Tag

Cybersecurity Culture

Articles on building and sustaining a cybersecurity culture where secure behavior becomes second nature across every level of an organization. Topics include leadership engagement, employee mindset shifts, and integrating security values into daily operations.

posts

Cybersecurity Gamification Training

Cybersecurity Gamification Training That Actually Works

In 2019, PricewaterhouseCoopers launched a gamified cybersecurity exercise called Game of Threats — a real-time digital board game that pitted executives against simulated threat actors. The result? Decision-makers who'd never engaged with security training before were suddenly competing to outmaneuver ransomware campaigns and credential theft attacks. Engagement didn'

Carl B. Johnson Sep 15, 2026 5 min read
Cybersecurity Culture

Cybersecurity Culture in the Workplace: Build It or Pay

One Click Cost MGM Resorts Over $100 Million In September 2023, a social engineering attack against MGM Resorts International shut down slot machines, hotel key cards, and reservation systems across Las Vegas. The threat actors didn't exploit a zero-day vulnerability. They called the help desk, impersonated an employee,

Carl B. Johnson Jul 20, 2026 6 min read
Phishing Awareness Program

Phishing Awareness Program: Build One That Works

The Click That Cost One Company $47 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a single social engineering phone call that led to credential theft. The resulting breach caused an estimated $100 million in damages. And it started with

Carl B. Johnson Jul 01, 2026 5 min read
Cybersecurity Awareness Month

Cybersecurity Awareness Month: What Actually Works

October Comes and Goes — Breaches Don't Every October, organizations dust off the same tired PowerPoint decks, send a few reminder emails about password hygiene, and pat themselves on the back for "participating" in Cybersecurity Awareness Month. Then November arrives, an employee clicks a credential-harvesting link, and

Carl B. Johnson May 07, 2026 5 min read
Cybersecurity Culture

Building a Cybersecurity Culture That Actually Works

A Poster on the Breakroom Wall Never Stopped a Breach In 2023, MGM Resorts lost an estimated $100 million after a threat actor called the help desk, impersonated an employee found on LinkedIn, and talked their way into the network. No zero-day exploit. No nation-state malware. Just a phone call.

Carl B. Johnson Apr 30, 2026 5 min read
Employee Cybersecurity Training

Employee Cybersecurity Training: What Actually Works

In May 2024, a single employee at a major healthcare provider clicked a phishing link disguised as a routine benefits update. Within 72 hours, the organization lost access to 14 million patient records and ended up paying a multimillion-dollar ransom. The employee had technically "passed" their annual compliance

Carl B. Johnson Aug 17, 2025 8 min read
Cybersecurity Culture

Cybersecurity Culture in the Workplace: A Practical Guide

The Breach That Started With a Single Slack Message In September 2022, a threat actor convinced a Uber contractor to approve a multi-factor authentication push notification. That single moment of human failure gave the attacker access to Uber's internal systems, including their Slack workspace, vulnerability reports, and financial

Carl B. Johnson Mar 29, 2025 8 min read
Cybersecurity Culture

Building a Cybersecurity Culture That Actually Works

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past the help desk with a single phone call. The attacker didn't exploit a zero-day vulnerability. They didn't write custom malware. They called an employee, pretended to

Carl B. Johnson Mar 29, 2025 7 min read
Employee Cybersecurity Training

Employee Cybersecurity Training: What Actually Works

In January 2024, a finance employee at a multinational firm in Hong Kong transferred $25 million to threat actors after a deepfake video call convinced him his CFO had authorized the payment. No malware. No zero-day exploit. Just a well-trained employee who wasn't trained well enough. That incident

Carl B. Johnson Mar 24, 2024 7 min read