Tag

Zero Trust Security

Zero trust security content examines the principle of never trusting and always verifying every user, device, and connection. Articles explore micro-segmentation, least-privilege access, continuous monitoring, and how organizations transition from perimeter-based defenses to zero trust models.

posts

Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

The Phone Call That Cost One Company $25 Million In early 2024, a finance worker at engineering firm Arup was tricked into transferring $25 million after a video call with what appeared to be the company's CFO. Every person on that call was a deepfake. The attackers never

Carl B. Johnson Sep 08, 2026 5 min read
Insider Threat Examples

Insider Threat Examples: Real Breaches That Cost Millions

In 2022, a former Amazon engineer named Paige Thompson was convicted for the Capital One breach that exposed over 100 million customer records. She wasn't an outside hacker who cracked through a firewall. She was an insider — someone with knowledge of the cloud infrastructure who exploited a misconfigured

Carl B. Johnson Sep 07, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

In 2023, MGM Resorts had a multi-billion dollar security stack — endpoint detection, firewalls, SIEM platforms, the works. A single social engineering phone call bypassed all of it. The attackers impersonated an employee, convinced the IT help desk to reset credentials, and caused an estimated $100 million in damages. If you

Carl B. Johnson Sep 04, 2026 5 min read
Cyber Security

Cyber Security in 2026: What Actually Stops Breaches

In 2024, the average cost of a data breach hit $4.88 million globally, according to IBM's Cost of a Data Breach Report. That number hasn't gone down. If you're responsible for cyber security at any level — whether you're a CISO, an

Carl B. Johnson Sep 02, 2026 5 min read
Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider called MGM Resorts' IT help desk, impersonated an employee, and gained access to internal systems. The result? Over $100 million in losses, days of disrupted operations, and a data breach affecting millions of

Carl B. Johnson Aug 31, 2026 5 min read
Multi-Factor Authentication

Multi-Factor Authentication Setup: A Practical Guide

In March 2024, a threat actor breached a major healthcare provider's network using a single compromised password — no second factor required. The organization had purchased MFA licenses two years prior but never enforced enrollment. That gap cost them months of remediation and exposed the records of over 100,

Carl B. Johnson Aug 30, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States. The root cause? Compromised credentials on a remote access system that lacked multi-factor authentication. One account. No MFA. Billions of dollars in damage. I&

Carl B. Johnson Aug 24, 2026 5 min read