Topic Archives: Cybersecurity & Data Privacy

U.S. Government Responds to SolarWinds Hack, Seeks to Establish New Norms for Cyber Espionage

After much anticipation and hints, the U.S. Government announced a series of measures to respond to recent Russian actions against the United States, including the SolarWinds intrusion campaign. The measures underscore that companies are not in a position and should not be left to defend against nation state actors on their own, and that the ...›

January 11, 2021Cybersecurity & Data Privacy

Top Cybersecurity Considerations for Government Contractors in 2021

Although it was already apparent, recent events have made it even clearer that cybersecurity is an essential concern for government contractors.  The coming year is poised to include many cybersecurity-related changes and developments.  Below we highlight just a few: Continued Rollout of Department of Defense’s CMMC Program The Department of Defense (DoD) interim rule for ...›

November 23, 2020Cybersecurity & Data Privacy

Deadline Fast Approaching for DoD Contractors and Subcontractors to Report Cyber Compliance

As we previously reported, the Department of Defense (DoD) has issued an interim rule that requires all contractors and subcontractors that store, process, generate, transmit or access “covered defense information” to conduct a self- assessment of compliance with NIST SP 800-171 using the DoD Assessment Methodology.  Contractors must post their self-assessment scores on the Defense ...›

Breaking DOD’s Code: How to Figure Out and Resist What DOD Really, Truly Wants to Do to Your Data Rights

Your rights in technical data and software are at greater risk today than at any time during the last 25 years.  The Department of Defense (“DOD”) is proposing the authority to rewrite commercial software licenses in ways never before seen and guaranteed to be rejected by your software suppliers, as well as proposing authority to ...›

FCA

U.S. District Court for the District of Columbia Finds That Alleged Cybersecurity Vulnerability Is Not Material Under False Claims Act

In a decision sure to bring some comfort to contractors providing information technology equipment and services to the federal government, a U.S. district court judge recently granted a motion to dismiss a False Claims Act (FCA) suit, finding that the relator both failed to establish materiality under the FCA and failed to prove the necessary scienter on the part of the contractor. ...›

September 30, 2020Cybersecurity & Data Privacy

Department of Defense Issues CMMC Interim Rule, Setting up a Two-Part Process for Review of Contractor IT Systems

On September 29, 2020, the Department of Defense (DoD) issued a long-anticipated interim rule implementing its Cybersecurity Maturity Model Certification (CMMC) program.  The rule introduces a new mandatory construct, the DoD Assessment Methodology, to serve as an interim certification process before contractors undergo a full CMMC review.  A full description of the interim rule and ...›

Department of Defense March Towards CMMC Continues

Although, as of late, the coronavirus and its impact have been top of mind for government contractors and, indeed, the entire world, the Department of Defense (DoD) has continued undeterred with its planned implementation of the Cybersecurity Maturity Model Certification (CMMC) program.  Below we highlight some recent developments, preview upcoming activities pertaining to CMMC, and ...›

Cyber Preparedness for Government Contractors: Opportunistic Hackers and the COVID-19 Pandemic

The COVID-19 pandemic has disrupted operations across the globe as government agencies and corporations grapple with the implications of remote work, workforce and workplace limitations, and employee health and safety.  But while this worldwide crisis has introduced new complexities and challenges, it also has presented an opportunity for hackers seeking to capitalize on the pandemic ...›

February 3, 2020Cybersecurity & Data Privacy

Department of Defense Takes a More Gradual Approach to Cybersecurity Maturity Model Certification

On January 31, 2020, the Department of Defense (DoD) issued the widely anticipated final version (v.1) of its Cybersecurity Maturity Model Certification (CMMC) Model. The version followed seven drafts and multiple rounds of comments from the contracting community. In the lead up to the release, DoD representatives walked back the timing for full implementation of ...›