Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, a finance employee at Clorox received what looked like a routine vendor email. One click later, threat actors had a foothold inside the network. The resulting cyberattack disrupted operations for months and cost the company an estimated $356 million in damages

Carl B. Johnson Aug 14, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Proved Most Plans Are Fiction When Uber disclosed in 2022 that it had concealed a 2016 breach affecting 57 million users — and that its former CSO had been convicted of federal obstruction charges for the cover-up — it exposed something uglier than the breach itself. The company had

Carl B. Johnson Aug 14, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The Ransomware Gang That Treats Phishing Like a Business In March 2025, CISA and the FBI issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare, education, legal, insurance, manufacturing. The attack vector in the vast majority of cases?

Carl B. Johnson Aug 11, 2026 5 min read
Defense Evasion

When Attackers Removed Legitimate Software to Own You

They Didn't Just Bypass Your Security — They Removed Legitimate Tools Entirely In early 2024, a ransomware gang hit a mid-sized healthcare network and encrypted 11,000 endpoints in under four hours. The forensic report revealed something chilling: before deploying a single payload, the attackers methodically removed legitimate security

Carl B. Johnson Aug 10, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 10-Character Password That Cost a Hospital $3 Million In 2023, CommonSpirit Health disclosed a ransomware attack that disrupted operations across multiple states. Investigators traced the initial access back to compromised credentials — a password that met the organization's minimum requirements but crumbled under a credential stuffing attack. The

Carl B. Johnson Aug 10, 2026 5 min read
Cybersecurity Tips

Cybersecurity Tips That Actually Stop Breaches in 2026

A single employee at MGM Resorts answered a phone call from someone pretending to be a coworker. That one social engineering attack in September 2023 led to roughly $100 million in losses, a crippled reservation system, and slot machines going dark across Las Vegas. The attacker didn't exploit

Carl B. Johnson Aug 09, 2026 5 min read
AI Phishing Attacks

Gmail Users Warned About Sophisticated AI-Driven Phishing

The AI-Generated Email That Fooled a Security Engineer In early 2025, a Google Workspace consultant named Sam Mitrovic publicly documented how he nearly fell for an AI-driven phishing attack targeting his Gmail account. The attacker spoofed Google's support number, used a perfectly natural AI-generated voice, and referenced real

Carl B. Johnson Aug 08, 2026 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Criminals Fake Their Way In

In 2023, the FBI's Internet Crime Complaint Center reported over 43,000 victims of spoofing-related fraud, with losses exceeding $300 million. That number has only climbed since. And here's the part that should keep you up at night: a spoofing caller doesn't need malware,

Carl B. Johnson Aug 07, 2026 6 min read
Computer Security Advice

Computer Security Advice That Actually Works in 2026

A school district in Arizona lost $3.5 million in January 2024 after a single employee followed spoofed wire transfer instructions. The attacker didn't exploit a software vulnerability. They exploited trust. That incident captures why most computer security advice fails — it focuses on tools while ignoring the human

Carl B. Johnson Aug 07, 2026 5 min read