Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Data Breach Examples 2026

Data Breach Examples 2026: Real Incidents and Lessons

We're barely halfway through 2026 and the breach disclosures are already piling up. From healthcare systems crippled by ransomware to credential theft campaigns that bypassed legacy MFA, the data breach examples of 2026 reinforce a pattern I've tracked for over a decade: organizations keep making the

Carl B. Johnson Sep 15, 2026 5 min read
Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, Clorox disclosed a cybersecurity incident that disrupted operations for months and cost the company an estimated $49 million in recovery expenses. The attack reportedly began with social engineering — a threat actor tricking someone into giving up access. That's not

Carl B. Johnson Sep 14, 2026 6 min read
Physical Security and Cybersecurity

Physical Security and Cybersecurity: Why You Need Both

In 2023, a former employee of a New Jersey healthcare provider walked into an unlocked office, plugged a USB device into an unattended workstation, and exfiltrated over 20,000 patient records before anyone noticed. No firewall stopped it. No intrusion detection system flagged it. The breach happened because a physical

Carl B. Johnson Sep 14, 2026 5 min read
Types of Malware

Types of Malware: What Every Organization Must Know

In 2023, MGM Resorts lost roughly $100 million after a social engineering attack delivered malware that crippled operations across Las Vegas for over a week. Slot machines went dark, hotel room keys stopped working, and guest data was compromised. The entry point? A phone call to the help desk. Understanding

Carl B. Johnson Sep 13, 2026 5 min read
Security Awareness Training

How to Measure Security Awareness Training ROI

The Program That Looked Great on Paper — Until the Breach A mid-size healthcare company I consulted with had a 98% training completion rate. Every employee had clicked through every module. Leadership was proud. Then a single phishing email — disguised as a benefits enrollment update — compromised credentials for three domain admin

Carl B. Johnson Sep 12, 2026 5 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In March 2024, a finance employee at a Hong Kong multinational wired $25 million to threat actors after a single phishing email led to a deepfake video call with what appeared to be the company's CFO. That's not a Hollywood plot — it's a police-confirmed

Carl B. Johnson Sep 10, 2026 5 min read
Cybersecurity for Nonprofits

Cybersecurity for Nonprofits: A Practical Defense Guide

The Breach That Nearly Killed a Children's Charity In 2023, Save the Children International confirmed a cyberattack by the BianLian ransomware group that reportedly compromised nearly 7 GB of sensitive data — including financial records, health data, and personal information. A global nonprofit with dedicated IT resources still got

Carl B. Johnson Sep 09, 2026 5 min read
PayPal DocuSign Phishing

PayPal DocuSign Phishing: How This Combo Attack Works

Two Trusted Brands, One Devastating Scam In late 2024, security researchers at Avanan documented a surge in phishing campaigns that combined PayPal and DocuSign branding in a single attack chain. The attackers sent emails that appeared to come from DocuSign, notifying the recipient of a payment document waiting for their

Carl B. Johnson Sep 08, 2026 5 min read