Verizon Business Network Services LLC agreed to pay $4,091,317 to resolve False Claims Act allegations that its Managed Trusted Internet Protocol Service did not fully satisfy required cybersecurity controls on General Services Administration contracts from 2017 to 2021 — and the Justice Department publicly credited the company for self-disclosing, cooperating, and remediating. The settlement is a useful corrective to a common assumption: that cyber-fraud enforcement under the False Claims Act is a Department of Defense and CMMC story. It is not. Any contractor selling to the federal government against cybersecurity requirements can be a target.
What Happened
Verizon's Managed Trusted Internet Protocol Service (MTIPS) is designed to give federal agencies secure connections to the public internet and other external networks. It is sold through GSA vehicles and used across the civilian side of government.
The government alleged that, between 2017 and 2021, Verizon's MTIPS solution did not completely satisfy three required cybersecurity controls for Trusted Internet Connections (TIC) in connection with its GSA contracts. Trusted Internet Connections is a federal program — governed by OMB and CISA guidance — that standardizes how agencies route and secure their external network traffic. It is a different regime from the DFARS 252.204-7012 / NIST SP 800-171 framework that governs defense contractors handling Controlled Unclassified Information.
After Verizon identified the problems, it did the things the Justice Department has repeatedly said it wants to see: it gave the government a written self-disclosure, launched an independent investigation and compliance review, provided multiple detailed supplemental disclosures, cooperated with the investigation, and took prompt remedial measures. In announcing the settlement, DOJ expressly acknowledged that Verizon earned credit for cooperating.
(A settlement is not an admission of liability.)
The Civilian-Agency Angle Contractors Miss
The recurring lesson of the Civil Cyber-Fraud Initiative — launched October 6, 2021 — is often framed narrowly around defense: false SPRS self-assessment scores, unimplemented NIST 800-171 controls, DFARS 7012 flowdowns. The named cases that draw the most attention (Raytheon, Georgia Tech, MORSE, LOGZONE) all sit in that defense lane.
Verizon is the reminder that the theory is broader than the defense context. The Initiative reaches any knowing failure to meet cybersecurity obligations that a contractor represented it would satisfy when it took federal money. The obligation here came from a GSA contract and a civilian security program (TIC), not from a DoD clause. The payment mechanism — the False Claims Act — is the same, and so is the treble-damages exposure that makes these cases financially serious.
For contractors on GSA Schedules, civilian agency IDIQs, or governmentwide acquisition contracts, the practical takeaway is direct: your cybersecurity representations to civilian agencies carry the same FCA weight as a defense contractor's SPRS score. If your contract incorporates a security standard — TIC, FedRAMP, agency-specific control baselines, or the FAR 52.204-21 basic safeguards — and you certify or invoice as though you meet it while you do not, you have the same exposure Verizon did.
Why the Cooperation Credit Matters
The government's public acknowledgment that Verizon received cooperation credit is not incidental — it is guidance. DOJ has built a consistent message across its cyber-fraud settlements: contractors who discover a gap, disclose it in writing, investigate it independently, and remediate promptly will see that conduct reflected in the resolution.
That framework does not erase liability. Verizon still paid more than $4 million. But it changes the trajectory of a case. The alternative path — waiting for a whistleblower's qui tam complaint or a government audit to surface the problem — forecloses the credit and typically produces a worse outcome. The Aero Turbine self-disclosure settlement makes the same point on the defense side; Verizon makes it on the civilian side. Two different agencies, one consistent message.
What This Means for Contractors
1. Map every cybersecurity representation in your civilian contracts, not just your defense ones. TIC, FedRAMP authorization, agency control baselines, and FAR 52.204-21 all create obligations you are certifying against. Use Find My Requirements to identify which standards actually attach to your work.
2. Managed services are compliance surfaces, too. Verizon's exposure came from a service it operated on the government's behalf — not from data sitting on its own network. If you provide a managed or cloud service to agencies, the controls you promised are part of what you are being paid for, and a shortfall is a potential false claim.
3. Build a self-disclosure playbook before you need it. The credit framework only helps contractors who can move quickly and credibly when they find a gap. Decide in advance how you will investigate, document, involve counsel, and disclose. The enforcement page collects the pattern of cases that reward this discipline.
4. Treat cybersecurity compliance as a whole-of-portfolio issue. Defense work draws the headlines, but civilian contracts carry identical FCA risk. A Compliance Roadmap Assessment™ should cover every contract vehicle you hold, not just your DoD footprint.
Key Takeaways
- Verizon Business Network Services paid $4,091,317 to resolve FCA allegations that its MTIPS service failed to fully satisfy three Trusted Internet Connection cybersecurity controls on GSA contracts from 2017 to 2021 — with DOJ publicly crediting the company's written self-disclosure, cooperation, and remediation.
- Cyber-fraud enforcement is not limited to defense contractors or CMMC/NIST 800-171: the Civil Cyber-Fraud Initiative reaches any knowing failure to meet cybersecurity obligations a contractor represented it would satisfy, including civilian-agency and GSA-vehicle work.
- Prompt, documented self-disclosure is a recognized mitigating factor across both defense and civilian cyber-fraud cases; contractors who build a disclosure playbook before a gap surfaces materially improve their position over waiting for a whistleblower or audit.