Tag

Cybersecurity Awareness Training

Provides guidance on designing, implementing, and optimizing security awareness programs for organizations. Articles cover curriculum development, interactive training methods, compliance requirements, engagement metrics, and techniques to transform employees into an active line of defense against cyber threats.

posts

Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
Cost of a Data Breach 2026

Cost of a Data Breach 2026: What the Numbers Mean

The Bill Nobody Plans For IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88 million — a 10% jump from the prior year and the highest figure ever recorded. That number has only continued climbing. When I talk to business owners about the

Carl B. Johnson Aug 16, 2026 5 min read
Securing Remote Employees

Securing Remote Employees: What Actually Works in 2026

The Coffee Shop Breach That Cost $6.5 Million In 2024, a mid-size financial services firm discovered that a single remote employee working from a hotel lobby had their session token hijacked through a man-in-the-middle attack on the hotel's Wi-Fi. The threat actor used that access to move

Carl B. Johnson Jul 27, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to stealing over $120 million from Google and Facebook using a sophisticated man in the middle attack scheme. He impersonated a legitimate hardware vendor, intercepted invoice communications, and redirected payments to bank accounts he controlled. The scheme ran for two

Carl B. Johnson Jun 02, 2026 5 min read
DNS Spoofing

DNS Spoofing Attack: How Hackers Redirect Your Traffic

In April 2024, researchers at Akamai discovered a massive DNS hijacking campaign targeting financial institutions across Southeast Asia. Attackers poisoned DNS caches at the ISP level, silently redirecting thousands of banking customers to pixel-perfect phishing sites. Victims entered their credentials on pages that looked identical to their bank's

Carl B. Johnson May 14, 2026 5 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does Inside Your Network

The Invoice That Took Down a Hospital Network In 2023, a hospital system in Illinois watched helplessly as Qakbot — a trojan horse malware strain — moved laterally through its entire Active Directory environment in under four hours. The initial infection? A single employee opened what looked like an overdue vendor invoice

Carl B. Johnson May 09, 2026 5 min read