Tag

Multi-Factor Authentication

Posts tagged with multi-factor authentication explain how layered identity verification strengthens access security. Coverage includes MFA implementation strategies, authenticator app comparisons, hardware token options, and best practices for deploying MFA across enterprise environments.

posts

Zero Trust Network Access

Zero Trust Network Access: What It Actually Takes

In 2023, the U.S. Marshals Service suffered a major breach when a threat actor compromised a system containing sensitive law enforcement data — personal information on investigative targets, internal processes, and more. The agency had traditional perimeter defenses in place. What they didn't have was a model that

Carl B. Johnson Oct 04, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeters Are Dead

In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard had accessed senior executive email accounts — not by exploiting some exotic zero-day, but by spray-attacking a legacy test account that lacked multi-factor authentication. One account. No MFA. That's all it took to breach

Carl B. Johnson Oct 03, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Password In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past a help desk using nothing more than a phone call and a LinkedIn profile. No zero-day exploit. No advanced malware. Just a

Carl B. Johnson Sep 29, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

A $12.5 Billion Problem That Keeps Getting Worse The FBI's Internet Crime Complaint Center reported $12.5 billion in cybercrime losses for 2023 — a 22% jump from the prior year. And the trajectory hasn't slowed. If you're reading this in 2026 and still

Carl B. Johnson Sep 29, 2026 5 min read
Cyber Hygiene Checklist

Cyber Hygiene Checklist: 12 Steps That Actually Work

The Breach That Started With an Unpatched Laptop In 2023, the MOVEit Transfer vulnerability (CVE-2023-34362) was exploited by the Cl0p ransomware group to compromise over 2,500 organizations worldwide. The root cause wasn't some exotic zero-day that no one could have predicted — it was a known vulnerability with

Carl B. Johnson Sep 26, 2026 5 min read
Security in Cloud Computing

Security in Cloud Computing: What Goes Wrong in 2026

A Single Checkbox Left Unchecked Cost Them Everything In 2023, Toyota disclosed that a cloud misconfiguration had exposed the location data of 2.15 million customers for over a decade. Not a sophisticated zero-day exploit. Not a nation-state threat actor. A misconfigured cloud database left publicly accessible because someone didn&

Carl B. Johnson Sep 25, 2026 5 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In 2024, Ivanti disclosed critical vulnerabilities in its VPN appliances — CVE-2024-21887 and CVE-2023-46805 — that were actively exploited by threat actors before patches were available. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. That's not a drill. That's your VPN

Carl B. Johnson Sep 24, 2026 5 min read
Computer Security Security

Computer Security Security: Why One Layer Is Never Enough

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to their help desk. The attackers didn't exploit some exotic zero-day. They bypassed one security control — identity verification — and the dominoes fell. That incident is a masterclass

Carl B. Johnson Sep 23, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read
Phishing Prevention Tips

Phishing Prevention Tips That Actually Stop Attacks

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Yet most of the phishing prevention tips circulating online read like they were written in 2009. "Don't click suspicious

Carl B. Johnson Sep 16, 2026 5 min read