Honeywell Paid $2 Million to Make a Quantum Problem Go Quiet
On December 14, 2020, one day after the SolarWinds breach became public knowledge, monitoring software on a Honeywell network started firing alerts. Between 9:30 in the morning and midnight Central Time, it logged:
- An Orion-initiated connection modifying the configuration of an employee device
- More than 1,200 megabytes of data moving from the network’s central server to a compromised Orion server
- Remote sessions continuing after the Orion server was powered off, some borrowing Orion’s IP address
- Unattributable users doing things nobody could explain, including a final session that ran until around midnight, when nobody was supposed to be working
A manager looked at the logs and concluded, “I don’t see anything concerning based on the available evidence.” The three-hour session with no owner? A “hung session.” The investigation was closed at the direction of the IT unit’s Chief Security Officer (CSO), and Honeywell skipped the remediation steps the Cybersecurity and Infrastructure Security Agency (CISA) had published for exactly this scenario.
That network wasn’t a corporate file share.
What the Government Bought, and What It Got
According to the unsealed redacted qui tam complaint in US ex rel. Tenney v. Honeywell International, the network in question was a Special Use Network, internally called the Gray Network, holding Controlled Unclassified Information (CUI) tied to US intelligence programs. It stored raw government data being processed on Honeywell’s quantum computers under a set of Department of Defense (DOD) contracts, first awarded May 17, 2016, worth tens of millions of dollars. The first contract’s Attachment B flagged two categories of protected material: external photographs of end-item hardware, and unclassified details about communications security (COMSEC) equipment design.
If you read the press coverage of the settlement, you learned that a “Phoenix-based aerospace business” paid $2,042,518 for a paperwork problem involving National Institute of Standards and Technology (NIST) SP 800-171 compliance between April 2020 and December 2023. That’s the entire public story, and it comes almost verbatim from the Department of Justice’s (DOJ) own announcement, which Hoodline and other outlets reprised nearly word for word. None of the coverage printed the word “quantum,” and none of it mentioned SolarWinds. The most interesting noun in the entire case got scrubbed out of the news cycle along with the rest of the sealed record.
The Five Failures
Rachel Tenney filed under the False Claims Act (FCA) on March 25, 2022, in the Western District of North Carolina, nearly eight months after being escorted out of the building. Her complaint, unsealed in redacted form in August 2026, alleges five categories of security failure on the Gray Network, and they compound:
- The firewall was the whole security program. The network wasn’t air gapped; devices could leave the building with employees, which defeats a firewall in the most literal sense possible. Segregating the Gray Network from Honeywell’s corporate network actually made things worse, because the corporate side had safeguards the Gray Network never got.
- No antivirus worth the name. Employees could buy off-the-shelf computers and plug them into a network holding intelligence-adjacent CUI. An IT specialist admitted the only antivirus was Windows Defender, deployed to workstations and never to servers. After SolarWinds, management tried to inventory the machines and couldn’t.
- No access control. Employees working purely on commercial projects roamed the network. Remote access was described internally as “anything goes,” traffic wasn’t encrypted, tunneling protocols went unvetted, and sessions never timed out.
- Theoretical incident response. No tests, no exercises, no playbook, nothing.
- Alerts routed to nowhere. Darktrace and Palo Alto gear generated warnings that no trained personnel were assigned to triage, and Honeywell’s Security Operations Center (SOC) had no visibility into the Gray Network at all.
Each failure violates specific controls in NIST SP 800-171, which the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 makes a condition of getting paid, with a past-due compliance deadline of December 31, 2017. The redacted complaint alleges Honeywell collected invoices while representing otherwise, which is how a security lapse becomes a fraud case with treble-damage exposure.
The Double Standard Is the Story
Here’s the part that should bother anyone who sells to the government. During the same period, Honeywell ran CrowdStrike Falcon and Microsoft Defender on its commercial customers’ environments. It maintained a functioning SOC for the corporate network, and it offered encryption and session timeouts to commercial clients.
The intelligence community’s quantum data got Windows Defender on half the machines, monitored by nobody.
The redacted complaint’s theory of motive reads like an indictment of priorities: Honeywell was racing to grow its commercial quantum business and starved the government side to feed it. That commercial effort became Quantinuum, launched in Q4 2021 as a majority-owned subsidiary when Honeywell Quantum Solutions merged with Cambridge Quantum Computing, per Honeywell’s own earnings release. Honeywell later reduced its stake far enough that its Q2 2026 filing reported earnings per share (EPS) of $17.83 reflecting “a one-time gain on deconsolidation of Quantinuum.” The business that allegedly ran on Defender delivered its parent a windfall. The complaint names Honeywell International Inc. as the defendant; the settlement was paid by Honeywell Aerospace Inc., which didn’t exist as a standalone company until the June 29, 2026 spinoff, years after the conduct ended.
