Tag

security awareness

Content dedicated to raising security awareness across organizations and among individuals. Covers threat recognition, safe online behavior, reporting protocols, and strategies for embedding a culture of vigilance that reduces human error and minimizes cyber risk exposure.

posts

CISA cybersecurity guidelines

CISA Cybersecurity Guidelines: What Actually Matters

In February 2024, CISA issued an emergency directive after a threat actor compromised Microsoft's corporate email systems and accessed correspondence from multiple federal agencies. The directive forced agencies to reset credentials, review logs, and report back within days. That single incident crystallized something I've been telling

Carl B. Johnson May 16, 2026 6 min read
phishing awareness training

Phishing Awareness Training: What Actually Works in 2026

A 3-Minute Email Cost One Company $37 Million In 2024, a finance employee at a multinational firm joined a deepfake video call with what appeared to be the company's CFO and several colleagues. Every person on that call was AI-generated. The employee transferred $25.6 million (approximately HK$

Carl B. Johnson Apr 15, 2026 5 min read
cybersecurity training

How to Train Employees on Cybersecurity in 2026

The Breach That Started With a Single Click In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past help desk staff with a ten-minute phone call. The attackers didn't exploit some exotic zero-day. They exploited a human being

Carl B. Johnson Mar 30, 2026 5 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2025, the FBI's Internet Crime Complaint Center reported that phishing was — for the ninth consecutive year — the most-reported cybercrime in the United States. Not ransomware. Not cryptojacking. Phishing. The simplest attack in the playbook continues to cause the most damage, and the phishing meaning most people

Carl B. Johnson Jan 17, 2026 7 min read
cybersecurity tips

Cybersecurity Tips That Actually Work in 2025

The Breach That Started With a Single Password In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard accessed corporate email accounts — including those of senior leadership — using nothing more than a password spray attack against a legacy test account that lacked multi-factor authentication. No

Carl B. Johnson Nov 06, 2025 7 min read
cybersecurity awareness training

Cybersecurity Awareness Training: What Works in 2022

In January 2022, the Red Cross disclosed that a cyberattack compromised the personal data of over 515,000 vulnerable people — victims of conflict, missing persons, detainees. The attack vector? A threat actor exploiting an unpatched vulnerability, combined with social engineering techniques that went undetected for weeks. It's a

Carl B. Johnson Mar 21, 2022 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In May 2021, Ireland's Health Service Executive got hit with a Conti ransomware attack that started with a single phishing email. One employee opened one malicious Excel attachment, and the entire national healthcare system went offline for weeks. That's the real-world weight behind the phishing meaning

Carl B. Johnson Aug 25, 2021 7 min read
phishing emails

How to Spot Phishing Emails Before They Cost You

In July 2021, a single phishing email led to a ransomware attack that shut down fuel deliveries across the entire U.S. East Coast. The Colonial Pipeline breach started — like most breaches do — with a compromised credential. If one employee had known how to spot phishing emails, $4.4 million

Carl B. Johnson Aug 18, 2021 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing — making it the most reported cybercrime in the United States for the fifth consecutive year. Yet when I ask employees during security assessments to explain what phishing actually is, most give me a

Carl B. Johnson Feb 27, 2020 6 min read