Honeywell Aerospace Pays $2M Over Cybersecurity False Claims Act Settlement

2 min readSources: National Law Review

Honeywell Aerospace settled for $2 million over alleged False Claims Act cybersecurity violations.

Why it matters: Government contractors must ensure compliance with federal cybersecurity standards like NIST SP 800-171 to avoid FCA risks and costly penalties.

  • Honeywell Aerospace settled for $2,042,518 to resolve FCA allegations involving cybersecurity noncompliance.
  • The claims relate to failure to meet NIST SP 800-171 standards for protecting Controlled Unclassified Information from April 2020 through December 2023.
  • Former employee Rachel Tenney filed the whistleblower lawsuit and will receive a $375,823 share of the settlement.
  • Honeywell Aerospace separated from Honeywell International Inc. in June 2023, affecting corporate structure during the alleged violations.

Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve allegations under the False Claims Act (FCA) concerning its failure to meet federal cybersecurity standards.

The U.S. Department of Justice alleged that Honeywell did not comply with the National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) requirements, which protect Controlled Unclassified Information (CUI) on Department of Defense contracts. The period cited was April 2020 to December 2023.

The suit originated from a whistleblower complaint filed by former Honeywell employee Rachel Tenney. Under the settlement terms, Tenney will receive $375,823 as a share of the recovered funds. This payout reflects the DOJ's ongoing use of the FCA to incentivize employees to report compliance failures internally.

Officials emphasized the importance of cybersecurity compliance in government contracting. Brett A. Shumate, Assistant Attorney General for the DOJ Civil Division, said, "Government contractors entrusted with defense information must comply with required cybersecurity standards." Complementing this, Russ Ferguson, U.S. Attorney for the Western District of North Carolina, stated, "Cybersecurity rules for federal contractors exist to safeguard government systems and data from unauthorized access."

Honeywell Aerospace operated as part of Honeywell International Inc. until June 29, 2023, when it spun off as an independent company. The span of alleged noncompliance mostly precedes this separation.

The DOJ has not disclosed specific cybersecurity gaps, and Honeywell has not publicly commented on remedial measures taken. Nonetheless, this case underscores the growing FCA risks tied to inadequate cybersecurity practices among government contractors.

Legal and compliance teams should give priority to aligning cybersecurity programs with federal standards such as NIST SP 800-171 to minimize exposure to enforcement actions.

By the numbers:

  • $2,042,518 — total settlement amount paid by Honeywell Aerospace
  • $375,823 — whistleblower Rachel Tenney's share of settlement
  • April 2020 to December 2023 — timeframe of alleged cybersecurity noncompliance