Tag

Cybersecurity Awareness Training

Provides guidance on designing, implementing, and optimizing security awareness programs for organizations. Articles cover curriculum development, interactive training methods, compliance requirements, engagement metrics, and techniques to transform employees into an active line of defense against cyber threats.

posts

Computer Security Companies

Computer Security Companies: What They Won't Tell You

The Billion-Dollar Blind Spot in Cybersecurity Spending In 2024, global cybersecurity spending surpassed $215 billion. Organizations bought firewalls, endpoint detection, SIEM platforms, and managed services from every major vendor on the planet. And breaches still hit record numbers. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches

Carl B. Johnson Oct 02, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
Cost of a Data Breach 2026

Cost of a Data Breach 2026: What the Numbers Mean

The Bill Nobody Plans For IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88 million — a 10% jump from the prior year and the highest figure ever recorded. That number has only continued climbing. When I talk to business owners about the

Carl B. Johnson Aug 16, 2026 5 min read
Securing Remote Employees

Securing Remote Employees: What Actually Works in 2026

The Coffee Shop Breach That Cost $6.5 Million In 2024, a mid-size financial services firm discovered that a single remote employee working from a hotel lobby had their session token hijacked through a man-in-the-middle attack on the hotel's Wi-Fi. The threat actor used that access to move

Carl B. Johnson Jul 27, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In 2019, a Lithuanian national named Evaldas Rimasauskas pleaded guilty to stealing over $120 million from Google and Facebook using a sophisticated man in the middle attack scheme. He impersonated a legitimate hardware vendor, intercepted invoice communications, and redirected payments to bank accounts he controlled. The scheme ran for two

Carl B. Johnson Jun 02, 2026 5 min read