Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Insider Threat Indicators

Insider Threat Indicators: 9 Red Flags to Catch Early

In May 2022, a Yahoo research scientist named Qian Sang downloaded roughly 570,000 pages of proprietary source code to his personal devices — just two weeks after accepting a job at a competitor. Yahoo's internal systems flagged the bulk transfer, but only after the damage was done. This

Carl B. Johnson Jun 12, 2025 6 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeter Defense Is Dead

In January 2024, Microsoft disclosed that the Russian threat actor Midnight Blizzard had breached corporate email accounts — not by exploiting some exotic zero-day, but by password spraying a legacy test tenant that lacked multi-factor authentication. One overlooked account. No MFA. Catastrophic access. If a company with Microsoft's resources

Carl B. Johnson Jun 12, 2025 7 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2025

In January 2024, Microsoft disclosed that a Russian threat actor known as Midnight Blizzard breached corporate email accounts — not through some exotic zero-day, but by password-spraying a legacy test account that lacked multi-factor authentication. One forgotten account. No segmentation. No least-privilege enforcement. The result: a nation-state actor reading executive emails

Carl B. Johnson May 25, 2025 7 min read
Work From Home Cybersecurity

Work From Home Cybersecurity: A 2025 Survival Guide

In March 2024, a single remote employee at a midsize financial firm clicked a link in what looked like a Microsoft Teams notification. Within 72 hours, a threat actor had moved laterally across the company's network, exfiltrated 1.2 million customer records, and deployed ransomware that locked every

Carl B. Johnson May 25, 2025 7 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

Port 3389: The Door You Left Wide Open In January 2024, the FBI and CISA issued a joint advisory warning that the Phobos ransomware group had been exploiting exposed Remote Desktop Protocol (RDP) services to breach organizations across government, healthcare, education, and critical infrastructure. The attackers didn't use

Carl B. Johnson May 18, 2025 8 min read
Cybersecurity Training Compliance

Cybersecurity Training Compliance: What Regulators Want

In October 2024, the FTC finalized a settlement with Marriott International and its subsidiary Starwood Hotels over data breaches that exposed the personal information of 344 million customers. Among the FTC's requirements: Marriott had to implement a comprehensive information security program — including mandatory employee training. That wasn'

Carl B. Johnson May 10, 2025 7 min read
NIST Cybersecurity Framework

NIST Cybersecurity Framework: A Practical Guide for 2025

The Framework Nobody Reads — Until After the Breach In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the United States for weeks. UnitedHealth Group eventually disclosed that the breach affected roughly 100 million individuals — making it one of the largest healthcare data breaches in history.

Carl B. Johnson May 10, 2025 7 min read
Cybersecurity for Healthcare

Cybersecurity for Healthcare Organizations: A 2025 Guide

In February 2024, a ransomware attack on Change Healthcare — one of the largest health payment processors in the United States — disrupted claims processing for hospitals, pharmacies, and clinics across the country for weeks. UnitedHealth Group, its parent company, later confirmed that the personal health information of roughly 100 million individuals

Carl B. Johnson May 10, 2025 8 min read