Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Cybersecurity Tips

Cybersecurity Tips That Actually Stop Breaches in 2026

A single employee at MGM Resorts answered a phone call from someone pretending to be a coworker. That one social engineering attack in September 2023 led to roughly $100 million in losses, a crippled reservation system, and slot machines going dark across Las Vegas. The attacker didn't exploit

Carl B. Johnson Aug 09, 2026 5 min read
AI Phishing Attacks

Gmail Users Warned About Sophisticated AI-Driven Phishing

The AI-Generated Email That Fooled a Security Engineer In early 2025, a Google Workspace consultant named Sam Mitrovic publicly documented how he nearly fell for an AI-driven phishing attack targeting his Gmail account. The attacker spoofed Google's support number, used a perfectly natural AI-generated voice, and referenced real

Carl B. Johnson Aug 08, 2026 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Criminals Fake Their Way In

In 2023, the FBI's Internet Crime Complaint Center reported over 43,000 victims of spoofing-related fraud, with losses exceeding $300 million. That number has only climbed since. And here's the part that should keep you up at night: a spoofing caller doesn't need malware,

Carl B. Johnson Aug 07, 2026 6 min read
Computer Security Advice

Computer Security Advice That Actually Works in 2026

A school district in Arizona lost $3.5 million in January 2024 after a single employee followed spoofed wire transfer instructions. The attacker didn't exploit a software vulnerability. They exploited trust. That incident captures why most computer security advice fails — it focuses on tools while ignoring the human

Carl B. Johnson Aug 07, 2026 5 min read
Cloud Storage Security Risks

Cloud Storage Security Risks: What Your Team Ignores

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. No zero-day exploit. No sophisticated malware. Just a password spray against a forgotten cloud account. That single oversight gave attackers months of access

Carl B. Johnson Aug 06, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

The Breach That Changed How I Think About Cybersecurity In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations and medical claims processing across the entire United States. UnitedHealth Group later confirmed that roughly one-third of all Americans may have had their data exposed. The attack vector?

Carl B. Johnson Aug 05, 2026 6 min read
Password Manager

Why Use a Password Manager: The Case Is Closed

In January 2024, a massive credential stuffing attack compromised over 34,000 PayPal accounts — not because PayPal's systems failed, but because users reused passwords across multiple sites. The attackers didn't hack anything. They simply tried stolen credentials from other breaches and walked right in. If you&

Carl B. Johnson Aug 05, 2026 5 min read
Computer Virus Prevention

Computer Virus Prevention: 9 Steps That Actually Work

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with losses exceeding $12.5 billion — a 22% increase from the prior year. A significant portion of those complaints involved malware, ransomware, and credential theft that started with a single computer virus. If you think

Carl B. Johnson Aug 03, 2026 5 min read
Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read