Dive Brief:
- Honeywell Aerospace recently reached a $2.04 million settlement with the Justice Department to resolve allegations that it failed to comply with cybersecurity requirements under a Department of Defense contract.
- The agreement resolves allegations from April 1, 2020, through Dec. 31, 2023, involving an IT unit of Honeywell International that submitted false claims for payment by not complying with DOD’s cybersecurity assessment requirements, according to the whistleblower’s complaint filed in March 2022.
- The settlement also resolves the whistleblower’s lawsuit filed under the False Claims Act, which allows a private individual to file to sue an entity on behalf of the federal government. The whistleblower, former Honeywell employee Rachel Tenney, will receive $375,823, according to the agreement.
Dive Insight:
DOD’s cybersecurity assessment requirements are mandatory under the National Institute of Standards and Technology’s regulations, which aims to safeguard sensitive information.
The requirement is part of the DOD’s Cybersecurity Maturity Model Certification program, which has been in the works since 2019. It also falls under the Defense Federal Acquisition Regulation Supplement which mandates that contractors report cyber incidents to DOD.
The federal government claimed in the lawsuit that Honeywell began its “fraudulent scheme” when it received a quantum computing contract in 2020, according to court documents. It was around the same time period that the SolarWinds attack occurred, in which over 30,000 public and private organizations — including local, state and federal agencies — that used software company SolarWinds’ Orion network management system were hacked.
The hack compromised data, networks and systems by camouflaging malware as an Orion software update. Honeywell’s IT unit, called the Advanced Connected Sustainability Technologies, or ACST, created a network for its quantum contracts dubbed the “Gray Network,” which is supposed to protect and preserve highly confidential government and research and development information, according to the lawsuit.
However, Honeywell used SolarWinds' Orion software, which monitored and had high-level permissions, on the Gray network. When the global hack happened, Honeywell allegedly only took care of its commercial business unit, but “turned a blind eye” on its government contracting unit and failed to report the cybersecurity incident. The hack also led Honeywell to allegedly submit false claims to receive payment.
The ACST unit was established under Honeywell Technologies, before a spin off completed in June made Honeywell Aerospace a separate entity. The Honeywell conglomerate had multiple business groups including aerospace and industrial automation, but the IT unit was not a part of the aerospace unit. However, the ACST has moved under Honeywell Aerospace as part of the separation.
“It was in the best interest of Honeywell Aerospace to resolve this matter without further litigation,” the company said. “The settlement does not include any admission of wrongdoing. Honeywell Aerospace has been and remains committed to a robust and fully compliant cybersecurity program that protects our networks and our customers. Honeywell Aerospace complies with all applicable cybersecurity requirements and laws and its contractual and regulatory obligations.”
The Honeywell Aerospace settlement “should not be viewed in isolation,” according to a Sept. 8 post insight by law firm Shumaker. Over the past year, the DOJ has been suing various government contractors for allegedly not complying with NIST’s defense cybersecurity regulations and submitting false claims.
In June, defense contractor Logzone agreed to pay $507,144 to resolve the DOJ's False Claims Act’s accusations for contracts with the Department of the Navy.
RTX subsidiary, Raytheon, and national security solutions company Nightwing Group agreed to pay $8.4 million in May 2025 to settle allegations they violated the False Claims Act by failing to comply with DOD’s cybersecurity requirements.
The Honeywell Aerospace settlement emphasizes that cybersecurity compliance is “increasingly becoming enterprise legal risk,” Shumaker said in its post insights.
“For organizations receiving federal funds or performing government contracts, technical controls, contractual promises, security assessments, and payment claims are becoming increasingly interconnected,” Shumaker said. “A cybersecurity deficiency therefore cannot always be treated as an isolated IT problem, particularly as CMMC implementation introduces independent third-party verification requirements that will make compliance gaps harder to overlook.”
DOD temporarily paused Phase 2 of its CMMC program on July 13. The agency formed a reform task force to conduct a 60-day review charged with restructuring DOD’s supply chain cybersecurity approach so that it “strictly aligns” with the agency’s Acquisition Transformation Strategy, according to a July 13 memo by CIO Kirsten Davies. Recommendations may be released in October.