What the Public Record Establishes
The action is United States of America ex rel. Rachel Tenney v. Honeywell International Inc., filed March 25, 2022, in the Western District of North Carolina. The court's August 2026 order confirms that the United States intervened in part and unsealed three documents: the government's notice, the redacted complaint, and the order itself. Everything else on file remains sealed, including the original complaint. The paper is built on that deliberately limited record, and it is careful about what the record cannot support. Partial intervention is not adoption of every allegation, and the order does not explain the settlement amount, the scope of the release, or the reason particular records remain sealed.
The announced resolution. Honeywell Aerospace agreed to pay $2,042,518 covering April 2020 through December 2023, with $375,823 to former employee Rachel Tenney. DOJ expressly states there has been no determination of liability.
The names matter. The defendant named in the complaint is Honeywell International; the company DOJ identifies as settling is Honeywell Aerospace. A precise account preserves the distinction, and this paper does throughout.
The Gray Network
According to the complaint, the government work involved quantum computing contracts supported by a Special Use Network called the Gray Network, alleged to hold engineering drawings, technical specifications, simulations, and research associated with sensitive defense and intelligence programs. Tenney alleges the environment was separated from corporate systems while lacking protections that existed elsewhere in Honeywell, including monitoring by the corporate Security Operations Center. For any contractor using an enclave for Controlled Unclassified Information, the practical question the allegations raise is whether separation preserved accountability or merely moved the work beyond the people responsible for it.
The alleged deficiencies are recognizable operating disciplines rather than exotic failures: antivirus coverage that reached workstations but not servers, devices that could not be identified or administered, access that could not be attributed to an authorized person, and alerts that reached no one capable of acting on them. The paper connects each to the NIST SP 800-171 requirements involved while being explicit that the record contains no judicial finding that any particular control was violated.
The Decision to Close the Incident
SolarWinds gives the complaint its most detailed account. Tenney alleges compromised Orion software, unexplained remote sessions, configuration changes, and more than 1,200 megabytes moving to the compromised server, with administrators unable to account for the users or the activity. In a January 6, 2021 email reproduced in the complaint, she challenged the basis for treating the investigation as complete, describing unfinished analysis, missing logs, and software deployment no team member could explain.
Precision about the data movement. Movement to a compromised server inside the environment does not establish that the same volume of government information left the company, and the complaint itself acknowledges it remained unknown whether SolarWinds attackers acquired the government information. The record supports examining the adequacy of the investigation while leaving the extent of any compromise unresolved.
The management lesson. Closing a cyber incident is like closing a nonconformance: the closure statement can later be examined alongside the warnings that preceded it, and the decision needs a reason the record supports.
When Security Becomes a Payment Question
The complaint alleges that Honeywell continued invoicing while making false representations about network security and incidents. A deficiency alone does not establish False Claims Act liability; knowledge and materiality still have to be established. The paper works through those elements, the DFARS 252.204-7012 reporting obligation with its 72-hour trigger that does not wait for proven theft, and the CUI identification questions, including why the complaint's shorthand equating legacy FOUO markings with CUI is too broad to adopt as a compliance rule.
Notably, the case was not built on a failed CMMC assessment or an inaccurate SPRS score. Its account runs through the underlying work, the required security, incident handling, and payment. An assessment calendar and a contractual obligation operate on different terms, and a change to the former does not by itself amend the latter.
Before the Record Is Reconstructed
The settlement cannot responsibly be used to calculate the price of ignoring cybersecurity requirements, because the public record does not establish Honeywell's total cost or the damages rationale. Its more useful lesson concerns the evidence a company creates while performing the work: the device inventory, the access record, the alert, the email requesting investigation, the explanation for closure, and the representation associated with payment. A contractor can examine those records now, while corrective action remains an ordinary management task, rather than after an outside party begins reconstructing its decisions from emails, invoices, and incident logs.
Download the Full White Paper
The full paper covers the procedural record and what the unsealing order does and does not establish, the Gray Network allegations paragraph by paragraph, the malicious code, access control, and incident response allegations mapped to the NIST SP 800-171 requirements involved, the SolarWinds investigation and the reproduced correspondence challenging its closure, the False Claims Act knowledge and materiality elements, DFARS 252.204-7012 reporting mechanics, the CUI and legacy FOUO distinction, the retaliation allegations and the escalation process they implicate, and the management questions contractors can ask before litigation asks them. Claims are supported by citations to the redacted complaint, the unsealing order, the DOJ announcement, 31 U.S.C. 3729, DFARS 252.204-7012, NIST SP 800-171 Revision 2, and NARA CUI guidance.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →