Tag

Zero Trust Security

Zero trust security content examines the principle of never trusting and always verifying every user, device, and connection. Articles explore micro-segmentation, least-privilege access, continuous monitoring, and how organizations transition from perimeter-based defenses to zero trust models.

posts

Password Manager Benefits

Password Manager Benefits: Why Pros Never Go Without

In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade. That number hasn't budged much. I've worked incident response cases where a single reused password — a seven-character string an employee used on

Carl B. Johnson Aug 03, 2026 6 min read
Password Security

Password Security Best Practices That Actually Work

In 2024, the breach at Snowflake's customer environments didn't exploit some exotic zero-day vulnerability. Threat actors simply used stolen credentials — many of them passwords reused across services without multi-factor authentication. Over 165 organizations were impacted, including Ticketmaster and AT&T. The lesson was brutal and

Carl B. Johnson Jul 31, 2026 5 min read
Securing Remote Employees

Securing Remote Employees: What Actually Works in 2026

The Coffee Shop Breach That Cost $6.5 Million In 2024, a mid-size financial services firm discovered that a single remote employee working from a hotel lobby had their session token hijacked through a man-in-the-middle attack on the hotel's Wi-Fi. The threat actor used that access to move

Carl B. Johnson Jul 27, 2026 6 min read
Cybersecurity Definition

Cybersecurity Definition: What It Really Means in 2026

The Textbook Got It Wrong In 2023, MGM Resorts lost roughly $100 million after a threat actor social-engineered their IT help desk with a single phone call. The attackers didn't exploit a zero-day vulnerability. They didn't write custom malware. They just talked their way in. If

Carl B. Johnson Jul 26, 2026 5 min read
Ransomware Prevention

How to Prevent Ransomware: A Practical Defense Guide

A Single Click Cost One Hospital Chain $100 Million In 2024, Change Healthcare — one of the largest health payment processors in the U.S. — got hit with a ransomware attack that disrupted pharmacy operations across the entire country. UnitedHealth Group, its parent company, reported costs exceeding $870 million related to

Carl B. Johnson Jul 16, 2026 5 min read
Password Security

Password Security Best Practices That Stop Breaches

The 2024 Verizon Data Breach Investigations Report found that stolen credentials were involved in 77% of attacks against web applications. Let me restate that: more than three out of four web app breaches started with a compromised password. Despite billions spent on perimeter defenses, password security best practices remain the

Carl B. Johnson Jul 15, 2026 5 min read
Securing Employee Mobile Devices

Securing Employee Mobile Devices: A Practical Guide

The Breach That Started With a Single Phone In 2022, Uber suffered a devastating breach after a threat actor targeted an employee's mobile device with repeated multi-factor authentication push requests. The attacker combined social engineering with MFA fatigue, and one tap on a phone screen gave them access

Carl B. Johnson Jul 14, 2026 5 min read
Password Security Best Practices

Password Security Best Practices That Stop Breaches

The 10-Billion-Password Wake-Up Call In July 2024, a file called "RockYou2024" appeared on a popular hacking forum containing nearly 10 billion unique plaintext passwords compiled from decades of data breaches. It was the largest credential compilation ever leaked. Within weeks, threat actors were running those passwords against corporate

Carl B. Johnson Jul 12, 2026 5 min read