Contact Us

BREAKING: A Cyber Score of 104 That Was Really Negative 142. The $4.6 Million Lesson.

Published 2026 | TIKC NewsWire

One number tells this entire story. A defense contractor allegedly reported a cybersecurity self-assessment score of 104, near the top of the scale, when its actual score was negative 142. That gap, between the security it claimed and the security it had, cost the company $4.6 million to resolve under the False Claims Act. For any contractor that has ever entered a score into the government’s system and moved on, this case is a warning worth reading twice.

What the government alleged

According to the Department of Justice, the contractor resolved allegations that it failed to meet cybersecurity requirements on Department of Defense contracts and misrepresented its compliance. The alleged failures were specific and stackable:

  • Third-party email hosting used for years without ensuring the vendor met the required security baseline or the DoD cyber-incident-reporting rules.
  • Incomplete NIST SP 800-171 controls, including protections meant to stop network exploitation and the exfiltration of defense information.
  • No consolidated System Security Plan documenting system boundaries and how controls were implemented.
  • A false SPRS score: a reported 104 when the real figure was negative 142, and the correction did not come until months after a DOJ subpoena.

Why the SPRS score is the heart of it

Defense contractors handling covered information must assess themselves against NIST SP 800-171 and post a score in the Supplier Performance Risk System (SPRS). That score is a representation the government relies on to decide you are safe to hold its data. Reporting a score you have not earned is not an optimistic estimate. It is a false statement that can make every related invoice a false claim. The contractor here allegedly claimed near-perfection while sitting at a deeply negative score, which is exactly the kind of misrepresentation the Civil Cyber-Fraud Initiative was built to pursue.

GovCon iSource. Your pipeline runs while you run your business.

The delay made it worse

Notice the timeline. The inflated score allegedly sat in the system for more than two years, and the correction came only after a subpoena. Waiting until the government is already investigating to fix a false representation does not look like a good-faith mistake. It looks like concealment, which cuts hard against a contractor and squarely against the mandatory-disclosure expectation. If your score is wrong, the time to fix it is the moment you know, not the moment you are caught.

The whistleblower, again

As in so many of these cases, it started with an insider. A whistleblower brought the qui tam suit and received roughly $851,000 of the recovery. The pattern across the recent cyber-fraud settlements is consistent: the people who know your real security posture, your own IT staff and engineers, are the ones who can end up as relators. A score that your technical team knows is false is a liability sitting inside your own building.

What to do now

  • Make your SPRS score real. Base it on an honest NIST SP 800-171 assessment, not an aspiration.
  • Write the System Security Plan. A consolidated SSP is required, and its absence is itself a finding.
  • Vet your vendors. Email hosting and other services that touch covered information must meet the baseline and reporting rules.
  • Fix errors immediately. Correct a wrong score the day you discover it, not after a subpoena.
  • Listen to your technical team. If engineers say the score is not real, that is the warning, and the future relator, speaking.

Your cybersecurity score is a promise about how you protect the nation’s information. Earn the number before you post it, and keep it honest, and this is one headline you will never be in. Brick by brick.

Not sure where you fit? Start with a call. Book Free Call.

FAQ

What is an SPRS score?

A score, based on a NIST SP 800-171 self-assessment, that a defense contractor posts in the Supplier Performance Risk System. It represents the contractor’s cybersecurity compliance, and the government relies on it.

Why was reporting a high score a problem?

Because the contractor allegedly reported 104 when its real score was negative 142. Posting a score you have not earned is a misrepresentation that can turn related invoices into false claims.

Did the late correction help?

No. The correction allegedly came only after a DOJ subpoena, more than two years later. Waiting until you are investigated looks like concealment, not good faith.

How do these cases usually start?

Often with a whistleblower. Here, a relator brought the qui tam suit and received about $851,000. Technical staff who know the real posture are frequent sources.

GovCon iSource. Your pipeline runs while you run your business.

Sources

U.S. Department of Justice. (2026). Defense contractor MORSECORP Inc. agrees to pay $4.6 million to settle cybersecurity fraud allegations.

U.S. District Court, District of Massachusetts. (2026). United States ex rel. Berich v. MORSECORP Inc., No. 23-cv-10130.

This article is general information, not legal advice.

Melanie Patterson

About the Author

Melanie Patterson

Founder and CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale, brick by brick. Contact

Most Read

Federal grants come with rules as strict as any contract. The Uniform Guidance governs how
Government fraud enforcement increasingly reaches the people, not just the company. Owners and executives can

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading