Tag

Multi-Factor Authentication

Posts tagged with multi-factor authentication explain how layered identity verification strengthens access security. Coverage includes MFA implementation strategies, authenticator app comparisons, hardware token options, and best practices for deploying MFA across enterprise environments.

posts

Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Credential Theft Problem Nobody Takes Seriously Enough In January 2024, a massive credential dump called "Naz.API" exposed over 70 million unique email addresses and passwords harvested from stealer malware and credential-stuffing operations. Most of those credentials worked because the victims reused passwords across multiple services. I&

Carl B. Johnson Aug 27, 2026 5 min read
SaaS Security Best Practices

SaaS Security Best Practices to Protect Your Stack

The Average Company Uses 130 SaaS Apps — And Secures Maybe Half When I audited a mid-size financial services firm last year, they believed they had about 40 SaaS applications in production. The real number was 187. Over half were adopted by individual departments without IT's knowledge. Three of

Carl B. Johnson Aug 27, 2026 5 min read
Multi-Factor Authentication

What Is Multi-Factor Authentication? A Real-World Guide

In 2022, Uber's entire internal network was compromised because a single contractor approved a push notification on their phone. The threat actor had already stolen the contractor's password through social engineering — all they needed was that one tap. That breach exposed internal tools, source code, and

Carl B. Johnson Aug 25, 2026 5 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That one vishing call triggered a ransomware attack that shut down slot machines, hotel key

Carl B. Johnson Aug 18, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 10-Character Password That Cost a Hospital $3 Million In 2023, CommonSpirit Health disclosed a ransomware attack that disrupted operations across multiple states. Investigators traced the initial access back to compromised credentials — a password that met the organization's minimum requirements but crumbled under a credential stuffing attack. The

Carl B. Johnson Aug 10, 2026 5 min read
Cyber Hygiene

Cyber Hygiene Definition: What It Really Means in 2026

A Hospital Paid $475,000 Because Someone Skipped the Basics In 2023, the U.S. Department of Health and Human Services settled with a healthcare provider for $475,000 after a phishing attack exposed patient records. The root cause wasn't a sophisticated zero-day exploit. It was a lack

Carl B. Johnson Aug 09, 2026 5 min read
Cybersecurity Tips

Cybersecurity Tips That Actually Stop Breaches in 2026

A single employee at MGM Resorts answered a phone call from someone pretending to be a coworker. That one social engineering attack in September 2023 led to roughly $100 million in losses, a crippled reservation system, and slot machines going dark across Las Vegas. The attacker didn't exploit

Carl B. Johnson Aug 09, 2026 5 min read