Tag

security awareness

Content dedicated to raising security awareness across organizations and among individuals. Covers threat recognition, safe online behavior, reporting protocols, and strategies for embedding a culture of vigilance that reduces human error and minimizes cyber risk exposure.

posts

cybersecurity training

How to Train Employees on Cybersecurity in 2026

The Breach That Started With a Single Click In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past help desk staff with a ten-minute phone call. The attackers didn't exploit some exotic zero-day. They exploited a human being

Carl B. Johnson Mar 30, 2026 5 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2021, Ireland's Health Service Executive got hit with a Conti ransomware attack that started with a single phishing email. One employee opened one malicious Excel attachment, and the entire national healthcare system went offline for weeks. That's the real-world weight behind the phishing meaning

Carl B. Johnson Aug 25, 2021 7 min read
phishing emails

How to Spot Phishing Emails Before They Cost You

In July 2021, a single phishing email led to a ransomware attack that shut down fuel deliveries across the entire U.S. East Coast. The Colonial Pipeline breach started — like most breaches do — with a compromised credential. If one employee had known how to spot phishing emails, $4.4 million

Carl B. Johnson Aug 18, 2021 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing — making it the most reported cybercrime in the United States for the fifth consecutive year. Yet when I ask employees during security assessments to explain what phishing actually is, most give me a

Carl B. Johnson Feb 27, 2020 6 min read
NIST Cybersecurity Framework

NIST Cybersecurity Framework: A Practical Guide for 2026

The Framework 87% of Organizations Reference — But Most Implement Poorly When Change Healthcare suffered its catastrophic ransomware attack in early 2024 — ultimately affecting an estimated 100 million individuals — the post-incident analysis pointed to failures that the NIST Cybersecurity Framework was specifically designed to prevent. Missing multi-factor authentication on a critical

Carl B. Johnson Sep 20, 2019 8 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

A Single Email Cost This Company $100 Million In 2019, Toyota Boshoku Corporation wired $37 million to a threat actor who impersonated a business partner via email. Facebook and Google collectively lost over $100 million to a Lithuanian man who sent fake invoices over two years. These weren't

Carl B. Johnson Jun 18, 2019 6 min read
computer security security

Computer Security Security: Why One Layer Is Never Enough

The Breach That Proved "Secure Enough" Is a Myth In 2023, MGM Resorts lost an estimated $100 million after a social engineering phone call — just one phone call — gave threat actors the foothold they needed. MGM had firewalls. They had endpoint protection. They had a security team. What

Carl B. Johnson Feb 22, 2019 7 min read