Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

FTC Cybersecurity Requirements

FTC Cybersecurity Requirements for Businesses in 2026

The FTC Just Fined a Company $1.5 Million — Because They Skipped the Basics In 2023, the FTC settled with Chegg for $3.5 million after four separate data breaches exposed tens of millions of customer records. Employees had been sharing login credentials. Sensitive data sat in plain text. Multi-factor

Carl B. Johnson Jul 31, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Email Phishing Red Flags

Email Phishing Red Flags: 9 Signs You're Being Targeted

The Email That Cost One Company $37 Million In 2024, a single phishing email led to a business email compromise attack against Orion SA, a Luxembourg-based metals trading company, resulting in a $60 million wire transfer to threat actor-controlled accounts. The company later recovered roughly $23 million. The email looked

Carl B. Johnson Jul 31, 2026 5 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on cybersecurity tools, a single deceptive email still opens the door to catastrophic breaches. If you've ever

Carl B. Johnson Jul 30, 2026 5 min read
Acceptable Use Policy

Acceptable Use Policy Cybersecurity: Why Yours Fails

The Policy Everyone Signs and Nobody Reads In 2023, a single employee at a major casino operator plugged a personal USB device into a workstation. That device carried malware. Within hours, threat actors had lateral movement across the network. The resulting breach cost over $100 million in damages, downtime, and

Carl B. Johnson Jul 30, 2026 6 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Cold

In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints related to phishing and its variants — including vishing — resulting in losses exceeding $18.7 billion across all reported cybercrime categories. Voice phishing, or vishing, is one of the fastest-growing attack vectors because it bypasses

Carl B. Johnson Jul 30, 2026 5 min read
Phishing

What Is a Phishing Attack? A Security Pro Explains

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. I've investigated dozens of breaches that started with a single deceptive email. So when someone asks me what is a

Carl B. Johnson Jul 29, 2026 6 min read
Phishing Scams

Phishing Scams: What Actually Works to Stop Them

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 complaints about phishing scams — making it the most reported cybercrime category for the fifth consecutive year. The real number is almost certainly higher, because most incidents never get reported. I've spent years helping organizations

Carl B. Johnson Jul 29, 2026 5 min read