Tag

Data Protection

Articles under this tag address strategies, technologies, and best practices for safeguarding sensitive information from unauthorized access, breaches, and loss. Topics include encryption, data classification, backup protocols, regulatory compliance, and organizational policies that strengthen data security across all environments.

posts

Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

The Clock Starts Ticking the Moment You Discover a Breach In March 2024, AT&T disclosed a massive data breach affecting approximately 73 million current and former customers — but the compromised data dated back years. The delay between compromise and discovery is common. What matters just as much is

Carl B. Johnson Sep 16, 2026 5 min read
Shoulder Surfing Attack

Shoulder Surfing Attack: The Low-Tech Threat You Ignore

A financial analyst at a Fortune 500 company typed her corporate credentials into a laptop at Chicago O'Hare. The man sitting two seats behind her wasn't reading the news on his phone — he was recording her screen. Within 48 hours, the attacker used those stolen credentials

Carl B. Johnson Aug 31, 2026 5 min read
Clean Desk Policy

Clean Desk Policy Cybersecurity: Your Cheapest Defense

The Sticky Note That Cost a Hospital $3 Million A nurse left a sticky note with login credentials on her monitor. A visitor photographed it. Within 48 hours, a threat actor had accessed patient records for over 10,000 individuals. The resulting HIPAA settlement wasn't pretty. I'

Carl B. Johnson Jul 06, 2026 5 min read
Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

The Breach Nobody Reported — Until It Was Too Late In 2020, the health insurer Anthem agreed to pay $39.5 million to settle claims with 43 state attorneys general over a 2015 data breach affecting nearly 79 million people. The breach itself was devastating. But the lawsuits and regulatory actions

Carl B. Johnson Feb 24, 2022 7 min read
Mobile Device Security Policy

Mobile Device Security Policy: A Practical Guide

In April 2021, the FBI's IC3 reported a sharp rise in mobile-focused phishing attacks — schemes specifically designed to exploit the smaller screens and always-on nature of smartphones. I've watched organizations pour millions into securing their perimeters while ignoring the devices employees actually use the most. The

Carl B. Johnson Dec 22, 2021 7 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2021 Guide

The SolarWinds Breach Just Made Notification a National Crisis In December 2020, FireEye disclosed that a sophisticated threat actor had compromised SolarWinds Orion software, giving attackers access to roughly 18,000 organizations — including the U.S. Treasury, the Department of Homeland Security, and Fortune 500 companies. Weeks later, we'

Carl B. Johnson Jan 14, 2021 8 min read
Shoulder Surfing Attack

Shoulder Surfing Attack: The Low-Tech Threat You Ignore

A former employee at a financial services firm in Chicago watched his coworker type her password every morning for two weeks. He memorized it character by character. After he was terminated for performance issues, he used those stolen credentials to access the company's client database from a public

Carl B. Johnson Oct 10, 2020 7 min read