Computer Security US Blog

Computer Security News and Insights

Data Breach Response Plan

Data Breach Response Plan: What Actually Works

When SolarWinds disclosed in December 2020 that threat actors had compromised their Orion software update mechanism — infiltrating roughly 18,000 customer networks including multiple U.S. government agencies — the breach didn't just expose data. It exposed how many organizations had no real data breach response plan in place.

Carl B. Johnson Jan 14, 2021 8 min read
Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

The Clock Starts Ticking the Moment You Discover a Breach In December 2020, FireEye disclosed it had been breached by a sophisticated threat actor — a revelation that quickly unraveled into the massive SolarWinds supply chain compromise affecting 18,000 organizations including multiple U.S. government agencies. The question every security

Carl B. Johnson Jan 14, 2021 7 min read
Cost of a Data Breach

Cost of a Data Breach: What 2021 Trends Tell Us

The Cost of a Data Breach Is Already Staggering — And the Trajectory Is Alarming In 2020, the average cost of a data breach hit $3.86 million globally, according to IBM and the Ponemon Institute's annual Cost of a Data Breach Report. That number has been climbing steadily

Carl B. Johnson Jan 14, 2021 6 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2021 Guide

The SolarWinds Breach Just Made Notification a National Crisis In December 2020, FireEye disclosed that a sophisticated threat actor had compromised SolarWinds Orion software, giving attackers access to roughly 18,000 organizations — including the U.S. Treasury, the Department of Homeland Security, and Fortune 500 companies. Weeks later, we'

Carl B. Johnson Jan 14, 2021 8 min read
Password Security

Password Security Best Practices That Actually Work

The Breach That Started With a Single Reused Password In December 2020, the SolarWinds breach dominated every security headline on the planet. But while the world fixated on nation-state threat actors and supply chain attacks, I kept thinking about a detail that emerged early: a SolarWinds intern had reportedly set

Carl B. Johnson Jan 14, 2021 7 min read
Strong Passwords

How to Create a Strong Password: A Practical Guide

In the 2020 Verizon Data Breach Investigations Report, over 80% of hacking-related breaches involved stolen or brute-forced credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. The single thing most people treat as an afterthought is the single thing that gets most organizations compromised. Knowing how to create a strong

Carl B. Johnson Jan 14, 2021 7 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Won't Work Without One

The Breach That Started With a Sticky Note In 2020, a senior employee at a Florida water treatment facility reportedly reused passwords across multiple systems — including the one controlling sodium hydroxide levels in the public water supply. That incident, disclosed in early February 2021, showed exactly how a single weak

Carl B. Johnson Jan 14, 2021 6 min read
Multi-Factor Authentication

MFA vs Two-Factor Authentication: What Actually Matters

In July 2020, a teenager orchestrated one of the most high-profile breaches in social media history — the Twitter hack that compromised accounts belonging to Barack Obama, Elon Musk, and Apple. The attack vector? Social engineering and credential theft that bypassed weak authentication controls. It was a brutal reminder that passwords

Carl B. Johnson Jan 11, 2021 6 min read