Growing Cybersecurity Risks
Cyber risk is consistently ranked as a top risk facing higher education. Moody's recently recently echoed this sentiment, rating the sector as "high risk." However, an area of cyber risk that may be less well known is the correlation between cyber security requirements in government contracts and the financial impact of compliance associated with federal statutes.
๐๐ฎ๐น๐๐ฒ ๐๐น๐ฎ๐ถ๐บ๐ ๐๐ฐ๐: The False Claims Act (FCA), 31 U.S.C. ยงยง 3729 - 3733, is a federal statute that has existed since 1863. It was created in response to defense contractor fraud during the American Civil War. Per the Civil Division of the US Department of Justice, "The FCA provides that any person who knowingly submits, or causes to submit, false claims to the government is liable for three times the government's damages plus a penalty that is linked to inflation." So, what does this Civil War statute have to do with higher education?
๐ฃ๐ฒ๐ป๐ป ๐ฆ๐๐ฎ๐๐ฒ ๐ฆ๐ฒ๐๐๐น๐ฒ๐บ๐ฒ๐ป๐: The federal government questioned Penn State's cybersecurity controls after a whistleblower alleged that the University failed to adhere to the cybersecurity requirements required by a Department of Defense (DoD) contract. The allegations also included that the University lied to the government about its cybersecurity program. This misrepresentation was costly for Penn State, which agreed to pay $๐ญ.๐ฎ๐ฑ ๐บ๐ถ๐น๐น๐ถ๐ผ๐ป to settle the allegations.
๐ช๐ต๐ฎ๐ ๐ฐ๐ฎ๐ป ๐ฏ๐ฒ ๐ฑ๐ผ๐ป๐ฒ? This article by Carlton Fields provides valuable insights and risk mitigations to help your institution avoid costly fines and penalties associated with the False Claims Act.
๐๐ฒ๐ ๐๐ฎ๐ธ๐ฒ๐ฎ๐๐ฎ๐๐
Boards and fiduciaries must understand that contractual compliance with the US government is strictly scrutinized.
Boards and fiduciaries need to support investment in strong institutional cybersecurity policies and the risk management tools required to implement cyber controls.
Be mindful of how your institution represents itself to the federal government. Misrepresentations are costly.
Carlton Fields suggests that Universities should add a "False Claims Act-compliant whistleblower policy and include a procedure for routing and resolving employee complaints related to cybersecurity."
Failing to comply with contractual requirements and misrepresenting your institution's cyber security program can result in headlines and fines. Be proactive and support solid cyber risk management practices to avoid loss of reputation with the federal government, which can impact future contracts and the trust of the campus community.
Have something to add? Share your thoughts on LinkedIn.