Tag

Security Culture

Explore strategies for building and sustaining a strong security culture within organizations. These articles cover leadership engagement, employee behavior change, security awareness program design, and practical methods for making cybersecurity a shared responsibility across every department.

posts

Cybersecurity Training

How to Train Employees on Cybersecurity in 2026

The Breach That Started With a Single Click In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered an IT help desk employee with a phone call that lasted about ten minutes. The attacker didn't exploit a zero-day vulnerability. They didn&

Carl B. Johnson Apr 11, 2026 5 min read
Security Awareness Training

How to Measure Security Awareness Training Effectively

Your Training Program Is Worthless Without Proof In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to the help desk. The company almost certainly had a security awareness program in place. So did Caesars Entertainment, which paid a

Carl B. Johnson Oct 02, 2020 7 min read
Security Awareness Training

How to Measure Security Awareness Training ROI

Your Training Program Might Be Failing — and You'd Never Know In 2024, IBM's Cost of a Data Breach Report pegged the global average breach cost at $4.88 million. Organizations with security awareness training and incident response planning cut that number dramatically. But here's

Carl B. Johnson Sep 01, 2019 8 min read
Cybersecurity Gamification Training

Cybersecurity Gamification Training That Actually Works

A 45-Minute Training Video Nobody Watched In 2023, a mid-size healthcare company I consulted for spent $60,000 on a compliance-focused security awareness program. It featured a 45-minute narrated slideshow, a 10-question quiz, and a certificate of completion. Their post-training phishing simulation results? A 31% click rate — virtually unchanged from

Carl B. Johnson Sep 01, 2019 7 min read