A Lake Barrington-based company will pay nearly $500,000 after the Department of Justice accused it of failing to provide adequate cybersecurity for drawings of parts it supplied to Defense contractors.
Swiss Automation Inc. agreed to pay $421,234 to resolve False Claims Act violation allegations that it failed to provide adequate cybersecurity for certain drawings of parts that the company machined and supplied to Department of Defense (DoD) prime contractors.
Swiss Automation is a precision machining business based in Lake Barrington that supplies alloy and metal parts to commercial and government customers in many industries, including DoD prime contractors and subcontractors.
The Department of Justice (DOJ) said that Swiss Automation caused the submission of false claims by not providing adequate cybersecurity to safeguard certain drawings of parts that the company machined and supplied to DoD prime contractors.
The DOJ also said the company knew that the requirement to provide adequate security by implementing certain cybersecurity controls applied not only to DoD prime contractors but also to subcontractors and suppliers to the prime contractors.
The obligation to implement security controls specified in the National Institute of Standards and Technology Special Publication to protect certain DoD information has applied to DoD contracts, subcontracts and similar contractual instruments since 2017, according to the DOJ.
“As cyber threats continue to evolve, suppliers to defense contractors must be vigilant and take the steps required to protect sensitive government information from bad actors,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division.
“We will continue our efforts to hold defense contractors, subcontractors, and suppliers accountable when they fail to honor their DoD cybersecurity commitments,” Shumate said.
“Cybercriminals are increasingly targeting government contractors to steal sensitive and valuable information in their possession,” U.S. Attorney Andrew S. Boutros for the Northern District of Illinois said.
“Defense contractors in particular must maintain robust safeguards against these threats through stringent compliance with federal cybersecurity regulations. The U.S. Attorney’s Office in Chicago will continue to work closely with our law enforcement and agency partners to ensure that government contractors protect sensitive information and critical infrastructure in compliance with federal laws and regulations,” Boutros said.
Special Agent-in-Charge Jason Sargenski of the DCIS’s Southeast Field Office said that protecting the nation’s security includes protecting its data.
“As cyber threats become more sophisticated, defense contractors, subcontractors, and suppliers must do their part to safeguard sensitive government information. We will hold contractors, subcontractors, and suppliers accountable when they fall short of their cybersecurity obligations to the Department of Defense,” Sargenski said.
The settlement resolves a lawsuit filed under the whistleblower provisions of the False Claims Act, which allow private parties to sue on behalf of the government when a person or company has submitted or caused to be submitted false claims for government funds.
The settlement in the case provides for the whistleblower, Jaime Gomez, a former quality-control manager at Swiss Automation, to receive $65,291 as his share of the settlement.