Tag

Zero Trust

Understand the Zero Trust security model, which operates on the principle of never trust, always verify. Posts cover Zero Trust architecture, identity verification, micro-segmentation, least-privilege access, and practical steps for implementing Zero Trust frameworks across enterprise environments.

posts

Acceptable Use Policy

Acceptable Use Policy Cybersecurity: Why Yours Fails

The Policy Everyone Signs and Nobody Reads In 2023, a single employee at a major casino operator plugged a personal USB device into a workstation. That device carried malware. Within hours, threat actors had lateral movement across the network. The resulting breach cost over $100 million in damages, downtime, and

Carl B. Johnson Jul 30, 2026 6 min read
Password Hygiene Tips

Password Hygiene Tips That Actually Stop Breaches

The Breach That Started With "Summer2024!" In 2024, the Verizon Data Breach Investigations Report found that stolen credentials were involved in roughly 31% of all breaches over the prior decade — and that number hasn't meaningfully dropped. I've personally investigated incidents where an entire corporate

Carl B. Johnson Jul 22, 2026 5 min read
Work From Home Cybersecurity

Work From Home Cybersecurity: A Practical Guide

The $20 Million Breach That Started on a Home Wi-Fi Network In 2024, a healthcare company disclosed a breach that exposed 11 million patient records. The root cause? A remote employee connected to an unsecured home network, clicked a phishing link, and handed over VPN credentials to a threat actor.

Carl B. Johnson Jul 19, 2026 5 min read
Cybersecurity Terms Explained

Cybersecurity Terms Explained: A Practical Guide

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to a help desk. The attackers didn't exploit some exotic zero-day vulnerability. They used techniques that anyone familiar with basic cybersecurity terminology would recognize — vishing, credential theft,

Carl B. Johnson Jul 18, 2026 5 min read
Cybersecurity Policy for Employees

Cybersecurity Policy for Employees: A Practical Guide

In 2023, MGM Resorts lost an estimated $100 million after a threat actor social-engineered a help desk employee with a ten-minute phone call. The attacker didn't exploit a zero-day vulnerability. They exploited a gap in employee policy — specifically, the identity verification process for password resets. A strong cybersecurity

Carl B. Johnson Jul 05, 2026 5 min read
VPN Best Practices

VPN Best Practices: What Actually Protects You in 2026

In early 2024, Ivanti disclosed critical vulnerabilities in its Connect Secure VPN that were already being actively exploited by threat actors — including nation-state groups. CISA issued an emergency directive ordering federal agencies to disconnect affected devices within 48 hours. If that doesn't make you rethink your VPN best

Carl B. Johnson Jul 05, 2026 5 min read
Zero Trust

What Is Zero Trust? A Practical Guide for 2026

The Breach That Made "Trust" a Dirty Word In 2020, the SolarWinds breach gave threat actors access to the internal networks of at least nine U.S. federal agencies and over 100 private companies. The attackers moved laterally for months — undetected — because once they were inside the network

Carl B. Johnson Jul 03, 2026 5 min read