Tag

Credential Theft Protection

Explore strategies and tools to defend against credential theft attacks, including password spraying, keylogging, and credential stuffing. This tag covers best practices for safeguarding login credentials, implementing multi-factor authentication, and detecting compromised accounts before attackers exploit them.

posts

Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, Clorox disclosed a cybersecurity incident that disrupted operations for months and cost the company an estimated $49 million in recovery expenses. The attack reportedly began with social engineering — a threat actor tricking someone into giving up access. That's not

Carl B. Johnson Sep 14, 2026 6 min read
Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, a finance employee at Clorox received what looked like a routine vendor email. One click later, threat actors had a foothold inside the network. The resulting cyberattack disrupted operations for months and cost the company an estimated $356 million in damages

Carl B. Johnson Aug 14, 2026 5 min read
Business Email Compromise

Business Email Compromise: The $2.9 Billion Threat

In 2023, the FBI's Internet Crime Complaint Center (IC3) reported that business email compromise caused $2.9 billion in adjusted losses — making it the single most financially devastating cybercrime category they track. Not ransomware. Not credential theft rings. BEC. And that number only reflects what gets reported. I&

Carl B. Johnson Jun 11, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeter Defense Is Dead

A Castle With No Walls Left to Defend In January 2024, Microsoft disclosed that the Russian threat actor Midnight Blizzard had compromised executive email accounts — not by breaching a firewall, but by password-spraying a legacy test tenant account that lacked multi-factor authentication. The attackers moved laterally for weeks before detection.

Carl B. Johnson May 15, 2026 5 min read
Phishing Prevention Tips

Phishing Prevention Tips That Actually Stop Attacks

In March 2024, a finance employee at a multinational firm wired $25 million to threat actors after a deepfake video call that impersonated the company's CFO. The attack started with a single phishing email. That one message opened the door to a loss most companies would never recover

Carl B. Johnson May 13, 2026 5 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In early 2024, threat actors exploited critical vulnerabilities in Ivanti Connect Secure VPN appliances so aggressively that CISA issued an emergency directive ordering federal agencies to disconnect the devices entirely. Not patch them. Disconnect them. That moment should have been a wake-up call: having a VPN isn't enough.

Carl B. Johnson Apr 12, 2026 5 min read
Cybersecurity for Financial Services

Cybersecurity for Financial Services: A 2026 Playbook

The Industry That Can't Afford a Single Mistake In November 2023, the SEC fined several financial advisory firms a combined total of nearly $750,000 for cybersecurity failures following credential theft incidents that exposed thousands of customer records. The firms had the basics — firewalls, antivirus — but lacked the

Carl B. Johnson Mar 29, 2026 5 min read
Security for System

Security for System Environments: A 2025 Field Guide

The Breach That Started With a Single Unpatched System In February 2024, UnitedHealth Group's subsidiary Change Healthcare suffered a ransomware attack that disrupted healthcare payment processing across the United States for weeks. The attackers gained access through a Citrix remote access portal that lacked multi-factor authentication. One system.

Carl B. Johnson Nov 06, 2025 7 min read