Tag

phishing simulation

Learn how phishing simulation exercises help organizations test employee readiness against real-world email attacks. This tag covers simulation design, campaign metrics, benchmarking results, and using simulated phishing to continuously improve organizational resilience to social engineering threats.

posts

cyber security

Cyber Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — making it the largest healthcare

Carl B. Johnson Apr 23, 2026 5 min read
computer security software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack bypassed every piece of computer security software they had deployed. The attackers didn't exploit a zero-day vulnerability. They didn't brute-force a firewall. They called the help desk, impersonated an employee, and walked right

Carl B. Johnson Apr 18, 2026 5 min read
phishing awareness training

Phishing Awareness Training: What Actually Works in 2026

A 3-Minute Email Cost One Company $37 Million In 2024, a finance employee at a multinational firm joined a deepfake video call with what appeared to be the company's CFO and several colleagues. Every person on that call was AI-generated. The employee transferred $25.6 million (approximately HK$

Carl B. Johnson Apr 15, 2026 5 min read
cybersecurity training

How to Train Employees on Cybersecurity in 2026

The Breach That Started With a Single Click In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past help desk staff with a ten-minute phone call. The attackers didn't exploit some exotic zero-day. They exploited a human being

Carl B. Johnson Mar 30, 2026 5 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2025, the FBI's Internet Crime Complaint Center reported that phishing was — for the ninth consecutive year — the most-reported cybercrime in the United States. Not ransomware. Not cryptojacking. Phishing. The simplest attack in the playbook continues to cause the most damage, and the phishing meaning most people

Carl B. Johnson Jan 17, 2026 7 min read
phishing email

Phishing Email Attacks in 2025: What Actually Works

One Phishing Email Cost MGM Resorts $100 Million In September 2023, a single social engineering phone call — preceded by a carefully crafted phishing email reconnaissance campaign — led to the breach that shut down MGM Resorts' operations across Las Vegas. Slot machines went dark. Hotel room keys stopped working. The

Carl B. Johnson Dec 27, 2025 7 min read
phishing training for employees

Phishing Training for Employees: What Actually Works

A Single Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee with a phone call. That single interaction — not a sophisticated zero-day exploit, not a nation-state supply chain attack — led to a ransomware incident that cost the

Carl B. Johnson Sep 25, 2025 7 min read
cybersecurity training

How to Train Employees on Cybersecurity in 2025

The Breach That Started With a Single Click In January 2024, Microsoft disclosed that the Russian threat actor Midnight Blizzard compromised a legacy test tenant account using a password spray attack — no multi-factor authentication, no special exploit. Just a weak credential and an employee environment nobody was watching. The attackers

Carl B. Johnson Aug 17, 2025 7 min read
cybersecurity training

How to Train Employees on Cybersecurity That Sticks

The Click That Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee with a simple phone call. That one interaction led to a ransomware attack that shut down slot machines, hotel check-ins, and digital room keys across Las

Carl B. Johnson Feb 28, 2024 7 min read