Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Cybersecurity for Financial Services

Cybersecurity for Financial Services: A 2026 Playbook

The Industry That Can't Afford a Single Mistake In November 2023, the SEC fined several financial advisory firms a combined total of nearly $750,000 for cybersecurity failures following credential theft incidents that exposed thousands of customer records. The firms had the basics — firewalls, antivirus — but lacked the

Carl B. Johnson Mar 29, 2026 5 min read
Password Manager Benefits

Password Manager Benefits That Stop 80% of Breaches

One Reused Password Cost This Company $4.6 Billion In 2017, a single set of reused credentials let threat actors walk into Equifax's systems and expose 147 million records. The total cost exceeded $4.6 billion when you factor in the FTC settlement, lawsuits, and remediation. One password.

Carl B. Johnson Mar 29, 2026 5 min read
NIST Cybersecurity Framework

NIST Cybersecurity Framework: A Practical Guide for 2026

The Framework 83% of Organizations Claim to Follow — But Few Actually Implement When the City of Dallas was hit by a devastating ransomware attack in May 2023, investigations revealed systemic gaps in risk management, incident response, and access controls — the exact areas the NIST Cybersecurity Framework was designed to address.

Carl B. Johnson Mar 28, 2026 6 min read
Cybersecurity Awareness Quiz

Cybersecurity Awareness Quiz: Test Your Team Now

93% of Breaches Start With a Person, Not a Firewall In 2023, Verizon's Data Breach Investigations Report confirmed what security professionals have been screaming about for years: the human element was involved in 74% of all breaches. By 2024, that figure remained stubbornly high. A cybersecurity awareness quiz

Carl B. Johnson Mar 28, 2026 5 min read
Cybersecurity Terms Explained

Cybersecurity Terms Explained: A No-Nonsense Guide

During a breach investigation last year, I watched a CFO stare blankly at an incident response report and ask, "What's lateral movement? What does 'exfiltration' mean? Can someone just speak English?" That moment crystallized something I've known for two decades: the cybersecurity

Carl B. Johnson Mar 28, 2026 6 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The FBI Warned You About Medusa. Did You Listen? In March 2025, the FBI and CISA issued a joint advisory — #StopRansomware: Medusa Ransomware — warning that the Medusa ransomware gang had already hit over 300 organizations across critical infrastructure sectors. Healthcare, education, manufacturing, technology. The common thread? Nearly every intrusion started

Carl B. Johnson Jan 26, 2026 7 min read