Tag

security awareness training

Resources and best practices for designing and delivering effective security awareness training programs. Covers phishing simulations, compliance requirements, behavior change techniques, measuring training effectiveness, and fostering a culture of vigilance across organizations.

posts

computer security advice

Computer Security Advice That Actually Works in 2026

The Breach That Started With a Single Browser Extension In early 2024, a data breach at a mid-size healthcare firm started not with some sophisticated zero-day exploit, but with a Chrome extension an employee installed to manage their tabs. That extension harvested saved passwords, session cookies, and browser history. Within

Carl B. Johnson May 15, 2026 5 min read
cyber security

Cyber Security in 2026: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare suffered a ransomware attack that disrupted insurance claims processing for nearly every hospital and pharmacy in the United States. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — making it the largest healthcare

Carl B. Johnson Apr 23, 2026 5 min read
computer security software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack bypassed every piece of computer security software they had deployed. The attackers didn't exploit a zero-day vulnerability. They didn't brute-force a firewall. They called the help desk, impersonated an employee, and walked right

Carl B. Johnson Apr 18, 2026 5 min read
FBI Gmail

FBI Gmail Warning: What Every Organization Must Do Now

The FBI Gmail Alert That Changed the Threat Landscape In late 2024, the FBI issued a stark public service announcement: sophisticated phishing campaigns were actively targeting Gmail's 1.8 billion users, and the attacks were so convincing that even security-savvy professionals were falling for them. By 2025, the

Carl B. Johnson Apr 11, 2026 5 min read
phish

How One Phish Can Cost Your Company Millions

A Single Phish Email Took Down a $13 Billion Pipeline In May 2021, a single compromised password — likely harvested through a phish — shut down Colonial Pipeline and triggered fuel shortages across the U.S. East Coast. The company paid a $4.4 million ransom within hours. That's the

Carl B. Johnson Jan 26, 2026 7 min read
phishing email

Phishing Email Attacks in 2025: What Actually Works

One Phishing Email Cost MGM Resorts $100 Million In September 2023, a single social engineering phone call — preceded by a carefully crafted phishing email reconnaissance campaign — led to the breach that shut down MGM Resorts' operations across Las Vegas. Slot machines went dark. Hotel room keys stopped working. The

Carl B. Johnson Dec 27, 2025 7 min read
computer security

Computer Security in 2025: What Actually Works Now

In February 2025, the FBI's Internet Crime Complaint Center reported that cybercrime losses in 2024 exceeded $16 billion — a staggering jump from the $12.5 billion reported the year before. That number landed like a gut punch across the security community, but honestly, none of us were surprised.

Carl B. Johnson Nov 06, 2025 7 min read
phishing training for employees

Phishing Training for Employees: What Actually Works

A Single Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee with a phone call. That single interaction — not a sophisticated zero-day exploit, not a nation-state supply chain attack — led to a ransomware incident that cost the

Carl B. Johnson Sep 25, 2025 7 min read
phishing meaning

Phishing Meaning: What It Really Is and Why It Works

In January 2024, a finance employee at a multinational firm in Hong Kong transferred $25.6 million to criminals after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. That's where phishing lives now — far beyond

Carl B. Johnson Sep 18, 2024 7 min read
computer security

Computer Security in 2024: What Actually Works Now

In February 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by a ransomware attack that disrupted pharmacy operations, delayed patient care, and potentially exposed the protected health information of tens of millions of Americans. The root cause? Compromised credentials on a remote

Carl B. Johnson Jul 10, 2024 7 min read