Tag

data breach prevention

Strategies, technologies, and policies for preventing data breaches before they occur. This tag covers access controls, encryption, endpoint protection, incident response planning, vulnerability management, and the human factors that contribute to data exposure in organizations of all sizes.

posts

computer security

Computer Security in 2026: What Actually Works

In 2023, MGM Resorts lost roughly $100 million after a social engineering phone call — a single conversation — gave threat actors the foothold they needed to deploy ransomware across the entire enterprise. That incident didn't start with a zero-day exploit or some nation-state weapon. It started with a help

Carl B. Johnson Aug 15, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number didn't drop in 2025. And from what I've seen in the first half of 2026, it's still

Carl B. Johnson Jul 14, 2026 6 min read
computer security

Computer Security in 2026: What Actually Works Now

In 2023, MGM Resorts lost roughly $100 million from a single social engineering phone call. A threat actor called the help desk, impersonated an employee found on LinkedIn, and within minutes had the credentials needed to deploy ransomware across the entire enterprise. That's not a firewall failure. That&

Carl B. Johnson Jun 29, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — making it the largest healthcare

Carl B. Johnson Apr 23, 2026 5 min read
computer security software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack bypassed every piece of computer security software they had deployed. The attackers didn't exploit a zero-day vulnerability. They didn't brute-force a firewall. They called the help desk, impersonated an employee, and walked right

Carl B. Johnson Apr 18, 2026 5 min read
phishing awareness training

Phishing Awareness Training: What Actually Works in 2026

A 3-Minute Email Cost One Company $37 Million In 2024, a finance employee at a multinational firm joined a deepfake video call with what appeared to be the company's CFO and several colleagues. Every person on that call was AI-generated. The employee transferred $25.6 million (approximately HK$

Carl B. Johnson Apr 15, 2026 5 min read
cybersecurity training

How to Train Employees on Cybersecurity in 2026

The Breach That Started With a Single Click In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past help desk staff with a ten-minute phone call. The attackers didn't exploit some exotic zero-day. They exploited a human being

Carl B. Johnson Mar 30, 2026 5 min read
phish

How One Phish Can Cost Your Company Millions

A Single Phish Email Took Down a $13 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish — shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The company paid a $4.4 million ransom within hours. That's the

Carl B. Johnson Jan 26, 2026 7 min read