Penn State pays DoJ $1.25M to settle cybersecurity compliance case – The Register

TOPICS
Security
Fight On, State? Not this time
Pennsylvania State University has agreed to pay the Justice Department $1.25 million to settle claims of misrepresenting its cybersecurity compliance to the federal government and leaving sensitive data improperly secured. 
The settlement order between the DoJ and Penn State resolves allegations from a court case filed two years ago by a former university CIO who blew the whistle on the matter. Filing a case on behalf of the government (known as a qui tam complaint), Matthew Decker alleged that his former employer never implemented National Institute of Standards and Technology (NIST) cybersecurity requirements specified in contracts it had with the Pentagon and NASA. 
According to court documents, the DoJ took over the case to settle the matter, and its allegations are the same as Decker’s. 
The DoJ contends in its settlement agreement that Penn State failed to comply with NIST SP 800-171, which outlines requirements for how non-government entities have to store controlled unclassified information (CUI). Fifteen contracts between Penn State, the DoD, and NASA involved “collection, development, receipt, transmission, use or storing” of such info for the agencies, necessitating compliance with the NIST regulation. 
“Penn State did not implement certain NIST SP 800-171 security requirements, and did not adequately document, develop and implement plans of action designed to correct deficiencies,” the DoJ alleged. 
The settlement also contends that Penn State told the government in late 2020 that it hadn’t implemented all the requirements, but it never took steps to resolve the matter.
“Penn State also allegedly knowingly misstated … the dates by which it expected to implement all 110 of NIST SP 800-171’s requirements for those systems and failed to pursue plans of action for their implementation,” the DoJ said. 
In addition, the government argued (as did Decker) that Penn State abandoned its contract with government-compliant cloud host Box in favor of OneDrive, which doesn’t meet NIST’s CUI security requirements, to save money – hopefully more than $1.25 million. 
As Decker brought the original action, he’s eligible for a piece of the settlement pie, with the DoJ indicating he’ll be getting $250k of the settlement. 
Penn State (known where this vulture is from as the other original land grant university) expressed to The Register that the settlement wasn’t any admission of guilt on its part, and reiterated what it told us when we reported the Decker complaint in 2023 that it has significant resources devoted to complying with its obligations and enhancing cybersecurity.
As is often the publicly stated case with settlements like these, Penn State just wants to put the past behind it. 
“The University wishes to avoid costly and distracting litigation and to address any concerns our government sponsors may have related to this matter,” a PSU spokesperson told us, along with being sure we knew this alleged security failing never actually amounted to any real-world harm.
“There is no suggestion by our research sponsors that any of the non-classified information that has been the subject of this matter was ever compromised,” the spokesperson said. ®
… and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn’t helping
Hackers spent four days inside the org’s cloud platforms after apparently talking their way in
PARTNER CONTENT: Platform engineering won the argument. Now it has to grow up fast and evolve for the AI era.
Vendors are moving way beyond Nvidia’s GPUs in the datacenter
Bingeing the boxed set of binary bafflement
Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
ON-PREM
… and those are figures from the start of the AI boom. It can only be worse now. Silo-ed reporting isn’t helping
ai and ML
Your irresponsibility is someone else’s opportunity
SAAS
Show us the money
ai and ml
Fahrenheit 203, the temperature GPUs stop gorging on literature
DEVOPS
v 1.27 expands generics to support methods
Security
PLUS: US takes down Iranian propaganda sites; Marketing company asks ‘Why Do We Have Your Information?’ And more!
Security
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month
On the plus side, infosec’s a good bet for a long, stable career
Word up
New ‘Simple-taskbar’ is an option, but there’s a simpler, stabler way
New Debian versions hit FOSSland in the form of 13.6 and 12.15
Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
Joins yserver, Phoenix, and of course XLibre – and outlier Arcan
Next version of Linux Mint’s desktop has both kinds of display server

Biting the hand that feeds IT
Contact us
Advertise with us
Who we are
Newsletter
The Next Platform
DevClass
Blocks and Files
Situation Publishing
Cookies Policy
Privacy Policy
Ts & Cs
Do not share my personal information
Your Consent Options
Copyright. All rights reserved © 1998-2026.

source

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *