logo

US defense contractor cops to sloppy security, settles after infosec lead blows whistle

ID: a65beeef-0977-5377-ba0d-729eac328490

STIX ID: report--a65beeef-0977-5377-ba0d-729eac328490

Feed Name: The Register (Security)

Date Published: 2025-03-26

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

A US defense contractor, MORSE Corp, agreed to a $4.6 million settlement after a whistleblower-led investigation found it failed to meet DoD cybersecurity requirements and allegedly submitted false claims, including misrepresenting its NIST SP 800-171 implementation score (reporting 104 vs. a third-party assessed -142). Prosecutors cited noncompliance with FedRAMP Moderate for email hosting, gaps in NIST control implementation, absence of required system security plans, and delayed correction of the firm’s SPRS score, while MORSE denies committing cybersecurity fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.