Tag

Security Awareness

Develop a strong security mindset with articles focused on security awareness principles, social engineering defense, safe browsing habits, password hygiene, and recognizing manipulation tactics used by attackers targeting human vulnerabilities.

posts

Vishing Scam Awareness

Vishing Scam Awareness: Stop Voice Phishing Now

The Phone Call That Cost MGM Resorts $100 Million In September 2023, a threat actor called MGM Resorts' IT help desk, impersonated an employee found on LinkedIn, and convinced a technician to reset credentials. That single vishing call — a voice phishing attack — triggered a ransomware event that shut down

Carl B. Johnson Oct 03, 2026 5 min read
Phishing Definition

Phishing Definition: What It Really Means in 2026

In 2024, the FBI's Internet Crime Complaint Center received over 298,000 phishing complaints — making it the most reported cybercrime for the fifth consecutive year. Yet when I ask executives to give me a phishing definition, most of them still say something like "those fake emails from

Carl B. Johnson Oct 02, 2026 5 min read
Computer Security Companies

Computer Security Companies: What They Won't Tell You

The Billion-Dollar Blind Spot in Cybersecurity Spending In 2024, global cybersecurity spending surpassed $215 billion. Organizations bought firewalls, endpoint detection, SIEM platforms, and managed services from every major vendor on the planet. And breaches still hit record numbers. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches

Carl B. Johnson Oct 02, 2026 5 min read
Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

A Marketing Team's Slack Alternative Cost Their Company $2.1 Million I once consulted for a mid-sized healthcare firm that suffered a data breach because three employees in the marketing department decided to use an unsanctioned project management tool. They uploaded patient-adjacent data to a platform with zero

Carl B. Johnson Sep 28, 2026 5 min read
Cyber Hygiene Checklist

Cyber Hygiene Checklist: 12 Steps That Actually Work

The Breach That Started With an Unpatched Laptop In 2023, the MOVEit Transfer vulnerability (CVE-2023-34362) was exploited by the Cl0p ransomware group to compromise over 2,500 organizations worldwide. The root cause wasn't some exotic zero-day that no one could have predicted — it was a known vulnerability with

Carl B. Johnson Sep 26, 2026 5 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In 2024, Ivanti disclosed critical vulnerabilities in its VPN appliances — CVE-2024-21887 and CVE-2023-46805 — that were actively exploited by threat actors before patches were available. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. That's not a drill. That's your VPN

Carl B. Johnson Sep 24, 2026 5 min read
Cybersecurity Due Diligence

Cybersecurity Due Diligence: What Most Companies Miss

In 2017, Verizon knocked $350 million off its acquisition price of Yahoo after discovering the company had suffered two massive data breaches affecting over three billion accounts. That's not a rounding error. That's what happens when cybersecurity due diligence gets treated as a last-minute checkbox instead

Carl B. Johnson Sep 21, 2026 5 min read
NIST Standards

NIST Standards: A Practical Guide for Real Security

In 2023, MGM Resorts lost roughly $100 million to a ransomware attack that started with a social engineering phone call. The attackers didn't exploit some exotic zero-day. They called a help desk, impersonated an employee, and got credentials reset. MGM had security tools. What they lacked was a

Carl B. Johnson Sep 19, 2026 5 min read