.29.25
Crowell & Moring’s Government Contracts Legal Forum
Jessica's Insights
Client Alert | 4 min read | 09.21.26
In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality
In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
Client Alert | 2 min read | 09.11.26
New ISOO Guidance Directs Federal Agencies to Provide More CUI Guidance to Contractors
Client Alert | 5 min read | 07.21.26




