Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Password Security

Password Security Best Practices That Stop Breaches

The 2024 Verizon Data Breach Investigations Report found that stolen credentials were involved in 77% of attacks against web applications. Let me restate that: more than three out of four web app breaches started with a compromised password. Despite billions spent on perimeter defenses, password security best practices remain the

Carl B. Johnson Jul 15, 2026 5 min read
Strong Passwords

Strong Password Examples That Actually Stop Hackers

In 2023, a single reused password led to the MGM Resorts breach that cost the company over $100 million in damages. The threat actor didn't exploit a zero-day vulnerability or write custom malware. They called the help desk, social-engineered their way in, and leveraged weak credentials to move

Carl B. Johnson Jul 13, 2026 5 min read
Phishing Scams

Phishing Scams: What They Cost and How to Stop Them

The FBI Says Phishing Scams Are the #1 Cybercrime — And It's Not Even Close In 2023, the FBI's Internet Crime Complaint Center (IC3) received over 298,000 complaints about phishing scams — more than any other cybercrime category. That number has topped the charts for five consecutive

Carl B. Johnson Jul 13, 2026 6 min read
DNS Spoofing

DNS Spoofing Attack: How Hackers Redirect Your Traffic

A Bank's Customers Were Logging In — Just Not to the Real Bank In 2017, attackers hijacked DNS records for a major Brazilian bank, redirecting all of its online customers to perfectly cloned phishing sites for roughly five hours. Every login, every transaction, every credential — harvested in real time.

Carl B. Johnson Jul 13, 2026 5 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 10-Billion-Password Wake-Up Call In July 2024, a file called "RockYou2024" appeared on a popular hacking forum containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. It was the largest credential compilation ever leaked. Within weeks, threat actors were running those passwords against corporate

Carl B. Johnson Jul 12, 2026 5 min read
Cybersecurity for Healthcare

Cybersecurity for Healthcare Organizations: A 2026 Guide

The Hospital That Lost 133 Days to Ransomware In 2024, Change Healthcare suffered a ransomware attack that disrupted claims processing for thousands of hospitals, pharmacies, and clinics across the United States. UnitedHealth Group, its parent company, disclosed costs exceeding $870 million in the first quarter alone. Patient care was delayed.

Carl B. Johnson Jul 12, 2026 5 min read
Password Manager Benefits

Password Manager Benefits That Stop 80% of Breaches

One Reused Password Cost This Company $10 Million In 2024, the Snowflake customer breach wave compromised over 165 organizations — including Ticketmaster and AT&T — because attackers used stolen credentials harvested from infostealer malware. The common thread? Employees reusing passwords across personal and corporate accounts with no password manager in

Carl B. Johnson Jul 10, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Exposed 147 Million People — And a Broken Response When Equifax disclosed its 2017 breach, the technical failure got the headlines. But the real catastrophe was the response. Weeks of delay, a phishing-prone notification website, and executives who dumped stock before the public announcement. The company eventually paid

Carl B. Johnson Jul 09, 2026 5 min read