Tag

Human Risk Management

Focuses on identifying, measuring, and reducing cybersecurity risks that originate from human behavior. Articles cover topics such as security culture development, behavioral analytics, insider threat mitigation, and strategies to turn employees into a strong line of defense.

posts

Cybersecurity Awareness Quiz

Cybersecurity Awareness Quiz: Test Your Team Now

93% of Breaches Start With a Person, Not a Firewall In 2023, Verizon's Data Breach Investigations Report confirmed what security professionals have been screaming about for years: the human element was involved in 74% of all breaches. By 2024, that figure remained stubbornly high. A cybersecurity awareness quiz

Carl B. Johnson Mar 28, 2026 5 min read
Security Awareness Metrics

Security Awareness Metrics That Actually Prove ROI

In 2024, IBM's Cost of a Data Breach Report pegged the global average breach cost at $4.88 million — the highest ever recorded. That same report found that organizations with security awareness training programs saved an average of $258,629 per breach compared to those without. Yet when

Carl B. Johnson Mar 29, 2025 8 min read
Security Awareness Metrics

Security Awareness Metrics That Prove ROI in 2023

When MGM Resorts got hit with a devastating social engineering attack in September 2023, it wasn't a firewall failure. It wasn't a zero-day exploit. A threat actor called the help desk, impersonated an employee, and walked right through the front door. The estimated cost? Over $100

Carl B. Johnson Sep 16, 2023 7 min read
Security Awareness Metrics

Security Awareness Metrics That Actually Prove ROI

In 2020, a mid-sized healthcare provider invested $250,000 in a security awareness program. Twelve months later, the CISO couldn't answer one question from the board: "Is it working?" No baseline measurements. No tracking. No defensible data. That CISO is now updating a résumé. I'

Carl B. Johnson Nov 28, 2021 7 min read
Security Awareness Metrics

Security Awareness Metrics That Prove ROI in 2026

When the SEC fined SolarWinds' CISO for misleading investors about cybersecurity practices, it sent a shockwave through every security department in America. The message was unmistakable: vague assurances about security posture aren't enough anymore. Boards, regulators, and cyber insurers now demand evidence. That's why security

Carl B. Johnson Oct 10, 2020 8 min read