Tag

Cybersecurity Training

Covers cybersecurity training programs, techniques, and best practices designed to equip employees and individuals with the skills to recognize and respond to cyber threats. Topics include security awareness curricula, simulation exercises, and measuring training effectiveness.

posts

Fake Email

Fake Email: How to Spot One Before It Costs You

In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook — using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from spoofed email addresses, and two of the most sophisticated tech companies on

Carl B. Johnson Aug 19, 2026 6 min read
Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, a small accounting firm in Ohio discovered that a browser toolbar one employee installed — what looked like a harmless coupon finder — had been silently logging keystrokes and exfiltrating client tax records for eleven months. The toolbar was adware on the surface. Underneath, it was spyware. And the firm

Carl B. Johnson Aug 13, 2026 6 min read
Data Breach Notification

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of roughly 100 million Americans. The fallout wasn't just technical — it was a regulatory nightmare. State attorneys general demanded answers. Congressional hearings followed. And organizations downstream from the breach scrambled to figure out

Carl B. Johnson Aug 12, 2026 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Criminals Fake Their Way In

In 2023, the FBI's Internet Crime Complaint Center reported over 43,000 victims of spoofing-related fraud, with losses exceeding $300 million. That number has only climbed since. And here's the part that should keep you up at night: a spoofing caller doesn't need malware,

Carl B. Johnson Aug 07, 2026 6 min read
Keylogger Attack

Keylogger Attack: How Hackers Steal Every Keystroke

In 2023, the FBI's IC3 received over 21,000 complaints related to malware infections that led directly to credential theft — and a significant number of those involved keyloggers silently recording every password, credit card number, and private message typed on a compromised machine. A keylogger attack doesn'

Carl B. Johnson Aug 04, 2026 5 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into wiring $25 million after a video call with what appeared to be the company's CFO — deepfake technology made the voice and face indistinguishable from the real

Carl B. Johnson Aug 04, 2026 6 min read
Types of Malware

Types of Malware: What Every Organization Must Know

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase from the previous year. A staggering number of those incidents involved some form of malicious software. Understanding the types of malware your organization faces isn&

Carl B. Johnson Aug 04, 2026 5 min read
Email Phishing Red Flags

Email Phishing Red Flags: 9 Signs You're Being Targeted

The Email That Cost One Company $37 Million In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked

Carl B. Johnson Jul 31, 2026 5 min read