Tag

Data Breach Prevention

Explores strategies and best practices for preventing data breaches in organizations of all sizes. Covers topics like access controls, encryption, network monitoring, incident response planning, and employee awareness to help reduce the risk of unauthorized data exposure.

posts

Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts employee through a simple phone call to the IT help desk. That single conversation — not a sophisticated zero-day exploit, not a nation-state attack — led to a ransomware incident that shut

Carl B. Johnson Aug 23, 2026 5 min read
Phishing

Phishing: Why It Still Works and How to Stop It

A Single Email Cost This Company Everything In 2023, MGM Resorts lost an estimated $100 million after a threat actor used a phone-based social engineering attack — a technique closely related to phishing — to gain access to their systems. The attackers didn't exploit a zero-day vulnerability or brute-force a

Carl B. Johnson Aug 22, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

A $100,000 Antivirus Setup That Stopped Nothing I worked with an organization in 2024 that had invested heavily in computer security software — endpoint detection, next-gen firewalls, SIEM, the works. They still got hit with a ransomware attack that encrypted 14,000 files and shut down operations for nine days.

Carl B. Johnson Aug 21, 2026 5 min read
Vendor Risk Management

Vendor Risk Management Cybersecurity: A Practical Guide

The Breach That Didn't Start With You In 2023, the MOVEit Transfer vulnerability didn't just hit one company — it cascaded through thousands of organizations that trusted a single vendor's file transfer software. Clop ransomware operators exploited the flaw, and suddenly organizations like the BBC,

Carl B. Johnson Aug 20, 2026 6 min read
Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware.

Carl B. Johnson Aug 19, 2026 5 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

The Framework Nobody Reads But Everyone Claims to Follow I once walked into a mid-sized financial firm that proudly declared on their website they were "aligned with NIST standards." Thirty minutes into the assessment, I found admin passwords on sticky notes, no multi-factor authentication on critical systems, and

Carl B. Johnson Aug 18, 2026 6 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Defenses

In 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider impersonated an employee on a help desk call — a textbook spear phishing technique that bypassed every technical control the company had. The attacker didn't blast out a million generic emails. They researched one

Carl B. Johnson Aug 17, 2026 5 min read