Tag

Zero Trust Security

Zero trust security content examines the principle of never trusting and always verifying every user, device, and connection. Articles explore micro-segmentation, least-privilege access, continuous monitoring, and how organizations transition from perimeter-based defenses to zero trust models.

posts

Computer Security Advice

Computer Security Advice That Actually Stops Breaches

The Breach That Started With a Single Reused Password In 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations across the entire United States. The root cause? Compromised credentials on a remote access system that lacked multi-factor authentication. One account. No MFA. Billions of dollars in damage. I&

Carl B. Johnson Aug 24, 2026 5 min read
Cybersecurity Best Practices

Cybersecurity Best Practices for Employees in 2026

One Click Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts employee through a simple phone call to the IT help desk. That single conversation — not a sophisticated zero-day exploit, not a nation-state attack — led to a ransomware incident that shut

Carl B. Johnson Aug 23, 2026 5 min read
Computer Security Software

Computer Security Software: What Actually Stops Breaches

A $100,000 Antivirus Setup That Stopped Nothing I worked with an organization in 2024 that had invested heavily in computer security software — endpoint detection, next-gen firewalls, SIEM, the works. They still got hit with a ransomware attack that encrypted 14,000 files and shut down operations for nine days.

Carl B. Johnson Aug 21, 2026 5 min read
Social Engineering Attacks

Social Engineering Attacks: How They Actually Work

In September 2023, a threat actor called Scattered Spider social-engineered their way into MGM Resorts by calling the company's IT help desk. One phone call. That's all it took to trigger a shutdown that cost MGM an estimated $100 million. No zero-day exploit. No sophisticated malware.

Carl B. Johnson Aug 19, 2026 5 min read
Cybersecurity Tips

Cybersecurity Tips That Actually Stop Breaches in 2026

A single employee at MGM Resorts answered a phone call from someone pretending to be a coworker. That one social engineering attack in September 2023 led to roughly $100 million in losses, a crippled reservation system, and slot machines going dark across Las Vegas. The attacker didn't exploit

Carl B. Johnson Aug 09, 2026 5 min read
Computer Security Advice

Computer Security Advice That Actually Works in 2026

A school district in Arizona lost $3.5 million in January 2024 after a single employee followed spoofed wire transfer instructions. The attacker didn't exploit a software vulnerability. They exploited trust. That incident captures why most computer security advice fails — it focuses on tools while ignoring the human

Carl B. Johnson Aug 07, 2026 5 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Spring2024!" In 2023, a Verizon Data Breach Investigations Report finding shook the industry: roughly 49% of breaches involved stolen credentials. Not sophisticated zero-day exploits. Not nation-state malware. Passwords. Reused, predictable, phishable passwords. I've responded to incidents where the root cause was

Carl B. Johnson Aug 06, 2026 5 min read
Cybersecurity

Cybersecurity in 2026: What Actually Works Now

The Breach That Changed How I Think About Cybersecurity In February 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations and medical claims processing across the entire United States. UnitedHealth Group later confirmed that roughly one-third of all Americans may have had their data exposed. The attack vector?

Carl B. Johnson Aug 05, 2026 6 min read