Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Stolen Credentials Dark Web

Stolen Credentials Dark Web: How Your Logins Get Sold

In 2024, the FBI's Internet Crime Complaint Center (IC3) reported that compromised credentials were a factor in a staggering number of the complaints they received, driving billions of dollars in losses. I've personally worked incident response cases where a single set of stolen credentials — purchased on

Carl B. Johnson Aug 17, 2026 5 min read
Data Breach Examples 2026

Data Breach Examples 2026: Lessons from Real Attacks

We're barely halfway through 2026, and the breach disclosures are already stacking up at a pace that should alarm every executive, IT director, and business owner reading this. If you're searching for data breach examples 2026, you're probably trying to figure out what'

Carl B. Johnson Aug 16, 2026 5 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

A Single Email Cost This Company $100 Million In 2019, Toyota Boshoku Corporation lost $37 million to a single business email compromise attack. A threat actor impersonated a senior executive and convinced a finance employee to change wire transfer details. The money vanished. That's phishing — not some abstract

Carl B. Johnson Aug 15, 2026 5 min read
Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Single Click Cost One Hospital Chain $100 Million In 2020, Universal Health Services — a Fortune 500 hospital operator — got hit by the Ryuk ransomware strain. The result: 400 facilities knocked offline, staff reverting to pen and paper, and an estimated $67 million in direct costs plus ongoing damages that

Carl B. Johnson Aug 15, 2026 5 min read
Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, a finance employee at Clorox received what looked like a routine vendor email. One click later, threat actors had a foothold inside the network. The resulting cyberattack disrupted operations for months and cost the company an estimated $356 million in damages

Carl B. Johnson Aug 14, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Proved Most Plans Are Fiction When Uber disclosed in 2022 that it had concealed a 2016 breach affecting 57 million users — and that its former CSO had been convicted of federal obstruction charges for the cover-up — it exposed something uglier than the breach itself. The company had

Carl B. Johnson Aug 14, 2026 5 min read
Medusa Ransomware

Medusa Ransomware Gang Phishing Campaigns: What to Know

The Ransomware Gang That Treats Phishing Like a Business In March 2025, CISA and the FBI issued a joint advisory — AA25-071A — warning that the Medusa ransomware gang had compromised over 300 organizations across critical infrastructure sectors. Healthcare, education, legal, insurance, manufacturing. The attack vector in the vast majority of cases?

Carl B. Johnson Aug 11, 2026 5 min read
Defense Evasion

When Attackers Removed Legitimate Software to Own You

They Didn't Just Bypass Your Security — They Removed Legitimate Tools Entirely In early 2024, a ransomware gang hit a mid-sized healthcare network and encrypted 11,000 endpoints in under four hours. The forensic report revealed something chilling: before deploying a single payload, the attackers methodically removed legitimate security

Carl B. Johnson Aug 10, 2026 5 min read
Strong Password Examples

Strong Password Examples That Actually Stop Hackers

The 10-Character Password That Cost a Hospital $3 Million In 2023, CommonSpirit Health disclosed a ransomware attack that disrupted operations across multiple states. Investigators traced the initial access back to compromised credentials — a password that met the organization's minimum requirements but crumbled under a credential stuffing attack. The

Carl B. Johnson Aug 10, 2026 5 min read