Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Home Computer Security

How Can You Protect Your Home Computer in 2024

In February 2024, the FBI's Internet Crime Complaint Center reported that Americans lost over $12.5 billion to cybercrime in 2023 — a 22% increase from the year before. A staggering number of those complaints originated from personal devices. Not corporate servers. Not government networks. Home computers. So how

Carl B. Johnson May 13, 2024 6 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

The Virus That Cost a Hospital Chain $100 Million In 2017, the NotPetya malware ripped through networks worldwide. It wasn't theoretical. Nuance Communications, a major healthcare IT vendor, took a $92 million hit. Maersk, the shipping giant, lost around $300 million. Heritage Valley Health System in Pennsylvania lost

Carl B. Johnson May 13, 2024 6 min read
Cyber Security Definition

Cyber Security Definition: What It Actually Means in 2024

In March 2024, a Change Healthcare breach exposed the protected health information of tens of millions of Americans and disrupted pharmacy operations nationwide. A single set of stolen credentials — no multi-factor authentication in place — gave a threat actor the keys to one of the largest healthcare payment processors in the

Carl B. Johnson May 13, 2024 6 min read
Computer Security Jobs Pay

Computer Security Jobs Pay: 2024 Salary Breakdown

A former teacher I mentored landed a security analyst role in 2023 at $92,000 — with no prior IT experience and one certification earned in eight months. That's not an outlier anymore. The cybersecurity talent shortage has pushed salaries to levels that make even seasoned software engineers reconsider

Carl B. Johnson May 13, 2024 6 min read
Computer Security Service

Computer Security Service: What Actually Works in 2024

The Breach That a $200K Security Stack Couldn't Stop In January 2024, a mid-sized accounting firm in the Midwest had firewalls, endpoint detection, SIEM logging, and a managed SOC. They spent over $200,000 a year on their computer security service stack. Then an employee clicked a phishing

Carl B. Johnson May 13, 2024 7 min read
Cybersecurity Definition

Cybersecurity Definition: What It Really Means in 2024

In March 2024, a ransomware attack on Change Healthcare — one of the largest health payment processors in the U.S. — disrupted claims processing for pharmacies and hospitals nationwide. Patients couldn't fill prescriptions. Providers couldn't get paid. A single breach paralyzed a massive chunk of American healthcare

Carl B. Johnson May 13, 2024 7 min read
Cloud Computing Security

Cloud Computing Security: 7 Mistakes That Cause Breaches

In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard had breached its corporate email systems — not through some exotic zero-day exploit, but through a password spray attack on a legacy test account that lacked multi-factor authentication. If Microsoft, a company that literally sells cloud

Carl B. Johnson May 13, 2024 7 min read
computer security advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached executive email accounts using a password spray attack against a legacy test account that lacked multi-factor authentication. Microsoft. One of the largest technology companies on Earth. Compromised

Carl B. Johnson May 13, 2024 7 min read
Define Cyber

Define Cyber: What Security Pros Actually Mean

The Word Everyone Uses But Few Can Explain In March 2024, the FBI's Internet Crime Complaint Center (IC3) released its 2023 annual report showing $12.5 billion in reported cybercrime losses — a 22% jump from the year before. Politicians, news anchors, and boardroom executives all toss around the

Carl B. Johnson May 04, 2024 6 min read
NIST Standards

NIST Standards: What Actually Matters for Your Security

In February 2024, NIST released version 2.0 of its Cybersecurity Framework — the biggest overhaul in a decade. Within weeks, I watched organizations scramble to figure out what changed and what they needed to do about it. Most of them were still struggling to implement version 1.1. Here'

Carl B. Johnson May 03, 2024 7 min read