The Messenger Got Punished
Tenney did what Deputy Attorney General Lisa Monaco asked the workforce to do when she announced the Civil Cyber-Fraud Initiative on October 6, 2021: “If you see something, say something.” Tenney said something nine months before Monaco said that. Her January 6, 2021 email cited a Darktrace alert “resembling Teardrop and Beacon,” the former being the custom dropper the SolarWinds attackers used to deliver follow-on payloads, plus missing logs and an agent deployment no team member could account for.
What followed, per the redacted complaint:
| Date | Event |
|---|---|
| Dec 2020 – Jan 2021 | Tenney repeatedly pushes for a real SolarWinds investigation |
| Jan 6, 2021 | Emails CSO objecting to incomplete analysis; cites Teardrop/Beacon alert |
| Jan 8, 2021 | Pulled off SolarWinds work; told not to “debate” compliance concerns |
| Jan 12, 2021 | Scheduled Insider Threat Executive Council meeting canceled |
| Jan 13, 2021 | CSO calls her adversarial and insubordinate; threatens her job |
| Summer 2021 | Two hostile investigations opened in succession; supervisory duties removed; desk relocated across from HR |
| Aug 5, 2021 | Escorted out in front of coworkers, eleven days before her new job started |
Her retaliation claims rode along with the fraud counts; her $375,823 relator share works out to 18.4 percent of the settlement, consistent with DOJ intervening in part and declining the rest.
Show Me the Risk Math
“Cyber risk” is a phrase that needs retiring. There are business risks that sometimes involve computers, and companies price them like any other. So let’s price this one.
What the Alleged Conduct Period Was Worth
Over the exact window of alleged conduct, 2020 through 2023, Honeywell International’s results, per its Q4 2021 earnings tables, its 2020 10-K, Value.today, and MacroTrends:
| Fiscal Year | Revenue | Net Income |
|---|---|---|
| 2020 | $32.64B | $4.78B |
| 2021 | $34.39B | $5.54B |
| 2022 | $35.47B | $4.97B |
| 2023 | $33.01B | $5.66B |
| Cumulative | ~$135.5B | ~$20.9B |
The settlement equals about 0.01 percent of cumulative net income. Honeywell earned the entire settlement amount back in net income roughly every four hours, four years running. And the customer comparison is sharper still: the same 10-K reports DOD sales of $3,661 million and total US government sales of $4,218 million in 2020 alone. The buyer of these allegedly compromised services spends annually roughly 2,000 times what the seller ever paid for compromising them.
What Compliance Would Have Cost
Now flip it around. The settlement averages to about $580,000 a year over the alleged period, so consider what actual security would have run:
- A per-endpoint endpoint protection platform (EPP) license from CrowdStrike runs in the tens of dollars per machine annually; even a few hundred Gray Network machines would land well under six figures a year
- One competent SOC analyst, the person missing from the monitoring stack, would have cost Honeywell less than the entire settlement over the same period, before counting a dollar of licensing
- Encryption, session timeouts, and access controls are configuration work on infrastructure Honeywell already ran elsewhere
In other words, properly securing the Gray Network plausibly cost less over the whole period than the eventual settlement. The cheapest option was compliance, and nobody bought it, which means the failure wasn’t a rational gamble on saving money. It only makes sense if you price the downside at zero, which, to be fair, might not have been crazy at the time. When the alleged conduct started, no court had held that cybersecurity non-compliance could sustain a False Claims Act case, and the DOJ’s Civil Cyber-Fraud Initiative that changed that was still years away. The rational move, on paper, was to assume nobody would ever send the invoice.
The redacted complaint alleges something harsher than bad math: that the starvation was deliberate, with resources actively diverted to commercial work. But a settlement resolves allegations only, no liability finding, and the terms defining what DOJ actually intervened in sit inside a sealed agreement. We can’t know whether this was intentional neglect or institutional drift, and the public record was built to make sure we can’t.
The Discount Is the Message
Federal cyber-related FCA recoveries topped $52 million across nine settlements in fiscal 2025, part of a record $6.8 billion in total FCA recoveries that year, and the Raytheon, RTX, and Nightwing settlement in May 2025 was $8.4 million across 29 Pentagon contracts. Honeywell’s $2.04 million for years of alleged non-compliance on quantum work for intelligence programs is the cheapest number on that board. Pentagon sales alone were $3.66 billion in 2020, so the settlement equals about 0.05 percent of a single year of DOD billing. Contractors read discounts, and this one reads like an invitation.
The Question Nobody Answered

Paragraph 201 of the complaint contains the sentence that outlives the settlement. Because Honeywell never investigated and never disclosed, it states, “it is unknown whether the SolarWinds Attackers are privy to the Government’s secrets on the Gray Network.” DNS logs showed traffic to the attackers’ command-and-control domain in June and July 2020, months before the breach was public. The 72-hour DFARS reporting clock ran, and nobody called.
Four years, one settlement, zero answers about whether nation-state attackers read the government’s quantum research. The government collected $2 million, a company earning that back every four hours resealed the file, and the security improvements that might have cost less than the fine were never bought. Executives reading this should understand exactly what got priced: the secrets stayed secret, the customer stayed quiet, and the discount held.