Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions. First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had. Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings. These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow. We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes. Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords. By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.