Tag

Security Awareness Training

Discover resources and strategies for building effective security awareness training programs. Posts cover curriculum design, engagement techniques, compliance requirements, and methods for measuring training impact to reduce human-related security incidents across organizations.

posts

Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware.

Carl B. Johnson Aug 19, 2026 5 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

The Framework Nobody Reads But Everyone Claims to Follow I once walked into a mid-sized financial firm that proudly declared on their website they were "aligned with NIST standards." Thirty minutes into the assessment, I found admin passwords on sticky notes, no multi-factor authentication on critical systems, and

Carl B. Johnson Aug 18, 2026 6 min read
Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

A Single Phone Call Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That one vishing call triggered a ransomware attack that shut down slot machines, hotel key

Carl B. Johnson Aug 18, 2026 5 min read
Spear Phishing

Spear Phishing: Why Targeted Attacks Beat Defenses

In 2023, MGM Resorts lost roughly $100 million after a threat actor called Scattered Spider impersonated an employee on a help desk call — a textbook spear phishing technique that bypassed every technical control the company had. The attacker didn't blast out a million generic emails. They researched one

Carl B. Johnson Aug 17, 2026 5 min read
Stolen Credentials Dark Web

Stolen Credentials Dark Web: How Your Logins Get Sold

In 2024, the FBI's Internet Crime Complaint Center (IC3) reported that compromised credentials were a factor in a staggering number of the complaints they received, driving billions of dollars in losses. I've personally worked incident response cases where a single set of stolen credentials — purchased on

Carl B. Johnson Aug 17, 2026 5 min read
Data Breach Examples 2026

Data Breach Examples 2026: Lessons from Real Attacks

We're barely halfway through 2026, and the breach disclosures are already stacking up at a pace that should alarm every executive, IT director, and business owner reading this. If you're searching for data breach examples 2026, you're probably trying to figure out what'

Carl B. Johnson Aug 16, 2026 5 min read
Phishing

What Is Phishing? A Security Pro's Real-World Guide

A Single Email Cost This Company $100 Million In 2019, Toyota Boshoku Corporation lost $37 million to a single business email compromise attack. A threat actor impersonated a senior executive and convinced a finance employee to change wire transfer details. The money vanished. That's phishing — not some abstract

Carl B. Johnson Aug 15, 2026 5 min read
Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Single Click Cost One Hospital Chain $100 Million In 2020, Universal Health Services — a Fortune 500 hospital operator — got hit by the Ryuk ransomware strain. The result: 400 facilities knocked offline, staff reverting to pen and paper, and an estimated $67 million in direct costs plus ongoing damages that

Carl B. Johnson Aug 15, 2026 5 min read