Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Securing Cloud Applications

Securing Cloud Applications: A Practical Field Guide

The $65 Million Misconfiguration Nobody Saw Coming In March 2023, Toyota disclosed that a cloud misconfiguration had exposed vehicle data on 2.15 million customers for over a decade. A single cloud storage bucket, left publicly accessible, quietly leaked data from 2012 to 2023. Nobody noticed for ten years. That&

Carl B. Johnson Nov 03, 2023 7 min read
Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

The App Your Marketing Team Installed Last Tuesday Could Cost You Millions In 2022, a mid-size healthcare company discovered that an employee had been syncing patient records to a personal Dropbox account for three years. No malicious intent — they just wanted to work from home more easily. The resulting HIPAA

Carl B. Johnson Nov 03, 2023 7 min read
Shadow IT

What Is Shadow IT? The Hidden Risk Draining Your Security

The Salesforce Instance Nobody Knew About In 2022, a mid-size healthcare company discovered that one of its marketing teams had been running an entirely separate Salesforce instance — for eleven months. Patient-adjacent data sat in an environment with no encryption at rest, no access controls, and no logging. The IT security

Carl B. Johnson Nov 03, 2023 7 min read
SaaS Security

SaaS Security Best Practices: A Hands-On Guide

The Breach That Started With a Single SaaS Login In January 2023, Mailchimp disclosed its second major breach in less than a year. The cause? A threat actor used social engineering to trick an employee into handing over credentials to an internal tool. That single compromised SaaS login exposed 133

Carl B. Johnson Sep 29, 2023 7 min read
Mobile Device Security Policy

Mobile Device Security Policy: What Most Companies Get Wrong

In March 2023, Samsung employees accidentally leaked sensitive source code and internal meeting notes by pasting proprietary data into ChatGPT — on their mobile devices. No malware was involved. No sophisticated threat actor broke through a firewall. Employees simply used their phones in ways the company's mobile device security

Carl B. Johnson Sep 18, 2023 7 min read
BYOD Security Risks

BYOD Security Risks: What Your Policy Is Missing

In January 2023, T-Mobile disclosed that a threat actor had stolen data on 37 million customer accounts — and the intrusion reportedly exploited an API accessible from systems that included employee-used devices. It wasn't a sophisticated zero-day. It was a gap in how endpoints and access were managed. If

Carl B. Johnson Sep 18, 2023 7 min read
USB Drive Security Risks

USB Drive Security Risks: The Threat Already on Your Desk

In January 2022, the FBI issued a public warning that the cybercriminal group FIN7 had been mailing malicious USB drives to U.S. companies — disguised as packages from Amazon and the U.S. Department of Health and Human Services. The drives, once plugged in, deployed ransomware onto corporate networks. This

Carl B. Johnson Sep 18, 2023 7 min read
Tailgating Attack

Tailgating Attack Cybersecurity: Stop the Walk-In Threat

In 2019, a man wearing a reflective vest and carrying a clipboard walked into a secure data center in Atlanta, unplugged a server, tucked it under his arm, and walked right back out the front door. Nobody stopped him. Nobody questioned him. A $2.5 million client database left the

Carl B. Johnson Sep 18, 2023 7 min read