Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Computer Security Security

Computer Security Security: Why One Layer Is Never Enough

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to their help desk. The attackers didn't exploit some exotic zero-day. They bypassed one security control — identity verification — and the dominoes fell. That incident is a masterclass

Carl B. Johnson Sep 23, 2026 5 min read
Cybersecurity for Law Firms

Cybersecurity for Law Firms: A Practical Defense Guide

The Breach That Put Every Law Firm on Notice In 2023, the international law firm Bryan Cave Leighton Paisner disclosed a data breach that exposed the personal information of over 51,000 individuals — including clients of major corporations like Mondelēz. The firm didn't just lose data. It lost

Carl B. Johnson Sep 22, 2026 6 min read
Phishing

What Is Phishing? The Attack Behind 90% of Breaches

In 2023, a single phishing email gave attackers access to MGM Resorts' entire IT infrastructure. The result: over $100 million in losses, days of operational chaos, and a security wake-up call that echoed across every industry. The attackers didn't exploit a zero-day vulnerability or deploy sophisticated malware.

Carl B. Johnson Sep 22, 2026 5 min read
Insider Threat Awareness

Insider Threat Awareness: What Most Companies Miss

The Threat Already Inside Your Building In 2022, a former Twitter employee was convicted of spying on behalf of Saudi Arabia, accessing the personal data of thousands of users — including dissidents — using nothing more than his legitimate employee credentials. No malware. No phishing email. Just a trusted insider with access

Carl B. Johnson Sep 21, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns Explained

In March 2025, CISA and the FBI issued a joint advisory warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors — healthcare, education, legal, insurance, and manufacturing. The attack vector in the vast majority of cases? Phishing emails and credential theft. If you think your

Carl B. Johnson Sep 19, 2026 6 min read
Phishing Scams

Phishing Scams in 2026: What Actually Works to Stop Them

The Phishing Email That Cost One Company $37 Million In 2024, a finance employee at a multinational firm in Hong Kong joined a video call with people who looked and sounded exactly like the company's CFO and other executives. Every face on that call was a deepfake. The

Carl B. Johnson Sep 18, 2026 6 min read
Smishing Attacks

Smishing Attack Examples: Real Texts That Steal Data

The Text Message That Cost One Company $15 Million In 2022, Twilio disclosed that a sophisticated smishing campaign tricked several employees into handing over their credentials via text messages impersonating the company's IT department. The attackers then used those stolen credentials to access internal systems and customer data.

Carl B. Johnson Sep 18, 2026 5 min read
Phishing Prevention Tips

Phishing Prevention Tips That Actually Stop Attacks

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Yet most of the phishing prevention tips circulating online read like they were written in 2009. "Don't click suspicious

Carl B. Johnson Sep 16, 2026 5 min read
Cybersecurity Gamification Training

Cybersecurity Gamification Training That Actually Works

In 2019, PricewaterhouseCoopers launched a gamified cybersecurity exercise called Game of Threats — a real-time digital board game that pitted executives against simulated threat actors. The result? Decision-makers who'd never engaged with security training before were suddenly competing to outmaneuver ransomware campaigns and credential theft attacks. Engagement didn'

Carl B. Johnson Sep 15, 2026 5 min read