Tag

Zero Trust Architecture

Zero trust architecture posts dive into the technical frameworks and infrastructure designs that support zero trust implementations. Topics include identity-aware proxies, software-defined perimeters, network access control, policy engines, and integration with cloud and hybrid environments.

posts

Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

The Framework Nobody Reads But Everyone Claims to Follow I once walked into a mid-sized financial firm that proudly declared on their website they were "aligned with NIST standards." Thirty minutes into the assessment, I found admin passwords on sticky notes, no multi-factor authentication on critical systems, and

Carl B. Johnson Aug 18, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read
Cloud Security Best Practices

Cloud Security Best Practices That Actually Stop Breaches

The Misconfiguration That Exposed 100 Million Records In 2019, a former cloud engineer exploited a misconfigured web application firewall at Capital One and accessed over 100 million customer records stored in AWS S3 buckets. The breach cost the company over $270 million in settlements and remediation. It wasn't

Carl B. Johnson Jul 25, 2026 6 min read
Security in Cloud Computing

Security in Cloud Computing: What Goes Wrong in 2026

A Single Checkbox Left 540 Million Facebook Records Exposed Back in 2019, researchers at UpGuard discovered that two third-party Facebook app developers had stored more than 540 million user records on Amazon S3 buckets with no access restrictions. Not encrypted. Not firewalled. Just sitting there, publicly readable, because someone didn&

Carl B. Johnson Jul 09, 2026 6 min read
Zero Trust Network Access

Zero Trust Network Access: A Practical Guide for 2026

The Breach That Proved Firewalls Aren't Enough In 2023, MGM Resorts lost an estimated $100 million after a threat actor used social engineering — a single phone call to the help desk — to bypass perimeter defenses and move laterally through internal systems. The attackers didn't need to

Carl B. Johnson Jun 30, 2026 6 min read
Security in Cloud Computing

Security in Cloud Computing: What Goes Wrong First

Capital One Lost 100 Million Records — The Cloud Wasn't the Problem In 2019, a former AWS employee exploited a misconfigured web application firewall and exfiltrated over 100 million Capital One customer records. The cloud infrastructure worked exactly as designed. The humans configuring it didn't. That breach

Carl B. Johnson Jun 27, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeter Defense Is Dead

The Breach That Proved "Trust But Verify" Was a Lie In 2020, a threat actor compromised SolarWinds' Orion software update mechanism and silently infiltrated over 18,000 organizations — including multiple U.S. federal agencies and Fortune 500 companies. The attackers didn't blast through firewalls. They

Carl B. Johnson Jun 25, 2026 6 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

A $4.88 Million Average — and a Framework Most Organizations Ignore IBM's 2024 Cost of a Data Breach Report pegged the global average at $4.88 million per incident. That's a record. Yet when I ask mid-size companies whether they've implemented any NIST standards,

Carl B. Johnson Jun 24, 2026 5 min read
BYOD Security Risks

BYOD Security Risks: What Your Policy Is Missing

In 2023, a single employee's personal phone led to one of the most damaging casino breaches in history. Threat actors used social engineering to compromise MGM Resorts, and the attack vector started with a device the company didn't fully control. The resulting disruption cost MGM over

Carl B. Johnson Jun 08, 2026 5 min read