Kate M. GrowleyCIPP/G/US, AIGP, CMMC RP

Partner and Crowell Global Advisors Senior Director | CIPP/G/US, AIGP, CMMC RP

Overview

Businesses around the globe rely on Kate M. Growley to navigate their most challenging digital issues, particularly those involving cybersecurity, artificial intelligence, digital infrastructure, and their intersection with national security. Clients seek her guidance on proactive compliance, incident response, internal and government-facing investigations, and policy engagement. With a unique combination of legal, policy, and consulting experience, Kate excels in translating complex technical topics into advice that is practical and informed by risk and business needs.

Kate has extensive experience working with members of the U.S. government contracting community, especially those within the Defense Industrial Base. She has partnered with contractors from every major sector, including technology, manufacturing, health care, and professional services. Kate is an IAPP AI Governance Professional (AIGP) and a Certified Information Privacy Professional for both the U.S. private and government sectors (CIPP/G and CIPP/US). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB) and an adjunct professor on cybersecurity and AI with the National Security Institute at George Mason University’s Antonin Scalia Law School.

Having lived in Greater China for several years, Kate also brings an uncommon understanding of digital and national security requirements from across the Asia Pacific region. She has notable experience with the regulatory environments of Australia, Singapore, Japan, and Greater China—including the growing regulation of sensitive data flows between the United States and China.

Kate is a partner in the firm’s Washington, D.C. office, as well as a senior director in the firm’s consultancy Crowell Global Advisors, to which she was seconded for several years. She is a founding member of the firm’s Privacy and Cybersecurity Group and part of the firm’s AI Steering Committee. Kate’s substantial experience has been recognized by Chambers, Law360, and the American Bar Association (ABA). She currently serves as the co-chair of the ABA Cybersecurity Legal Task Force and as a council member of the ABA’s Science & Technology Section. Kate has also been inducted as a lifetime fellow in the American Bar Foundation.

Career & Education

    • Florida State University, B.S., summa cum laude, International Relations
    • University of Virginia School of Law, J.D.
    • Florida State University, B.S., summa cum laude, International Relations
    • University of Virginia School of Law, J.D.
    • Virginia
    • District of Columbia
    • Virginia
    • District of Columbia

Kate's Insights

Client Alert | 4 min read | 09.21.26

In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality

In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in  United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim....

Kate's Insights

Client Alert | 4 min read | 09.21.26

In a First, District Court Dismisses FCA Cybersecurity Complaint for Lack of Materiality

In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in  United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim....