<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Common Sense Is Dead. But the False Claims Act and Cybersecurity Liability Just Got Interesting. in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Common-Sense-Is-Dead-But-the-False-Claims-Act-and-Cybersecurity/m-p/83031#M7609</link>
    <description>&lt;P&gt;It is quite alarming to know that the Illumina settlement didn't even appear as a byline in my news feed.&amp;nbsp; Thank you for sharing this, sir.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Aug 2025 14:04:37 GMT</pubDate>
    <dc:creator>ericgeater</dc:creator>
    <dc:date>2025-08-12T14:04:37Z</dc:date>
    <item>
      <title>Common Sense Is Dead. But the False Claims Act and Cybersecurity Liability Just Got Interesting.”</title>
      <link>https://community.isc2.org/t5/Industry-News/Common-Sense-Is-Dead-But-the-False-Claims-Act-and-Cybersecurity/m-p/83014#M7605</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Once upon a time, in a world not yet swallowed by legalese, cybersecurity frameworks, and acronyms so dense, they could stop a ransomware attack out of sheer confusion, we had something called &lt;STRONG&gt;Common Sense&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;He taught us things like:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Don't touch hot things.&lt;/LI&gt;&lt;LI&gt;Don't lie.&lt;/LI&gt;&lt;LI&gt;Lock the damn door.&lt;/LI&gt;&lt;LI&gt;And perhaps most relevant now: &lt;STRONG&gt;Don’t sell a product that’s defective and tell the buyer it’s bulletproof.&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;But alas, &lt;STRONG&gt;Common Sense&lt;/STRONG&gt; died. According to the &lt;EM&gt;London Times&lt;/EM&gt;, he passed quietly after a prolonged illness, preceded in death by &lt;STRONG&gt;Truth&lt;/STRONG&gt;, &lt;STRONG&gt;Trust&lt;/STRONG&gt;, and &lt;STRONG&gt;Responsibility&lt;/STRONG&gt;. He is survived by his loud, litigious stepchildren:&lt;/P&gt;&lt;P class=""&gt;“I Know My Rights,” “I Want It Now,” “Someone Else Is to Blame,” and “I’m a Victim.”&lt;/P&gt;&lt;P class=""&gt;Today, however, we are not here to mourn. We are here to warn. Because as it turns out, &lt;STRONG&gt;False Claims Act violations now come gift-wrapped in cybersecurity negligence &amp;nbsp;and not just for government contractors anymore.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Case in Point: The Illumina DNA Debacle&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;The Department of Justice just slapped Illumina, a DNA sequencing giant, with a &lt;STRONG&gt;$9.8 million settlement&lt;/STRONG&gt;. Not for a data breach. Not for ransomware. Not even for medical misdiagnosis. But for what?&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Selling medical devices to the government while lying about their cybersecurity posture.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;According to whistleblowers and prosecutors, Illumina promised it adhered to NIST standards, FDA’s &lt;STRONG&gt;Quality System Regulation (QSR)&lt;/STRONG&gt;, and all the usual regulatory bedtime stories, but in reality, they left default admin settings, plaintext credentials, and a few invitations to hackers under the digital doormat.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“We Meant to Patch That.”&lt;/STRONG&gt; &lt;EM&gt;Buried next to: “The intern had it on his to-do list.”&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;Imagine selling armored trucks to the government with cardboard floors but signing off that you used titanium. That’s what happened. And the&lt;STRONG&gt;False Claims Act&lt;/STRONG&gt; doesn’t take kindly to being lied to. Even if no one &lt;EM&gt;yet&lt;/EM&gt; got hurt.&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;But Here's Where the Plot Thickens:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;If you think this only applies to &lt;STRONG&gt;companies selling to Uncle Sam&lt;/STRONG&gt;, think again.&lt;/P&gt;&lt;P class=""&gt;Because &lt;STRONG&gt;lying about cybersecurity isn’t just bad for federal contracts, it’s bad business.&lt;/STRONG&gt; And it may soon be bad &lt;EM&gt;criminal defense strategy&lt;/EM&gt; if someone gets hurt.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“The CISO Signed Off.”&lt;/STRONG&gt; &lt;EM&gt;Turns out the 'CISO' was Carl from Accounting. He's very sorry.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;The Legal Risk Spaghetti: FCA + QSR + Product Liability&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Let’s untangle it:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;False Claims Act (FCA)&lt;/STRONG&gt;: Lie to the government about the safety or compliance of your product = triple damages + civil penalties. Boom.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Quality System Regulation (21 CFR Part 820)&lt;/STRONG&gt;: Mandates manufacturers document how their products are safe, secure, and well-managed. (Spoiler: screenshots of "we got it" Slack messages don’t count.)&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Product Liability&lt;/STRONG&gt;: When someone &lt;EM&gt;does&lt;/EM&gt; get hurt either physically, financially, reputationally, because your product was insecure by design, the &lt;STRONG&gt;tort bar&lt;/STRONG&gt; will be there, filing claims faster than you can say “patch management lifecycle.”&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“It Was Only a Marketing Statement.”&lt;/STRONG&gt; &lt;EM&gt;Cause of death: Discovery subpoena.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Security By Design: Not Just a Platitude&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;The idea is simple. Make cybersecurity part of your &lt;STRONG&gt;design phase&lt;/STRONG&gt;, not just a &lt;STRONG&gt;compliance checklist&lt;/STRONG&gt; signed by an intern.&lt;/P&gt;&lt;P class=""&gt;To quote JP Morgan CISO Patrick Optet:&lt;/P&gt;&lt;P class=""&gt;“Secure and resilient by design must go beyond slogans , it requires continuous, demonstrable evidence that controls are working effectively…”&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Translation: &lt;STRONG&gt;"Trust us, we’re secure"&lt;/STRONG&gt; is dead. &lt;STRONG&gt;Common Sense killed it&lt;/STRONG&gt; before he passed. And “Trust, but audit” is the new sheriff in town.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“We Followed Industry Best Practices.”&lt;/STRONG&gt; &lt;EM&gt;Which, unfortunately, means “whatever we made up last quarter.”&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;This Isn't Just a Government Problem. It’s a &lt;/STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;Boardroom&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt; Problem.&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Every company that:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Claims SOC2 compliance in a sales pitch,&lt;/LI&gt;&lt;LI&gt;Embeds a “secure login” icon in a PowerPoint slide,&lt;/LI&gt;&lt;LI&gt;Certifies HIPAA compliance in a business associate agreement,&lt;/LI&gt;&lt;LI&gt;Or signs off on a D&amp;amp;O policy with &lt;EM&gt;“adequate cyber controls”&lt;/EM&gt; attestation…&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;…might be creating &lt;STRONG&gt;false claims&lt;/STRONG&gt; or &lt;STRONG&gt;warranty breaches&lt;/STRONG&gt; they’ll wish they hadn’t when:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A breach happens,&lt;/LI&gt;&lt;LI&gt;The class actions come,&lt;/LI&gt;&lt;LI&gt;The insurance claim gets denied,&lt;/LI&gt;&lt;LI&gt;And the audit trail leads back to &lt;STRONG&gt;someone in marketing saying, “just put secure on it.”&lt;/STRONG&gt; I’ve seen it a million times!&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“Our Insurance Will Cover It.”&lt;/STRONG&gt; &lt;EM&gt;Gravestone reads: “Claim Denied — Material Misrepresentation.”&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;What Would Common Sense Say?&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Common Sense, if he weren’t six feet under, would whisper:&lt;/P&gt;&lt;P class=""&gt;“If you don’t design it securely, don’t say that you did.” “If your CISO is part-time and reports to IT, get a will.” “Security theater is not a defense strategy.” Because your Lawyer is not an IT Specialist and God Help you if it is an OT event…Pucker up!&lt;/P&gt;&lt;P class=""&gt;And for private-sector executives?&lt;/P&gt;&lt;P class=""&gt;“If you think the FCA won’t apply to you, wait until your biggest client is the VA, a public university hospital, or a federally funded research lab.”&lt;/P&gt;&lt;P class=""&gt;Why are we so certain? Welcome to the Second-Order liabilities of which you probably have no clue what that means.&amp;nbsp; Well, reality didn’t die… and reality says you gotta pay up for this information!&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“The Client Never Asked About That.”&lt;/STRONG&gt; &lt;EM&gt;Until the breach. Then they asked. In court.&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Final Words from the Grave&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Common Sense may be gone. But perhaps his ghost lives on in &lt;STRONG&gt;regulatory enforcement&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class=""&gt;He tried to warn us with phrases like:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;“Don’t sell a lie.”&lt;/LI&gt;&lt;LI&gt;“Don’t delegate security to chance.”&lt;/LI&gt;&lt;LI&gt;“Don’t certify what you can’t prove.”&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;But we were too busy shouting:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;“That’s not &lt;EM&gt;my&lt;/EM&gt; job.”&lt;/LI&gt;&lt;LI&gt;“We have insurance for that.”&lt;/LI&gt;&lt;LI&gt;“Legal signed off!”&lt;/LI&gt;&lt;LI&gt;And The Best one…” Blame the Intern”!&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Postmortem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;“We Had a Strong Security Culture.”&lt;/STRONG&gt; &lt;EM&gt;Until the phishing email said, “Free Pizza.”&lt;/EM&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;So, Here’s the Call to Action:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Whether you’re in government procurement, healthcare tech, fintech SaaS, or you're just the guy responsible for that checkbox on your company’s compliance spreadsheet:&lt;/P&gt;&lt;P class=""&gt;A.&amp;nbsp;&amp;nbsp; Bake security into your products.&lt;/P&gt;&lt;P class=""&gt;B.&amp;nbsp;&amp;nbsp; &amp;nbsp;Document everything like your bonus depends on it.&lt;/P&gt;&lt;P class=""&gt;C.&amp;nbsp;&amp;nbsp; Assume your biggest client has a whistleblower with a conscience and a lawyer.&lt;/P&gt;&lt;P class=""&gt;D.