Tag

Zero Trust Architecture

Zero trust architecture posts dive into the technical frameworks and infrastructure designs that support zero trust implementations. Topics include identity-aware proxies, software-defined perimeters, network access control, policy engines, and integration with cloud and hybrid environments.

posts

Zero Trust Network Access

Zero Trust Network Access: What It Actually Takes

In 2023, the U.S. Marshals Service suffered a major breach when a threat actor compromised a system containing sensitive law enforcement data — personal information on investigative targets, internal processes, and more. The agency had traditional perimeter defenses in place. What they didn't have was a model that

Carl B. Johnson Oct 04, 2026 5 min read
Zero Trust Security Model

Zero Trust Security Model: Why Perimeters Are Dead

In January 2024, Microsoft disclosed that a Russian threat actor group known as Midnight Blizzard had accessed senior executive email accounts — not by exploiting some exotic zero-day, but by spray-attacking a legacy test account that lacked multi-factor authentication. One account. No MFA. That's all it took to breach

Carl B. Johnson Oct 03, 2026 5 min read
Remote Desktop Security Risks

Remote Desktop Security Risks Your Team Ignores Daily

3389: The Port That Keeps Giving — to Attackers In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as the single most common initial access vector in ransomware incidents reported to law enforcement. Not phishing. Not USB drives. RDP. And yet, in 2026, I still

Carl B. Johnson Sep 30, 2026 6 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

A $12.5 Billion Problem That Keeps Getting Worse The FBI's Internet Crime Complaint Center reported $12.5 billion in cybercrime losses for 2023 — a 22% jump from the prior year. And the trajectory hasn't slowed. If you're reading this in 2026 and still

Carl B. Johnson Sep 29, 2026 5 min read
Security in Cloud Computing

Security in Cloud Computing: What Goes Wrong in 2026

A Single Checkbox Left Unchecked Cost Them Everything In 2023, Toyota disclosed that a cloud misconfiguration had exposed the location data of 2.15 million customers for over a decade. Not a sophisticated zero-day exploit. Not a nation-state threat actor. A misconfigured cloud database left publicly accessible because someone didn&

Carl B. Johnson Sep 25, 2026 5 min read
Cybersecurity for Financial Services

Cybersecurity for Financial Services: A 2026 Guide

In 2023, a single MOVEit vulnerability gave threat actors access to data from over 2,500 organizations — and financial institutions were among the hardest hit. Banks, credit unions, wealth management firms, and insurance companies collectively reported hundreds of millions of compromised records. If you work in finance, you already know

Carl B. Johnson Aug 29, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What's Actually Exposed

In early 2024, Change Healthcare — one of the largest health payment processors in the United States — was brought to its knees by the ALPHV/BlackCat ransomware group. The initial entry point? A Citrix remote access portal without multi-factor authentication. That single vulnerability led to the exfiltration of data affecting roughly

Carl B. Johnson Aug 28, 2026 5 min read
Zero Trust Implementation

Zero Trust Implementation: A Practical Guide for 2026

In January 2024, Microsoft disclosed that a Russian state-sponsored threat actor — the group known as Midnight Blizzard — breached corporate email accounts by exploiting a legacy test tenant that lacked multi-factor authentication. Microsoft. One of the most well-resourced technology companies on the planet. If they can get caught with a gap

Carl B. Johnson Aug 23, 2026 6 min read
NIST Standards

NIST Standards: What They Actually Mean for Your Security

The Framework Nobody Reads But Everyone Claims to Follow I once walked into a mid-sized financial firm that proudly declared on their website they were "aligned with NIST standards." Thirty minutes into the assessment, I found admin passwords on sticky notes, no multi-factor authentication on critical systems, and

Carl B. Johnson Aug 18, 2026 6 min read
Remote Desktop Security Risks

Remote Desktop Security Risks: What Attackers See

In 2023, the FBI's Internet Crime Complaint Center flagged Remote Desktop Protocol (RDP) as one of the top three initial access vectors used in ransomware incidents. That wasn't a surprise to anyone who's worked an incident response engagement. I've personally investigated breaches

Carl B. Johnson Jul 26, 2026 5 min read