Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

FakeEmail

FakeEmail Attacks: How Threat Actors Spoof Your Inbox

The FakeEmail That Cost One Company $37 Million In 2024, the FBI's IC3 reported that business email compromise — the art of sending a convincing fakeemail that impersonates a trusted sender — accounted for over $2.9 billion in adjusted losses. That's not a typo. One European company

Carl B. Johnson Oct 04, 2026 5 min read
Zero Trust Network Access

Zero Trust Network Access: What It Actually Takes

In 2023, the U.S. Marshals Service suffered a major breach when a threat actor compromised a system containing sensitive law enforcement data — personal information on investigative targets, internal processes, and more. The agency had traditional perimeter defenses in place. What they didn't have was a model that

Carl B. Johnson Oct 04, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeters Are Dead

In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard had accessed senior executive email accounts — not by exploiting some exotic zero-day, but by spray-attacking a legacy test account that lacked multi-factor authentication. One account. No MFA. That's all it took to breach

Carl B. Johnson Oct 03, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The FBI Didn't Issue a Joint Advisory for Nothing In March 2025, CISA, the FBI, and MS-ISAC released a joint cybersecurity advisory (#StopRansomware) specifically about the Medusa ransomware variant. By that point, Medusa had already hit over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, technology,

Carl B. Johnson Oct 01, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

Your Computer Security Software Didn't Stop the Breach In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that bypassed every piece of computer security software the company had deployed. The threat actors didn't hack through a firewall. They called the help

Carl B. Johnson Sep 30, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks Your Team Ignores Daily

3389: The Port That Keeps Giving — to Attackers In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as the single most common initial access vector in ransomware incidents reported to law enforcement. Not phishing. Not USB drives. RDP. And yet, in 2026, I still

Carl B. Johnson Sep 30, 2026 6 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Password In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past a help desk using nothing more than a phone call and a LinkedIn profile. No zero-day exploit. No advanced malware. Just a

Carl B. Johnson Sep 29, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

A $12.5 Billion Problem That Keeps Getting Worse The FBI's Internet Crime Complaint Center reported $12.5 billion in cybercrime losses for 2023 — a 22% jump from the prior year. And the trajectory hasn't slowed. If you're reading this in 2026 and still

Carl B. Johnson Sep 29, 2026 5 min read
Jobs Computer Security

Jobs in Computer Security: Your 2026 Career Guide

There are roughly 500,000 unfilled cybersecurity positions in the United States right now, according to CyberSeek, the workforce analytics tool backed by NIST and CompTIA. That's not a future projection — that's a gap employers are desperately trying to close today. If you've been

Carl B. Johnson Sep 28, 2026 5 min read