&amp;nbsp;&amp;nbsp; And whatever you do, &lt;STRONG&gt;don’t certify something you can’t prove&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class=""&gt;Because in the absence of &lt;STRONG&gt;Common Sense&lt;/STRONG&gt;, we now have the &lt;STRONG&gt;False Claims Act&lt;/STRONG&gt;, the &lt;STRONG&gt;QSR&lt;/STRONG&gt;, &lt;STRONG&gt;class action lawyers&lt;/STRONG&gt;, and possibly (more than likely) your &lt;STRONG&gt;personal assets&lt;/STRONG&gt; on the line.&lt;/P&gt;&lt;P class=""&gt;May Common Sense rest in peace. May your audit trail not end up as Exhibit A.&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;Coming next week from the graveyard of good intentions:&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;“The Tragic Tale of Documentation Deferred,” “Gone Too Soon: The Patch That Never Was,” and “We Hired a Consultant (But Never Read the Report).”&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;EM&gt;For those who want to see the muse of my logic …Read on!&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;EM&gt;An Obituary printed in the London Times&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Today we mourn the passing of a beloved old friend, Common Sense,&amp;nbsp;who has been with us for many years. No one knows for sure how old he&amp;nbsp;was, since his birth records were long ago lost in bureaucratic red&amp;nbsp;tape. He will be remembered as having cultivated such valuable&amp;nbsp;lessons as:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Knowing when to come in out of the rain;&lt;/LI&gt;&lt;LI&gt;Why the early bird gets the worm;&lt;/LI&gt;&lt;LI&gt;Life isn't always fair; and&lt;/LI&gt;&lt;LI&gt;Maybe it was my fault.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Common Sense lived by simple, sound financial policies (don't spend&amp;nbsp;more than you can earn) and reliable strategies (adults, not&amp;nbsp;children, are in charge). His health began to deteriorate rapidly when well-intention ed but&amp;nbsp;overbearing regulations were set in place. Reports of a 6-year-old&amp;nbsp;boy charged with **gender** harassment for kissing a classmate; teens&amp;nbsp;suspended from school for using mouthwash after lunch; and a teacher&amp;nbsp;fired for reprimanding an unruly student, only worsened his&amp;nbsp;condition. Common Sense lost ground when parents attacked teachers for doing&amp;nbsp;the job that they themselves had failed to do in disciplining their&amp;nbsp;unruly children. It declined even further when schools were required to get parental&amp;nbsp;consent to administer sun lotion or an aspirin to a student; but&amp;nbsp;could not inform parents when a student became pregnant and wanted to&amp;nbsp;have an abortion. Common Sense lost the will to live as the churches became&amp;nbsp;businesses; and criminals received better treatment than their&amp;nbsp;victims. Common Sense took a beating when you couldn't defend yourself from a&amp;nbsp;burglar in your own home and the burglar could sue you for assault. Common Sense finally gave&amp;nbsp;up the will to live, after a woman failed&amp;nbsp;to realise that a steaming cup of coffee was hot. She spilled a&amp;nbsp;little in her lap, and was promptly awarded a huge settlement. Common Sense was preceded in death, by his parents, Truth and Trust,&amp;nbsp;by his wife, Discretion, by his daughter, Responsibility, and by his&amp;nbsp;son, Reason. He is survived by his 4 stepbrothers;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I Know My Rights&lt;/LI&gt;&lt;LI&gt;I Want It Now&lt;/LI&gt;&lt;LI&gt;Someone Else Is To Blame&lt;/LI&gt;&lt;LI&gt;I'm A Victim&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Not many attended his funeral because, so few realized he was gone. If&amp;nbsp;you still remember him, pass this on. If not, join the majority and&amp;nbsp;do nothing.&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Thank you to Gerry Kennedy&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;A href="https://www.linkedin.com/pulse/common-sense-dead-false-claims-act-cybersecurity-just-gerry-kennedy-35l5e" target="_blank" rel="noopener"&gt;https://www.linkedin.com/pulse/common-sense-dead-false-claims-act-cybersecurity-just-gerry-kennedy-35l5e&lt;/A&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Regards&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2025 05:41:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Common-Sense-Is-Dead-But-the-False-Claims-Act-and-Cybersecurity/m-p/83014#M7605</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2025-08-12T05:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Common Sense Is Dead. But the False Claims Act and Cybersecurity Liability Just Got Interesting.</title>
      <link>https://community.isc2.org/t5/Industry-News/Common-Sense-Is-Dead-But-the-False-Claims-Act-and-Cybersecurity/m-p/83031#M7609</link>
      <description>&lt;P&gt;It is quite alarming to know that the Illumina settlement didn't even appear as a byline in my news feed.&amp;nbsp; Thank you for sharing this, sir.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Aug 2025 14:04:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Common-Sense-Is-Dead-But-the-False-Claims-Act-and-Cybersecurity/m-p/83031#M7609</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2025-08-12T14:04:37Z</dc:date>
    </item>
  </channel>
</rss>

