Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Cloud Storage Security Risks

Cloud Storage Security Risks: What Your Team Ignores

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. No zero-day exploit. No sophisticated malware. Just a password spray against a forgotten cloud account. That single oversight gave attackers months of access

Carl B. Johnson Aug 06, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

The Breach That Changed How I Think About Cybersecurity In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations and medical claims processing across the entire United States. UnitedHealth Group later confirmed that roughly one-third of all Americans may have had their data exposed. The attack vector?

Carl B. Johnson Aug 05, 2026 6 min read
Password Manager

Why Use a Password Manager: The Case Is Closed

In January 2024, a massive credential stuffing attack compromised over 34,000 PayPal accounts — not because PayPal's systems failed, but because users reused passwords across multiple sites. The attackers didn't hack anything. They simply tried stolen credentials from other breaches and walked right in. If you&

Carl B. Johnson Aug 05, 2026 5 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion — a 22% increase from the prior year. A significant portion of those complaints involved malware, ransomware, and credential theft that started with a single computer virus. If you think

Carl B. Johnson Aug 03, 2026 5 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read
FTC Cybersecurity Requirements

FTC Cybersecurity Requirements for Businesses in 2026

The FTC Just Fined a Company $1.5 Million — Because They Skipped the Basics In 2023, the FTC settled with Chegg for $3.5 million after four separate data breaches exposed tens of millions of customer records. Employees had been sharing login credentials. Sensitive data sat in plain text. Multi-factor

Carl B. Johnson Jul 31, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Email Phishing Red Flags

Email Phishing Red Flags: 9 Signs You're Being Targeted

The Email That Cost One Company $37 Million In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked

Carl B. Johnson Jul 31, 2026 5 min read