Tag

Security Awareness

Develop a strong security mindset with articles focused on security awareness principles, social engineering defense, safe browsing habits, password hygiene, and recognizing manipulation tactics used by attackers targeting human vulnerabilities.

posts

Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts employee through a simple phone call to the IT help desk. That single conversation — not a sophisticated zero-day exploit, not a nation-state attack — led to a ransomware incident that shut

Carl B. Johnson Aug 23, 2026 5 min read
Cyber Incident Response Steps

Cyber Incident Response Steps That Actually Work

A Ransomware Attack Exposed What Most Plans Are Missing In February 2024, Change Healthcare suffered a ransomware attack that disrupted prescription processing for millions of Americans. UnitedHealth Group later confirmed the breach affected approximately 100 million individuals — the largest healthcare data breach in U.S. history. The attackers got in

Carl B. Johnson Aug 21, 2026 5 min read
Fake Email

Fake Email: How to Spot One Before It Costs You

In 2019, a Lithuanian man named Evaldas Rimasauskas pleaded guilty to stealing over $100 million from Google and Facebook — using nothing more than a series of fake email messages. He impersonated a legitimate hardware vendor, sent invoices from spoofed email addresses, and two of the most sophisticated tech companies on

Carl B. Johnson Aug 19, 2026 6 min read
Fake Identity Website

Fake Identity Website Scams: How to Spot Them Fast

A Single Fake Identity Website Fueled a $10 Million Fraud Ring In 2023, the FBI dismantled an identity fraud operation that relied heavily on fake identity websites — convincing portals designed to harvest personal data from unsuspecting victims. The ring used stolen credentials to open bank accounts, file fraudulent tax returns,

Carl B. Johnson Aug 17, 2026 5 min read
Cost of a Data Breach 2026

Cost of a Data Breach 2026: What the Numbers Mean

The Bill Nobody Plans For IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88 million — a 10% jump from the prior year and the highest figure ever recorded. That number has only continued climbing. When I talk to business owners about the

Carl B. Johnson Aug 16, 2026 5 min read
Adware vs Spyware

Adware vs Spyware: What Security Teams Must Know

In 2023, a small accounting firm in Ohio discovered that a browser toolbar one employee installed — what looked like a harmless coupon finder — had been silently logging keystrokes and exfiltrating client tax records for eleven months. The toolbar was adware on the surface. Underneath, it was spyware. And the firm

Carl B. Johnson Aug 13, 2026 6 min read
Data Breach Notification

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of roughly 100 million Americans. The fallout wasn't just technical — it was a regulatory nightmare. State attorneys general demanded answers. Congressional hearings followed. And organizations downstream from the breach scrambled to figure out

Carl B. Johnson Aug 12, 2026 6 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: What You Owe

23andMe Proved That Getting Breached Is Bad — But Notifying Wrong Is Worse In late 2023, 23andMe disclosed a breach affecting nearly 7 million users. The breach itself was devastating. But the company's notification missteps — delayed disclosures, shifting blame to users, and inconsistent communications across jurisdictions — turned a security

Carl B. Johnson Aug 11, 2026 6 min read
Cyber Hygiene

Cyber Hygiene Definition: What It Really Means in 2026

A Hospital Paid $475,000 Because Someone Skipped the Basics In 2023, the U.S. Department of Health and Human Services settled with a healthcare provider for $475,000 after a phishing attack exposed patient records. The root cause wasn't a sophisticated zero-day exploit. It was a lack

Carl B. Johnson Aug 09, 2026 5 min read