Tag

security awareness training

Resources and best practices for designing and delivering effective security awareness training programs. Covers phishing simulations, compliance requirements, behavior change techniques, measuring training effectiveness, and fostering a culture of vigilance across organizations.

posts

phishing attack

Phishing Attack Trends in 2026: What's Actually Working

The Phishing Attack That Cost One Hospital $65 Million In February 2024, Change Healthcare — one of the largest health payment processors in the U.S. — was hit by a ransomware attack that started with a single compromised credential. No multi-factor authentication on a remote access portal. One phishing attack opened

Carl B. Johnson Sep 11, 2026 5 min read
cybersecurity gamification training

Cybersecurity Gamification Training: Why It Works

A Fortune 500 company ran the same annual compliance training for three straight years. Completion rates hovered around 92%. Their phishing click rate? Stubbornly stuck at 31%. Then they switched to a gamified approach — leaderboards, scenario-based challenges, real-time feedback. Within six months, that click rate dropped to 11%. Cybersecurity gamification

Carl B. Johnson Aug 28, 2026 5 min read
FBI Gmail

FBI Gmail Warning: What You Must Do Right Now

The FBI Just Told 1.8 Billion Gmail Users to Pay Attention When the FBI issues a public warning about a specific email platform, it's not a drill. Over the past year, the FBI has repeatedly flagged Gmail as a primary target for sophisticated phishing campaigns, AI-generated social

Carl B. Johnson Aug 12, 2026 6 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Email Cost One Company $100 Million In 2024, MGM Resorts confirmed that a social engineering attack — which started with a single phone call and a phish-style credential theft scheme — contributed to losses exceeding $100 million. The threat actors behind the Scattered Spider group didn't need

Carl B. Johnson Jul 23, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number didn't drop in 2025. And from what I've seen in the first half of 2026, it's still

Carl B. Johnson Jul 14, 2026 6 min read
computer security

Computer Security in 2026: What Actually Works Now

In 2023, MGM Resorts lost roughly $100 million from a single social engineering phone call. A threat actor called the help desk, impersonated an employee found on LinkedIn, and within minutes had the credentials needed to deploy ransomware across the entire enterprise. That's not a firewall failure. That&

Carl B. Johnson Jun 29, 2026 5 min read
phishing simulation training

Phishing Simulation Training: Why Most Programs Fail

A 60% Click Rate That Should Have Been a Wake-Up Call I ran a phishing simulation training exercise for a mid-size logistics company last year. The first campaign used a fake Microsoft 365 password reset email — nothing fancy, no zero-day exploit, just a convincing lure. Sixty percent of employees clicked.

Carl B. Johnson Jun 22, 2026 5 min read
computer security advice

Computer Security Advice That Actually Works in 2026

The Breach That Started With a Single Browser Extension In early 2024, a data breach at a mid-size healthcare firm started not with some sophisticated zero-day exploit, but with a Chrome extension an employee installed to manage their tabs. That extension harvested saved passwords, session cookies, and browser history. Within

Carl B. Johnson May 15, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — making it the largest healthcare

Carl B. Johnson Apr 23, 2026 5 min read
computer security software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack bypassed every piece of computer security software they had deployed. The attackers didn't exploit a zero-day vulnerability. They didn't brute-force a firewall. They called the help desk, impersonated an employee, and walked right

Carl B. Johnson Apr 18, 2026 5 min read