Tag

Phishing Simulation

Learn how phishing simulations help organizations measure employee susceptibility to email-based attacks. Articles cover simulation design, realistic phishing templates, campaign scheduling, result analysis, and strategies for turning simulation data into stronger security behaviors.

posts

Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, Clorox disclosed a cybersecurity incident that disrupted operations for months and cost the company an estimated $49 million in recovery expenses. The attack reportedly began with social engineering — a threat actor tricking someone into giving up access. That's not

Carl B. Johnson Sep 14, 2026 6 min read
Security Awareness Training

How to Measure Security Awareness Training ROI

The Program That Looked Great on Paper — Until the Breach A mid-size healthcare company I consulted with had a 98% training completion rate. Every employee had clicked through every module. Leadership was proud. Then a single phishing email — disguised as a benefits enrollment update — compromised credentials for three domain admin

Carl B. Johnson Sep 12, 2026 5 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In March 2024, a finance employee at a Hong Kong multinational wired $25 million to threat actors after a single phishing email led to a deepfake video call with what appeared to be the company's CFO. That's not a Hollywood plot — it's a police-confirmed

Carl B. Johnson Sep 10, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read
Trojan Horse Malware

Trojan Horse Malware: What It Really Does to Networks

In 2023, the FBI's Internet Crime Complaint Center reported over $12.5 billion in losses from cybercrime — and a staggering percentage of those incidents started with a single piece of software pretending to be something it wasn't. Trojan horse malware remains one of the most effective

Carl B. Johnson Sep 05, 2026 5 min read
Phishing Scams

What Is a Phishing Scam? A Security Pro's Real Guide

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated phishing incidents at organizations of every size, from ten-person startups to Fortune 500 companies. The pattern is always

Carl B. Johnson Sep 05, 2026 5 min read
Phishing Email

Phishing Email Attacks: What Actually Works in 2026

One Phishing Email Cost This Company $100 Million In 2023, MGM Resorts was brought to its knees — not by a sophisticated zero-day exploit, but by a phishing email and a follow-up phone call. Threat actors from the Scattered Spider group used social engineering to trick an IT help desk employee,

Carl B. Johnson Aug 30, 2026 6 min read
Phishing

Define Phishing: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on security tools, phishing remains the number one way threat actors break into organizations. So let's actually

Carl B. Johnson Aug 29, 2026 5 min read