Tag

security awareness training

Resources and best practices for designing and delivering effective security awareness training programs. Covers phishing simulations, compliance requirements, behavior change techniques, measuring training effectiveness, and fostering a culture of vigilance across organizations.

posts

FBI Gmail

FBI Gmail Warning: What You Must Do Right Now

The FBI Just Told 1.8 Billion Gmail Users to Pay Attention When the FBI issues a public warning about a specific email platform, it's not a drill. Over the past year, the FBI has repeatedly flagged Gmail as a primary target for sophisticated phishing campaigns, AI-generated social

Carl B. Johnson Aug 12, 2026 6 min read
phish

How One Phish Can Sink Your Entire Organization

A Single Phish Email Cost One Company $100 Million In 2024, MGM Resorts confirmed that a social engineering attack — which started with a single phone call and a phish-style credential theft scheme — contributed to losses exceeding $100 million. The threat actors behind the Scattered Spider group didn't need

Carl B. Johnson Jul 23, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number didn't drop in 2025. And from what I've seen in the first half of 2026, it's still

Carl B. Johnson Jul 14, 2026 6 min read
computer security

Computer Security in 2026: What Actually Works Now

In 2023, MGM Resorts lost roughly $100 million from a single social engineering phone call. A threat actor called the help desk, impersonated an employee found on LinkedIn, and within minutes had the credentials needed to deploy ransomware across the entire enterprise. That's not a firewall failure. That&

Carl B. Johnson Jun 29, 2026 5 min read
phishing simulation training

Phishing Simulation Training: Why Most Programs Fail

A 60% Click Rate That Should Have Been a Wake-Up Call I ran a phishing simulation training exercise for a mid-size logistics company last year. The first campaign used a fake Microsoft 365 password reset email — nothing fancy, no zero-day exploit, just a convincing lure. Sixty percent of employees clicked.

Carl B. Johnson Jun 22, 2026 5 min read
computer security advice

Computer Security Advice That Actually Works in 2026

The Breach That Started With a Single Browser Extension In early 2024, a data breach at a mid-size healthcare firm started not with some sophisticated zero-day exploit, but with a Chrome extension an employee installed to manage their tabs. That extension harvested saved passwords, session cookies, and browser history. Within

Carl B. Johnson May 15, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — making it the largest healthcare

Carl B. Johnson Apr 23, 2026 5 min read
computer security software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack bypassed every piece of computer security software they had deployed. The attackers didn't exploit a zero-day vulnerability. They didn't brute-force a firewall. They called the help desk, impersonated an employee, and walked right

Carl B. Johnson Apr 18, 2026 5 min read
FBI Gmail

FBI Gmail Warning: What Every Organization Must Do Now

The FBI Gmail Alert That Changed the Threat Landscape In late 2024, the FBI issued a stark public service announcement: sophisticated phishing campaigns were actively targeting Gmail's 1.8 billion users, and the attacks were so convincing that even security-savvy professionals were falling for them. By 2025, the

Carl B. Johnson Apr 11, 2026 5 min read
phish

How One Phish Can Cost Your Company Millions

A Single Phish Email Took Down a $13 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish — shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The company paid a $4.4 million ransom within hours. That's the

Carl B. Johnson Jan 26, 2026 7 min read