Matthew F. Ferraro
Overview
Matthew F. Ferraro is a partner in Crowell & Moring’s Privacy and Cybersecurity Group, where he helps clients address complex regulatory matters at the intersection of advanced technology, national security, and crisis management. He advises leading organizations on high-impact matters related to artificial intelligence (AI) and other emerging technologies, cyberattacks, domestic and international privacy compliance, internal investigations, foreign direct investment reviews, and high-stakes crises.
Career & Education
- Department of Homeland Security
- Senior Counselor for Cybersecurity and Emerging Technology to the Secretary, 2023–2025; Executive Director of the Artificial Intelligence Safety and Security Board, 2024–2025
- Central Intelligence Agency (CIA)
- Intelligence Officer, 2009–2010
- Office of the Director of National Intelligence
- Executive Assistant to the Deputy Director for Policy, Plans, and Requirements, 2007–2009
- Special Assistant to the Chief of Staff, 2006–2007
- Department of Homeland Security
- Adjunct Professor of Law, George Mason University, 2022–Present
- Stanford Law School, J.D., with pro bono distinction, 2013
- University of Cambridge, MPhil, historical studies, with distinction, 2005
- Yale University, B.A., history, with distinction, 2004
- District of Columbia
- California
- U.S. Court of Appeals for the District of Columbia Circuit
- U.S. Court of Appeals for the Ninth Circuit
- The Hon. John G. Koeltl, U.S. District Court for the Southern District of New York, 2015–2016
- The Hon. A. Raymond Randolph, U.S. Court of Appeals for the District of Columbia Circuit, 2014–2015
- The Hon. Jay S. Bybee, U.S. Court of Appeals for the Ninth Circuit, 2013–2014
- Life Member, Council on Foreign Relations, 2025–Present (Term Member, 2017–2023)
- Senior Fellow, National Security Institute, 2018–Present
Matthew's Insights
Client Alert | 4 min read | 09.21.26
In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality
In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
Client Alert | 7 min read | 09.14.26
AI in Life Sciences: Ten Legal Considerations and Risks of AI Use in Drug Discovery and Development
Publication | 08.19.26
The Next Saga In The End-to-End Encryption Debate: When the Cure Becomes the Crisis
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations
Insights
The Next Saga In The End-to-End Encryption Debate: When the Cure Becomes the Crisis
|08.19.26
Cybersecurity and AI Law Report
- |
07.27.26
The Journal of Federal Agency Action
Navigating Deepfakes in Litigation, Arbitration, and Mediation
|04.09.26
American Bar Association, GPSolo March/April 2026
Three Steps Tech Companies Can Take Today To Prepare To Ride A Blue Wave In 2026
|11.14.25
Washington Technology
Big Tech finds a foe in Texas’ robust consumer protection laws and AG Ken Paxton
|06.03.26
The Texas Tribune
Antitrust Agenda: Paxton’s Pending Departure Leaves Hole in State AG Antitrust Lineup
|06.01.26
The Capitol Forum
- |
06.16.26
Crowell & Moring's Government Contracts Legal Forum
DOJ Launches FOCUS Initiative, Seeks Data Miners to Assist in Identifying and Building Fraud Claims
|05.11.26
Crowell & Moring’s International Trade Law
White House National AI Policy Framework Calls for Preempting State Laws, Protecting Children
|04.25.26
Crowell & Moring’s Retail & Consumer Products Law Observer
- |
04.16.26
Crowell & Moring’s State AG Blog
Landmark Verdicts Against Meta and YouTube Signal New Era of Social Media Platform Liability
|04.01.26
Crowell & Moring’s Retail & Consumer Products Law Observer
AI for Government: 7 Days for Contractor Comments on GSA Proposed Contract Clause for AI Systems
|03.16.26
Crowell & Moring’s Government Contracts Legal Forum
DHS Announces Virtual Town Halls on CIRCIA Final Rule
|02.20.26
Crowell & Moring’s Government Contracts Legal Forum
CMMC for AI? Defense Policy Law Imposes AI Security Framework and Requirements on Contractors
|01.08.26
Crowell & Moring’s Government Contracts Legal Forum
The FY 2026 National Defense Authorization Act
|12.29.25
Crowell & Moring’s Government Contracts Legal Forum
Federal and State Regulators Target AI Chatbots and Intimate Imagery
|10.30.25
Crowell & Moring’s State AG Blog
Matthew's Insights
Client Alert | 4 min read | 09.21.26
In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality
In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.
Client Alert | 7 min read | 09.14.26
AI in Life Sciences: Ten Legal Considerations and Risks of AI Use in Drug Discovery and Development
Publication | 08.19.26
The Next Saga In The End-to-End Encryption Debate: When the Cure Becomes the Crisis
Client Alert | 4 min read | 08.14.26
License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations




