Tag

Employee Cybersecurity

Resources focused on building a security-conscious workforce through training, awareness campaigns, and policy enforcement. Topics include phishing simulations, security onboarding programs, acceptable use policies, and techniques for fostering lasting behavioral change among employees.

posts

Acceptable Use Policy

Acceptable Use Policy Cybersecurity: Why Yours Fails

The Policy Everyone Signs and Nobody Reads In 2023, a single employee at a major casino operator plugged a personal USB device into a workstation. That device carried malware. Within hours, threat actors had lateral movement across the network. The resulting breach cost over $100 million in damages, downtime, and

Carl B. Johnson Jul 30, 2026 6 min read
Insider Threats

How to Prevent Insider Threats Before They Cost Millions

In 2022, a former employee at Cash App's parent company, Block, downloaded reports containing the personal information of 8.2 million customers — months after they'd left the company. Their access had never been revoked. That single oversight triggered SEC filings, lawsuits, and reputational damage that took

Carl B. Johnson Jun 23, 2026 5 min read
Insider Threats

Malicious Insider vs Negligent Insider: The Real Threat

One Employee Stole Data. The Other Just Clicked a Link. Both Cost Millions. In 2022, a former Amazon employee was convicted for her role in the Capital One breach that exposed over 100 million customer records. That same year, the Verizon Data Breach Investigations Report found that 82% of breaches

Carl B. Johnson May 13, 2026 5 min read
Phish Food

Phish Food: What Employees Click and Why It Works

Your Employees Are Hungry — And Threat Actors Are Cooking In 2023, the FBI's Internet Crime Complaint Center (IC3) logged over 298,000 phishing complaints — more than any other cybercrime category for the fifth year running. That's nearly 817 reported phishing attacks per day. And those are

Carl B. Johnson May 05, 2026 5 min read