Tag

Multi-Factor Authentication

Posts tagged with multi-factor authentication explain how layered identity verification strengthens access security. Coverage includes MFA implementation strategies, authenticator app comparisons, hardware token options, and best practices for deploying MFA across enterprise environments.

posts

Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Spring2024!" In 2023, a Verizon Data Breach Investigations Report finding shook the industry: roughly 49% of breaches involved stolen credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. Reused, predictable, phishable passwords. I've responded to incidents where the root cause was

Carl B. Johnson Aug 06, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

The Breach That Changed How I Think About Cybersecurity In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations and medical claims processing across the entire United States. UnitedHealth Group later confirmed that roughly one-third of all Americans may have had their data exposed. The attack vector?

Carl B. Johnson Aug 05, 2026 6 min read
Password Manager

Why Use a Password Manager: The Case Is Closed

In January 2024, a massive credential stuffing attack compromised over 34,000 PayPal accounts — not because PayPal's systems failed, but because users reused passwords across multiple sites. The attackers didn't hack anything. They simply tried stolen credentials from other breaches and walked right in. If you&

Carl B. Johnson Aug 05, 2026 5 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Strong Passwords

How to Create a Strong Password That Actually Works

In 2023, a single compromised password at MGM Resorts helped threat actors trigger a social engineering attack that cost the company over $100 million. The attackers didn't exploit some exotic zero-day vulnerability. They exploited people — and weak credential hygiene handed them the keys. If you've ever

Carl B. Johnson Jul 28, 2026 5 min read
Securing Remote Employees

Securing Remote Employees: What Actually Works in 2026

The Coffee Shop Breach That Cost $6.5 Million In 2024, a mid-size financial services firm discovered that a single remote employee working from a hotel lobby had their session token hijacked through a man-in-the-middle attack on the hotel's Wi-Fi. The threat actor used that access to move

Carl B. Johnson Jul 27, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read
Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read