Published 2026 | TIKC NewsWire
One number tells this entire story. A defense contractor allegedly reported a cybersecurity self-assessment score of 104, near the top of the scale, when its actual score was negative 142. That gap, between the security it claimed and the security it had, cost the company $4.6 million to resolve under the False Claims Act. For any contractor that has ever entered a score into the government’s system and moved on, this case is a warning worth reading twice.
What the government alleged
According to the Department of Justice, the contractor resolved allegations that it failed to meet cybersecurity requirements on Department of Defense contracts and misrepresented its compliance. The alleged failures were specific and stackable:
- Third-party email hosting used for years without ensuring the vendor met the required security baseline or the DoD cyber-incident-reporting rules.
- Incomplete NIST SP 800-171 controls, including protections meant to stop network exploitation and the exfiltration of defense information.
- No consolidated System Security Plan documenting system boundaries and how controls were implemented.
- A false SPRS score: a reported 104 when the real figure was negative 142, and the correction did not come until months after a DOJ subpoena.
Why the SPRS score is the heart of it
Defense contractors handling covered information must assess themselves against NIST SP 800-171 and post a score in the Supplier Performance Risk System (SPRS). That score is a representation the government relies on to decide you are safe to hold its data. Reporting a score you have not earned is not an optimistic estimate. It is a false statement that can make every related invoice a false claim. The contractor here allegedly claimed near-perfection while sitting at a deeply negative score, which is exactly the kind of misrepresentation the Civil Cyber-Fraud Initiative was built to pursue.
The delay made it worse
Notice the timeline. The inflated score allegedly sat in the system for more than two years, and the correction came only after a subpoena. Waiting until the government is already investigating to fix a false representation does not look like a good-faith mistake. It looks like concealment, which cuts hard against a contractor and squarely against the mandatory-disclosure expectation. If your score is wrong, the time to fix it is the moment you know, not the moment you are caught.
The whistleblower, again
As in so many of these cases, it started with an insider. A whistleblower brought the qui tam suit and received roughly $851,000 of the recovery. The pattern across the recent cyber-fraud settlements is consistent: the people who know your real security posture, your own IT staff and engineers, are the ones who can end up as relators. A score that your technical team knows is false is a liability sitting inside your own building.
What to do now
- Make your SPRS score real. Base it on an honest NIST SP 800-171 assessment, not an aspiration.
- Write the System Security Plan. A consolidated SSP is required, and its absence is itself a finding.
- Vet your vendors. Email hosting and other services that touch covered information must meet the baseline and reporting rules.
- Fix errors immediately. Correct a wrong score the day you discover it, not after a subpoena.
- Listen to your technical team. If engineers say the score is not real, that is the warning, and the future relator, speaking.
Your cybersecurity score is a promise about how you protect the nation’s information. Earn the number before you post it, and keep it honest, and this is one headline you will never be in. Brick by brick.
FAQ
What is an SPRS score?
A score, based on a NIST SP 800-171 self-assessment, that a defense contractor posts in the Supplier Performance Risk System. It represents the contractor’s cybersecurity compliance, and the government relies on it.
Why was reporting a high score a problem?
Because the contractor allegedly reported 104 when its real score was negative 142. Posting a score you have not earned is a misrepresentation that can turn related invoices into false claims.
Did the late correction help?
No. The correction allegedly came only after a DOJ subpoena, more than two years later. Waiting until you are investigated looks like concealment, not good faith.
How do these cases usually start?
Often with a whistleblower. Here, a relator brought the qui tam suit and received about $851,000. Technical staff who know the real posture are frequent sources.
Sources
U.S. Department of Justice. (2026). Defense contractor MORSECORP Inc. agrees to pay $4.6 million to settle cybersecurity fraud allegations.
U.S. District Court, District of Massachusetts. (2026). United States ex rel. Berich v. MORSECORP Inc., No. 23-cv-10130.
This article is general information, not legal advice.
About the Author
Melanie Patterson
Founder and CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale, brick by brick. Contact


