Tag

Data Breach Prevention

Explores strategies and best practices for preventing data breaches in organizations of all sizes. Covers topics like access controls, encryption, network monitoring, incident response planning, and employee awareness to help reduce the risk of unauthorized data exposure.

posts

NIST Standards

NIST Standards: A Practical Guide for Real Security

In 2023, MGM Resorts lost roughly $100 million to a ransomware attack that started with a social engineering phone call. The attackers didn't exploit some exotic zero-day. They called a help desk, impersonated an employee, and got credentials reset. MGM had security tools. What they lacked was a

Carl B. Johnson Sep 19, 2026 5 min read
Phishing Prevention Tips

Phishing Prevention Tips That Actually Stop Attacks

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Yet most of the phishing prevention tips circulating online read like they were written in 2009. "Don't click suspicious

Carl B. Johnson Sep 16, 2026 5 min read
Cybersecurity Gamification Training

Cybersecurity Gamification Training That Actually Works

In 2019, PricewaterhouseCoopers launched a gamified cybersecurity exercise called Game of Threats — a real-time digital board game that pitted executives against simulated threat actors. The result? Decision-makers who'd never engaged with security training before were suddenly competing to outmaneuver ransomware campaigns and credential theft attacks. Engagement didn'

Carl B. Johnson Sep 15, 2026 5 min read
Physical Security and Cybersecurity

Physical Security and Cybersecurity: Why You Need Both

In 2023, a former employee of a New Jersey healthcare provider walked into an unlocked office, plugged a USB device into an unattended workstation, and exfiltrated over 20,000 patient records before anyone noticed. No firewall stopped it. No intrusion detection system flagged it. The breach happened because a physical

Carl B. Johnson Sep 14, 2026 5 min read
Security Awareness Training

How to Measure Security Awareness Training ROI

The Program That Looked Great on Paper — Until the Breach A mid-size healthcare company I consulted with had a 98% training completion rate. Every employee had clicked through every module. Leadership was proud. Then a single phishing email — disguised as a benefits enrollment update — compromised credentials for three domain admin

Carl B. Johnson Sep 12, 2026 5 min read
Cybersecurity for Nonprofits

Cybersecurity for Nonprofits: A Practical Defense Guide

The Breach That Nearly Killed a Children's Charity In 2023, Save the Children International confirmed a cyberattack by the BianLian ransomware group that reportedly compromised nearly 7 GB of sensitive data — including financial records, health data, and personal information. A global nonprofit with dedicated IT resources still got

Carl B. Johnson Sep 09, 2026 5 min read
Cyber Security Definition

Cyber Security Definition: What It Really Means in 2026

In 2023, MGM Resorts lost roughly $100 million after a social engineering phone call lasting just ten minutes gave a threat actor access to internal systems. The attackers didn't exploit some exotic zero-day vulnerability. They manipulated a help desk employee. If your cyber security definition starts and stops

Carl B. Johnson Sep 09, 2026 5 min read