Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Cybersecurity for Financial Services

Cybersecurity for Financial Services: A 2026 Guide

In 2023, a single MOVEit vulnerability gave threat actors access to data from over 2,500 organizations — and financial institutions were among the hardest hit. Banks, credit unions, wealth management firms, and insurance companies collectively reported hundreds of millions of compromised records. If you work in finance, you already know

Carl B. Johnson Aug 29, 2026 6 min read
Cyber Incident Reporting

How to Report a Cyber Incident: A Step-by-Step Guide

In 2023, the FBI's Internet Crime Complaint Center received over 880,000 complaints with potential losses exceeding $12.5 billion — a 22% increase in losses over the previous year. And those are just the incidents that were actually reported. In my experience, for every cyber incident that gets

Carl B. Johnson Aug 29, 2026 5 min read
Phishing

Define Phishing: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime category for the fifth consecutive year. Despite billions spent on security tools, phishing remains the number one way threat actors break into organizations. So let's actually

Carl B. Johnson Aug 29, 2026 5 min read
Mobile Phishing Attacks

Mobile Phishing Attacks: Why Your Phone Is Now #1 Target

82% of Phishing Sites Now Target Mobile Devices In 2024, Zimperium's Global Mobile Threat Report found that 82% of phishing sites specifically targeted mobile devices. That number didn't surprise me. What surprised me was how many security teams I spoke with still treated mobile phishing attacks

Carl B. Johnson Aug 27, 2026 6 min read
SaaS Security Best Practices

SaaS Security Best Practices to Protect Your Stack

The Average Company Uses 130 SaaS Apps — And Secures Maybe Half When I audited a mid-size financial services firm last year, they believed they had about 40 SaaS applications in production. The real number was 187. Over half were adopted by individual departments without IT's knowledge. Three of

Carl B. Johnson Aug 27, 2026 5 min read
Whaling Attack Cybersecurity

Whaling Attack Cybersecurity: How Execs Get Targeted

The CEO Who Wired $47 Million to a Stranger In 2016, FACC, an Austrian aerospace parts manufacturer, lost €42 million (roughly $47 million) after a threat actor impersonated the company's CEO via email and instructed an employee to wire funds for a fake acquisition project. The CEO and

Carl B. Johnson Aug 26, 2026 6 min read
Phishing Emails

How to Spot Phishing Emails Before They Cost You

In 2023, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — more than any other cybercrime category. That number has only climbed since. I've investigated breaches at organizations of every size, and the entry point is almost always the same: one employee who

Carl B. Johnson Aug 25, 2026 6 min read
Phishing Attack

Phishing Attack Anatomy: How Breaches Actually Start

In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past the help desk with a single phone call. But that attack started the way most do — with a phishing attack that gathered the intelligence needed to make that call convincing.

Carl B. Johnson Aug 24, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States. The root cause? Compromised credentials on a remote access system that lacked multi-factor authentication. One account. No MFA. Billions of dollars in damage. I&

Carl B. Johnson Aug 24, 2026 5 min read