Tag

Phishing Prevention

Delivers actionable advice on recognizing and preventing phishing attacks, including email phishing, spear phishing, smishing, and vishing. Covers detection techniques, employee training approaches, email security tools, and real-world phishing examples to strengthen your defenses.

posts

Computer Security Software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts had a multi-billion dollar security stack — endpoint detection, firewalls, SIEM platforms, the works. A single social engineering phone call bypassed all of it. The attackers impersonated an employee, convinced the IT help desk to reset credentials, and caused an estimated $100 million in damages. If you

Carl B. Johnson Sep 04, 2026 5 min read
Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider called MGM Resorts' IT help desk, impersonated an employee, and gained access to internal systems. The result? Over $100 million in losses, days of disrupted operations, and a data breach affecting millions of

Carl B. Johnson Aug 31, 2026 5 min read
Shoulder Surfing Attack

Shoulder Surfing Attack: The Low-Tech Threat You Ignore

A financial analyst at a Fortune 500 company typed her corporate credentials into a laptop at Chicago O'Hare. The man sitting two seats behind her wasn't reading the news on his phone — he was recording her screen. Within 48 hours, the attacker used those stolen credentials

Carl B. Johnson Aug 31, 2026 5 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In March 2024, a threat actor breached a major healthcare provider's network using a single compromised password — no second factor required. The organization had purchased MFA licenses two years prior but never enforced enrollment. That gap cost them months of remediation and exposed the records of over 100,

Carl B. Johnson Aug 30, 2026 5 min read
Cybersecurity for Financial Services

Cybersecurity for Financial Services: A 2026 Guide

In 2023, a single MOVEit vulnerability gave threat actors access to data from over 2,500 organizations — and financial institutions were among the hardest hit. Banks, credit unions, wealth management firms, and insurance companies collectively reported hundreds of millions of compromised records. If you work in finance, you already know

Carl B. Johnson Aug 29, 2026 6 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Credential Theft Problem Nobody Takes Seriously Enough In January 2024, a massive credential dump called "Naz.API" exposed over 70 million unique email addresses and passwords harvested from stealer malware and credential-stuffing operations. Most of those credentials worked because the victims reused passwords across multiple services. I&

Carl B. Johnson Aug 27, 2026 5 min read
SaaS Security Best Practices

SaaS Security Best Practices to Protect Your Stack

The Average Company Uses 130 SaaS Apps — And Secures Maybe Half When I audited a mid-size financial services firm last year, they believed they had about 40 SaaS applications in production. The real number was 187. Over half were adopted by individual departments without IT's knowledge. Three of

Carl B. Johnson Aug 27, 2026 5 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — more than any other cybercrime category. That number has only climbed since. I've investigated breaches at organizations of every size, and the entry point is almost always the same: one employee who

Carl B. Johnson Aug 25, 2026 6 min read