Carl B. Johnson
Author

Carl B. Johnson

vCISO and compliance expert.

https://carlbjohnson.com

posts

Cybersecurity Culture

Cybersecurity Culture in the Workplace: A Practical Guide

A Single Employee Click Cost MGM Resorts $100 Million In September 2023, MGM Resorts International disclosed a devastating cyberattack that disrupted hotel operations, slot machines, and reservation systems across Las Vegas. The attack vector? A social engineering phone call. A threat actor impersonated an employee, called the IT help desk,

Carl B. Johnson Sep 16, 2023 8 min read
Cybersecurity Culture

Building a Cybersecurity Culture That Actually Works

In January 2023, T-Mobile disclosed that a threat actor had stolen data on roughly 37 million customer accounts by exploiting a single API vulnerability. But here's what most people missed in the headlines — the breach went undetected for over a month. That's not just a technology

Carl B. Johnson Sep 16, 2023 7 min read
Security Awareness Metrics

Security Awareness Metrics That Prove ROI in 2023

When MGM Resorts got hit with a devastating social engineering attack in September 2023, it wasn't a firewall failure. It wasn't a zero-day exploit. A threat actor called the help desk, impersonated an employee, and walked right through the front door. The estimated cost? Over $100

Carl B. Johnson Sep 16, 2023 7 min read
Security Awareness Training

How to Measure Security Awareness Training Effectively

In 2022, Medibank — one of Australia's largest health insurers — suffered a breach that exposed 9.7 million customer records. The root cause? Compromised credentials. A single employee's stolen login led to one of the most damaging data breaches in Australian history. Medibank had security awareness training

Carl B. Johnson Sep 16, 2023 7 min read
Cybersecurity Training ROI

Cybersecurity Training ROI: The Numbers That Matter

A $2.6 Million Invoice Nobody Budgeted For In March 2023, the city of Oakland, California declared a state of emergency after a ransomware attack crippled city services for weeks. Systems went offline. Sensitive employee data leaked onto the dark web. The estimated recovery cost? Millions. And the initial entry

Carl B. Johnson Jun 09, 2023 7 min read
Cyber Hygiene

Cyber Hygiene Definition: What It Really Means in 2023

In March 2023, the FBI's Internet Crime Complaint Center reported that Americans lost over $10.3 billion to cybercrime in 2022 — a 49% jump from 2021. The vast majority of those losses traced back to failures in basic security practices. Not zero-day exploits. Not nation-state attacks. Basic, preventable

Carl B. Johnson Jun 08, 2023 7 min read
Cyber Hygiene

What Is Cyber Hygiene? The Daily Habits That Stop Breaches

In March 2023, the FBI's Internet Crime Complaint Center reported that Americans lost over $10.3 billion to cybercrime in 2022 — a 49% increase from 2021. The majority of those losses didn't come from sophisticated nation-state attacks. They came from poor habits: reused passwords, unpatched software,

Carl B. Johnson Jun 08, 2023 7 min read
Cyber Hygiene Checklist

Cyber Hygiene Checklist: 12 Steps That Actually Work

In March 2023, the FBI's Internet Crime Complaint Center reported that Americans lost over $10.3 billion to cybercrime in 2022 — a 49% increase from the year before. The uncomfortable truth? Most of those losses trace back to failures in basic security practices, not sophisticated zero-day exploits. A

Carl B. Johnson Jun 08, 2023 7 min read
Cybersecurity for Executives

Cybersecurity for Executives: What Boards Must Know Now

The SolarWinds Wake-Up Call That Still Echoes in Every Boardroom When SolarWinds disclosed its massive supply chain compromise in late 2020, it wasn't just IT teams scrambling — it was CEOs fielding calls from senators, board members demanding answers they didn't have, and general counsel mapping out

Carl B. Johnson Jun 08, 2023 7 min read