The Stakes for Complying With DoD Cybersecurity Requirements Are Higher Than Ever

The United States government has been ramping up its efforts to protect sensitive data and is making clear it expects its contractors to protect data they receive and create. According to a recent Inspector General report, Department of Defense contractors are not consistently implementing mandatory cybersecurity controls.
Defense contractors’ cybersecurity posture is under the microscope—cybersecurity audits are increasing, and the DoD is relying on cyber-compliance in contract award and cancellation. Moreover, cybersecurity-based False Claims Act cases are becoming a common occurrence. Companies must understand and implement their obligations to safeguard information received or generated under a DoD contract. As Katie Arrington, chief information security officer of the Pentagon’s acquisition policy office, reportedly told contractors this past Wednesday: “This is a change of culture. It’s going to take time, it’s going to be painful, and it’s going to cost money.”

