Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Fake Identity Website

Fake Identity Website Threats: What You Need to Know

A Single Fake Identity Website Cost One Company $47 Million In early 2024, a finance employee at engineering firm Arup wired $25 million after joining a video call with what appeared to be the company's CFO and other colleagues. Every person on that call was a deepfake. The

Carl B. Johnson Nov 13, 2025 7 min read
Fake Mailer

Fake Mailer Attacks: How Threat Actors Spoof Email

In January 2024, the FBI's Internet Crime Complaint Center reported that business email compromise — much of it powered by spoofed sender addresses — cost American organizations over $2.9 billion in 2023 alone. Behind a huge share of those losses sits a deceptively simple tool: the fake mailer. These

Carl B. Johnson Nov 06, 2025 6 min read
FBI Gmail Warning

FBI Gmail Warning: What You Need to Know in 2025

The FBI Gmail Alert That Should Have Changed How You Think About Email In late 2024, the FBI issued a stark warning: AI-driven phishing attacks targeting Gmail users had become so sophisticated that even technically savvy professionals were falling for them. The advisory wasn't hypothetical. It was based

Carl B. Johnson Nov 06, 2025 7 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

The Virus That Cost a Hospital Chain $100 Million In 2017, the NotPetya wiper malware tore through networks worldwide in under 24 hours. Heritage Valley Health System lost access to its entire network — radiology, cardiology, even surgical systems went dark. Across the globe, Maersk lost nearly $300 million. Merck reported

Carl B. Johnson Nov 06, 2025 7 min read
Cybersecurity

Cybersecurity in 2025: What Actually Works Now

The Breach That Changed How I Think About Cybersecurity In February 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by a ransomware attack that disrupted pharmacy operations, delayed patient care, and exposed the protected health information of roughly 100 million individuals. UnitedHealth

Carl B. Johnson Nov 06, 2025 7 min read
Cyber Security

Cyber Security in 2025: What Actually Works Now

The Breach That Changed How I Think About Cyber Security In February 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by a ransomware attack that disrupted pharmacies, hospitals, and insurance claims across the country for weeks. UnitedHealth Group, its parent company, later

Carl B. Johnson Nov 06, 2025 7 min read
IT Security

IT Security in 2025: What Actually Works Now

In March 2025, the FBI's Internet Crime Complaint Center reported that cybercrime losses in the United States exceeded $16.6 billion in 2024 — a 33% increase over the prior year. That number didn't come from sophisticated nation-state attacks alone. It came from basic IT security failures:

Carl B. Johnson Oct 26, 2025 7 min read
Jobs Computer Security

Jobs in Computer Security: Your 2025 Career Roadmap

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase in losses over the previous year. That tidal wave of cybercrime isn't slowing down in 2025. It's accelerating. And every single

Carl B. Johnson Oct 26, 2025 7 min read
Computer Security

Computer Security: What Actually Works in 2025

The Breach That Rewrote the Rules of Computer Security In February 2024, Change Healthcare — one of the largest health payment processors in the United States — suffered a ransomware attack that disrupted claims processing for hospitals, pharmacies, and clinics across the country. UnitedHealth Group, its parent company, disclosed in its SEC

Carl B. Johnson Oct 26, 2025 7 min read
Web Security Best Practices

Web Security Best Practices That Actually Stop Breaches

In January 2023, T-Mobile disclosed that a threat actor exploited an API vulnerability to steal personal data on 37 million customer accounts. Not through some exotic zero-day — through a misconfigured web API that had been leaking data since November 2022. That's two months of silent hemorrhaging before anyone

Carl B. Johnson Oct 26, 2025 8 min read