Tag

Zero Trust

Understand the Zero Trust security model, which operates on the principle of never trust, always verify. Posts cover Zero Trust architecture, identity verification, micro-segmentation, least-privilege access, and practical steps for implementing Zero Trust frameworks across enterprise environments.

posts

Shadow IT Risks

Shadow IT Risks: The Hidden Threat Draining Your Budget

A Marketing Team's Slack Alternative Cost Their Company $2.1 Million I once consulted for a mid-sized healthcare firm that suffered a data breach because three employees in the marketing department decided to use an unsanctioned project management tool. They uploaded patient-adjacent data to a platform with zero

Carl B. Johnson Sep 28, 2026 5 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In 2024, Ivanti disclosed critical vulnerabilities in its VPN appliances — CVE-2024-21887 and CVE-2023-46805 — that were actively exploited by threat actors before patches were available. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. That's not a drill. That's your VPN

Carl B. Johnson Sep 24, 2026 5 min read
Computer Security Security

Computer Security Security: Why One Layer Is Never Enough

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to their help desk. The attackers didn't exploit some exotic zero-day. They bypassed one security control — identity verification — and the dominoes fell. That incident is a masterclass

Carl B. Johnson Sep 23, 2026 5 min read
Insider Threat Awareness

Insider Threat Awareness: What Most Companies Miss

The Threat Already Inside Your Building In 2022, a former Twitter employee was convicted of spying on behalf of Saudi Arabia, accessing the personal data of thousands of users — including dissidents — using nothing more than his legitimate employee credentials. No malware. No phishing email. Just a trusted insider with access

Carl B. Johnson Sep 21, 2026 5 min read
Man in the Middle Attack

Man in the Middle Attack: How Hackers Steal Data

In January 2024, the FBI's Internet Crime Complaint Center flagged business email compromise — much of it powered by man in the middle attack techniques — as responsible for over $2.9 billion in adjusted losses during 2023 alone. That number isn't slowing down. I've investigated

Carl B. Johnson Sep 17, 2026 6 min read
Data Breach Examples 2026

Data Breach Examples 2026: Real Incidents and Lessons

We're barely halfway through 2026 and the breach disclosures are already piling up. From healthcare systems crippled by ransomware to credential theft campaigns that bypassed legacy MFA, the data breach examples of 2026 reinforce a pattern I've tracked for over a decade: organizations keep making the

Carl B. Johnson Sep 15, 2026 5 min read
Physical Security and Cybersecurity

Physical Security and Cybersecurity: Why You Need Both

In 2023, a former employee of a New Jersey healthcare provider walked into an unlocked office, plugged a USB device into an unattended workstation, and exfiltrated over 20,000 patient records before anyone noticed. No firewall stopped it. No intrusion detection system flagged it. The breach happened because a physical

Carl B. Johnson Sep 14, 2026 5 min read
SaaS Security

SaaS Security Best Practices Your Team Is Ignoring

The Breach That Started With a Forgotten SaaS App In 2023, a Salesforce misconfiguration exposed sensitive data at multiple government agencies and financial institutions. The root cause wasn't sophisticated malware or a zero-day exploit. It was a permissions setting that nobody reviewed after initial deployment. That single oversight

Carl B. Johnson Sep 04, 2026 6 min read