Tag

Zero Trust Security

Zero trust security content examines the principle of never trusting and always verifying every user, device, and connection. Articles explore micro-segmentation, least-privilege access, continuous monitoring, and how organizations transition from perimeter-based defenses to zero trust models.

posts

Computer Security Companies

Computer Security Companies: What They Won't Tell You

The Billion-Dollar Blind Spot in Cybersecurity Spending In 2024, global cybersecurity spending surpassed $215 billion. Organizations bought firewalls, endpoint detection, SIEM platforms, and managed services from every major vendor on the planet. And breaches still hit record numbers. The Verizon 2024 Data Breach Investigations Report found that 68% of breaches

Carl B. Johnson Oct 02, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

Your Computer Security Software Didn't Stop the Breach In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that bypassed every piece of computer security software the company had deployed. The threat actors didn't hack through a firewall. They called the help

Carl B. Johnson Sep 30, 2026 6 min read
Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Password In 2023, MGM Resorts lost an estimated $100 million after a threat actor called Scattered Spider social-engineered their way past a help desk using nothing more than a phone call and a LinkedIn profile. No zero-day exploit. No advanced malware. Just a

Carl B. Johnson Sep 29, 2026 5 min read
NIST Cybersecurity Framework

NIST Cybersecurity Framework: A Practical Guide for 2026

The Framework 80% of Organizations Reference — But Few Actually Implement When Change Healthcare suffered its catastrophic ransomware attack in early 2024, disrupting pharmacy operations for millions of Americans, the post-incident analysis pointed to gaps that the NIST Cybersecurity Framework was specifically designed to prevent. Missing multi-factor authentication on a critical

Carl B. Johnson Sep 27, 2026 6 min read
Cyber Hygiene Checklist

Cyber Hygiene Checklist: 12 Steps That Actually Work

The Breach That Started With an Unpatched Laptop In 2023, the MOVEit Transfer vulnerability (CVE-2023-34362) was exploited by the Cl0p ransomware group to compromise over 2,500 organizations worldwide. The root cause wasn't some exotic zero-day that no one could have predicted — it was a known vulnerability with

Carl B. Johnson Sep 26, 2026 5 min read
Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

In 2023, a mid-size healthcare company discovered that an employee had been syncing patient records to a personal Dropbox account for two years. The data breach affected over 30,000 patients and triggered a HIPAA investigation. The employee wasn't malicious — they just wanted an easier way to work

Carl B. Johnson Sep 23, 2026 5 min read
NIST Standards

NIST Standards: A Practical Guide for Real Security

In 2023, MGM Resorts lost roughly $100 million to a ransomware attack that started with a social engineering phone call. The attackers didn't exploit some exotic zero-day. They called a help desk, impersonated an employee, and got credentials reset. MGM had security tools. What they lacked was a

Carl B. Johnson Sep 19, 2026 5 min read
Phishing Training for Employees

Phishing Training for Employees: What Actually Works

One Click Cost This Company $47 Million In 2023, Clorox disclosed a cybersecurity incident that disrupted operations for months and cost the company an estimated $49 million in recovery expenses. The attack reportedly began with social engineering — a threat actor tricking someone into giving up access. That's not

Carl B. Johnson Sep 14, 2026 6 min read