Tag

IT Governance

posts

Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

In 2023, a mid-size healthcare company discovered that an employee had been syncing patient records to a personal Dropbox account for two years. The data breach affected over 30,000 patients and triggered a HIPAA investigation. The employee wasn't malicious — they just wanted an easier way to work

Carl B. Johnson Sep 23, 2026 5 min read
Acceptable Use Policy

Acceptable Use Policy Cybersecurity: Your First Defense

In 2023, a single employee at MGM Resorts used a corporate credential to respond to a social engineering call. The threat actor impersonated IT, gained access, and triggered a ransomware attack that cost the company over $100 million. The kicker? A well-enforced acceptable use policy — one that clearly defined how

Carl B. Johnson Apr 20, 2026 5 min read
Acceptable Use Policy

Acceptable Use Policy Cybersecurity: Your First Defense

The Policy Nobody Reads Until It's Too Late In 2023, a single employee at MGM Resorts called the help desk, and a threat actor used social engineering to gain access that led to a $100 million hit on operations. One phone call. No malware exploit. No zero-day vulnerability.

Carl B. Johnson Nov 08, 2020 6 min read