Tag

Security Awareness

Develop a strong security mindset with articles focused on security awareness principles, social engineering defense, safe browsing habits, password hygiene, and recognizing manipulation tactics used by attackers targeting human vulnerabilities.

posts

Cyber Hygiene Checklist

Cyber Hygiene Checklist: 12 Steps That Actually Work

In March 2023, the FBI's Internet Crime Complaint Center reported that Americans lost over $10.3 billion to cybercrime in 2022 — a 49% increase from the year before. The uncomfortable truth? Most of those losses trace back to failures in basic security practices, not sophisticated zero-day exploits. A

Carl B. Johnson Jun 08, 2023 7 min read
Vendor Risk Management

Vendor Risk Management Cybersecurity: A Practical Guide

The Breach That Didn't Start With You In January 2023, Mailchimp disclosed its second breach in under a year — this time through a social engineering attack on an employee. But the real damage radiated outward. Every company using Mailchimp as a vendor suddenly had a problem they didn&

Carl B. Johnson Jun 08, 2023 7 min read
Cybersecurity Glossary

Cybersecurity Glossary for Beginners: 40 Terms to Know

A hospital employee clicked a link in what looked like a routine password reset email. Within 72 hours, CommonSpirit Health — one of the largest U.S. health systems — was battling a ransomware attack that disrupted operations at over 140 facilities. The investigation report cited "lack of basic security awareness&

Carl B. Johnson Apr 23, 2023 7 min read
Adware vs Spyware

Adware vs Spyware: What's Actually Stealing Your Data

In February 2023, the FBI's Internet Crime Complaint Center reported that malware-related complaints had surged again, with losses running into the hundreds of millions. Buried in those numbers is a distinction most people get wrong: adware vs spyware. I've watched organizations treat adware as a minor

Carl B. Johnson Apr 10, 2023 6 min read
SQL Injection

SQL Injection Explained: The Attack That Won't Die

A 20-Year-Old Attack Still Dominating the Headlines In late 2022, the FBI and CISA issued a joint advisory warning about ongoing exploitation of a SQL injection vulnerability in a widely used healthcare software platform. The flaw had been known for years. The patches existed. And yet, threat actors kept walking

Carl B. Johnson Jan 09, 2023 7 min read
Phishing Definition

Phishing Definition: What It Really Means in 2022

Twilio, a company with a sophisticated security team and a tech-savvy workforce, got phished in August 2022. Attackers sent SMS messages to employees pretending to be the IT department, directing them to a fake login page. The result: compromised credentials, unauthorized access to customer data, and a breach that rippled

Carl B. Johnson Nov 21, 2022 6 min read
Spoofing Caller

Spoofing Caller Attacks: How Hackers Steal Trust

In March 2022, the FBI warned that threat actors were spoofing caller IDs of financial institutions and government agencies to steal millions from unsuspecting victims. The Bureau's Internet Crime Complaint Center (IC3) received over 18,000 complaints related to spoofing in 2021 alone, with adjusted losses exceeding $82

Carl B. Johnson Sep 04, 2022 6 min read