Lawsuit hits Georgia Tech affiliate for whistleblower cybersecurity concerns

August 23, 2024
1 min read

TLDR:

Georgia Tech and its affiliate GTRC are facing a federal whistleblower lawsuit for failing to meet cybersecurity requirements in connection with U.S. Department of Defense contracts. The lawsuit alleges a pattern of non-compliance dating back to 2019, with researchers pushing back against compliance measures. The Astrolavos Lab at Georgia Tech is a focal point of the lawsuit, accused of failing to develop and implement required security plans and neglecting antivirus and anti-malware tools. The lawsuit also claims that a fraudulent cybersecurity assessment score was submitted to the DoD. The whistleblower suit was filed by former members of Georgia Tech’s cybersecurity team, and the Department of Justice has intervened in the case.

Georgia Tech issued a statement denying the allegations and expressing commitment to cybersecurity. This case is the first under the Department of Justice’s Civil Cyber-Fraud Initiative and highlights the importance of contractor compliance with cybersecurity regulations.

The lawsuit is titled United States ex rel. Craig v. Georgia Tech Research Corp and is being handled by the Justice Department’s Civil Division and the U.S. Attorney’s Office for the Northern District of Georgia.

Latest from Blog

EU push for unified incident report rules

TLDR: The Federation of European Risk Management Associations (FERMA) is urging the EU to harmonize cyber incident reporting requirements ahead of new legislation. Upcoming legislation such as the NIS2 Directive, DORA, and