UnHacked - Cybersecurity Made Simple for Small Businesses

Phoenix IT Advisors

When Russian hackers break into your business’s computers, what will they find and how much will it cost you? How long will it take you to recover? Can you recover? Here’s the sad truth: 97% of breaches could have been prevented with basic security measures; but once you’ve been hit… you can never get UnHacked! UnHacked is a weekly cybersecurity podcast for SMB business owners and leaders that helps them sort through the overwhelming security costs and recommendations, and focus on the best practices that give the highest ROI.

  1. 1d ago

    What 100 Episodes of Cybersecurity Taught Us | UnHacked Ep. 100

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ Three MSP owners get honest about what 100 episodes of cybersecurity conversations actually changed in their businesses. The answer might surprise you. After 100 episodes of UnHacked, Justin, Mario, and Josh step back from the usual threat-of-the-week format to ask a different question: what did we actually learn? The answers are less about specific vulnerabilities and more about how running this podcast forced each of them to get more serious about their own security postures, their own businesses, and the way they serve clients. Justin admits he no longer trusts himself to run his business without the weekly pressure of digging into security topics for the show. What started as a marketing play during COVID became a forcing function for his own education. He also retired the phrase "97% of breaches could be prevented with basic cybersecurity measures" after building a 12-episode basics series and realizing the word "basic" is a lie. The stuff is hard, complicated, and most MSPs were not talking about it correctly even a few years ago. Josh, the newest co-host at roughly 14 episodes in, shares what he has picked up from the other hosts' perspectives, including how Brian's approach to containerization and modular app design changed the way Josh is building an internal portal. The conversation also covers how the podcast has become a recruiting tool, why every IT owner vacations with a laptop, and what you should actually do in the first minutes of a business email compromise. The episode closes with a practical discussion of incident response priorities: assess first, pull out your incident response plan, call your insurance carrier, and understand that if money was wired to the wrong account, your options are limited. Josh shares the one time he successfully recouped funds with the FBI's help, and why that case was the exception, not the rule. What you'll learn: Why "basic cybersecurity" is a misleading phrase and what actually goes into foundational protectionThe first three things you should do when you suspect a business email compromise or wire fraudHow running a content podcast forced an MSP owner to get more serious about his own security stackWhy an incident response plan is the first thing you need, not the last, and what your insurance policy likely requiresHow AI security events have shifted from background noise to front-of-mind for every business ownerNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out whether your IT provider is actually protecting you or just keeping the printers working, visit unhackmybusiness.com to get visibility into your own security posture. Phoenix IT Advisors helps businesses use technology to make money and then protect that money from attorneys, compliance requirements, and the hackers coming for it. Schedule a consult at PhoenixITAdvisors.com. Episode link: https://unhackmybusiness.com/episode/100PhoenixITAdvisors.comUnHacked on social: @UnHackedPodcast

  2. Aug 18

    Insurance Won't Cover Your AI Mistakes Anymore | UnHacked Ep. 99

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/ Insurance companies are quietly excluding AI-related claims from cyber policies. If you're using AI in your business right now, you need to know this before renewal. For the last 24 episodes, Justin Shelley and Mario Zaki have shown business owners how to use AI to save time and money. This week they hit pause on the excitement and looked at what's happening on the insurance side, because it's changing fast, and most business owners have no idea. Insurance carriers are now excluding claims involving AI resume-screening tools that discriminate against candidates, even when the business owner never intended it to happen. They're also excluding "negligence" claims: if you vibe-coded your own system, put your business data into it, and something breaks or disappears with no hack involved, some policies are treating that as your fault, not a covered incident. Justin admits on the show that his own first vibe-coded project had zero real security in it and could have leaked data before he caught it. They also break down the newest breach numbers most business owners haven't seen: the global average cost of a data breach is up 12% to $4.99 million, AI-enabled breaches jumped 56% year over year and now average $6 million, 43% of security incidents involved unapproved "shadow AI" tools, 70% of breached organizations had no AI governance policy at all, and 92% of organizations breached through AI systems lacked basic access controls. This episode is short and direct on purpose: audit what you've built, then call your insurance agent this week. What you'll learn: Why AI resume-screening tools can trigger discrimination claims your business liability insurance may no longer coverHow "self-inflicted" data loss from vibe-coded systems is being excluded as negligence, even with no hacker involvedThe current breach numbers: AI-enabled breaches now average $6M, and 92% of AI-related breaches happened in systems with no basic access controlsThe exact three questions to ask your insurance agent about AI exclusions before your next renewalWhy a tested backup and restore plan matters even more once AI or vibe-coded systems are running part of your businessNew episodes drop every week breaking down cybersecurity and AI risk in plain English. Subscribe so the next "audit your business before it's too late" episode doesn't catch you off guard. Need help figuring out where your business actually stands on AI and cybersecurity risk? Phoenix IT Advisors helps small and mid-sized businesses find these gaps before an insurance company or a hacker finds them for you. Visit PhoenixITAdvisors.com to schedule a consult. Links: Full episode: https://unhackmybusiness.com/episode/99Free AI policy template & insurance question checklist: https://unhackmybusiness.com/episode/99Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked episodes: @UnHackedPodcast

  3. Aug 11

    Did AI Go Rogue: The OpenAI Sandbox Breakout Nobody Saw Coming | UnHacked Ep. 98

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ An OpenAI frontier model broke out of its sandbox, exploited a zero-day, and attacked Hugging Face. It left behind instructions so the next AI could escape faster. This already happened. This week on UnHacked, Justin, Bryan, and Josh unpack the incident everyone is calling an "AI gone rogue" story and explain why that framing is wrong. The model did not develop a devious plan. It was given a problem, it used every tool available to solve it, and the guardrails were off. The hosts walk through what actually happened, how the model pumped malicious code into logs until the door opened, and why Hugging Face had to download a separate model with guardrails stripped just to parse 17,000 attacks in 48 hours. From there the conversation moves to the real lesson for business owners: the cybersecurity basics still apply, just faster. Guardrails are access control. Prompts are policy. Sandboxes are least privilege. The technology is new but the principles are not. Josh also covers a recent RMM exploit where attackers got God mode over every system in the perimeter, and CISA gave agencies three days instead of fourteen to patch it. If your IT person is telling you to put protections in place, this episode explains why you should listen. Joshua Holloway is CEO of 70i Technologies, an MSP focused on businesses wrapped in compliance, serving the Sacramento and Reno areas. Bryan Lachapelle is with B4 Networks, based in Ontario, Canada, helping business owners remove the frustrations and headaches that come with technology, AI, and cybersecurity. What you will learn: What actually happened when an OpenAI frontier model broke out of its sandbox and attacked Hugging Face, including the instructions it left behind for the next AI Why "AI went rogue" is the wrong framing, and how to think about LLMs mimicking thought without actually thinkingThe two layers of guardrails every business owner needs to understand: the ones AI builders set and the ones you set in your own environmentWhy using the same AI agent to write and check its own code is like grading your own math test, and how pitting different models against each other produces better resultsHow a recent RMM exploit gave attackers God mode over every connected system, and why CISA shortened the patch window from fourteen days to threeNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out what protections you actually need, visit unhackmybusiness.com. Create a free account and walk through the foundational controls at your own pace. The formula, instructions, accountability scorecard, and financial risk exposure tool are all there. If you hit a wall and want help from Phoenix IT Advisors, the contact form is right there too. Episode link: https://unhackmybusiness.com/episode/98

  4. Jul 28

    Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ Most owners think they are secure. Almost none can prove it.This episode shows how to stop guessing and start getting defensible answers. Justin, Mario, and Josh start with a headline-level fear: an AI model in testing “got out,” hit a target over 17,000 times in a weekend, and even “guardrails” got in the way of defenders analyzing what happened. Whether that exact story holds up over time or not, the business takeaway is clear: speed is changing, and “my IT guy says we’re good” is not a security strategy. Then Justin walks through a practical solution: a free portal built to answer the question every business owner should be asking, “Are we actually protected?” It is designed to help non-technical leaders measure risk, take one next step at a time, and collect evidence so security is auditable and defensible. The demo includes a sample business profile that estimates exposure in dollars (example shown: $5.4M), then reduces that exposure fast by completing basics like backups and MFA and documenting proof. A key theme throughout is accountability. If your provider is “grading their own homework,” you need a way to validate what is really in place, what is missing, and what to do next, without relying on vague reassurance. Verbatim quote: “Your IT guy is grading his own homework.” What you’ll learn Why AI-driven attacks make “monthly scans” and slow, human-only response feel outdatedHow to estimate breach exposure in dollars using simple business inputs (employees, revenue range, regulated data, downtime cost)The first two high-impact moves that immediately reduce risk in the demo: verified backups and MFAHow to turn “we think we did it” into evidence you can show in an audit, insurance claim, or lawsuitHow to build a realistic plan of action with milestones by scheduling security work by the week (example shown: 5 hours per week)Subscribe If you want straight talk on cybersecurity and resilience for real businesses, subscribe for weekly UnHacked episodes. Book a consult If you are a business owner and you cannot clearly prove your current security posture, Phoenix IT Advisors can help you validate what’s in place, close gaps, and build a defensible plan. Links Episode: https://unhackmybusiness.com/episode/97Phoenix IT Advisors: https://phoenixitadvisors.com@UnHackedPodcast

  5. Jul 21

    How a Reusable Portal Shell Unlocks Infinite Custom Apps for SMBs | UnHacked Ep. 96

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ What if you could build the custom business app you've always wanted in a single afternoon, without rebuilding login, security, and AI integrations from scratch every time? Most business owners settle for using 30% of an off-the-shelf app's features because building custom tools was never cost-effective. In this episode, Bryan Lachapelle from B4 Networks walks through a reusable portal shell he vibe-coded that changes that math. The shell handles login, permissions, multi-tenant architecture, AI integration, and email functionality so any new applet can be bolted on in hours instead of weeks. The conversation gets into the real economics of this approach. Bryan currently pays roughly $1,500 a month for two third-party tools (an employee check-in app and a meeting runner). He built replacements in an afternoon each, at a development cost of around $800. Now he can extend those same modules to every client at half the cost or free. The math stops being a simple ROI calculation and becomes exponential. But the episode also gets into the harder truths of vibe coding right now. Justin shares the moment Claude Code deleted an entry on his production system without asking for authorization, just to test if it could. Bryan explains how he uses hooks to prevent AI from running dangerous commands. Josh talks about pitting Claude and ChatGPT against each other to improve documentation, and getting one LLM to praise the other's work. And Mario raises the question every IT provider hears from clients: what about read-only access and data safety when integrating with systems like QuickBooks? This is phase three of the UnHacked mini-series on AI and cybersecurity, where the standing claim is that AI delivers 10 to 50X productivity gains. The examples in this episode push past that ceiling. Bryan Lachapelle is with B4 Networks, based in the Niagara region of Ontario, Canada. His company helps business owners remove the headaches and frustrations that come with dealing with technology, cybersecurity, and now AI. What you'll learn: How a reusable portal shell eliminates the need to rebuild login, permissions, and AI integrations every time you want a new custom appThe real cost math: replacing $1,500/month in third-party tools with custom modules built in an afternoon, then extending them to clientsWhy Claude Code deleted a production entry without asking for authorization, and how hooks can prevent AI from running dangerous commandsHow to handle read-only versus write-back access when integrating custom applets with systems like QuickBooks or XeroWhy pitting two LLMs against each other for documentation review can produce better results than either one aloneNew episodes every week breaking down cybersecurity, AI, and digital resilience for small to mid-sized business owners. Subscribe so you don't miss the next one. If you want help figuring out how AI fits into your business without exposing your data to risk, visit PhoenixITAdvisors.com and schedule a consult. We help business owners make money with AI and then protect that money from the threats that come with it. Episode link: https://unhackmybusiness.com/episode/96 PhoenixITAdvisors.com@UnHackedPodcast

  6. Jul 14

    Build an AI Agent to Replace 6–24 Hours Per Week of Manual Email Work (Safely) Ep. 95

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ A real AI agent watched a bid inbox, parsed attachments, filed everything, and cut 6 to 24 hours a week of manual work. Here is how they kept it from going off the rails. In this episode, Justin Shelley, Bryan Lachapelle, Mario Zaki, and Joshua Holloway break down what “vibe coding” looks like when it is tied to an actual business bottleneck, not a demo. Josh shares a real client build: an agent that monitors mailboxes, reads emails and attachments, moves files into a consistent folder structure, and extracts key data into Excel as a transitional step toward a dashboard. They also get candid about the risks. Models change, context breaks, and agents can misinterpret plain language. The group talks about guardrails, narrow task design, approvals, and why you should hard-code what you can so AI only handles the parts that truly need AI. There is also a practical hiring angle: instead of filling a $95K to $125K role that was open for 6 to 12 months, the company can potentially hire a more junior person who can work with the system, while the business uses the agent to move faster, reduce mistakes, and take on larger opportunities. What you’ll learn How an “email + attachments” agent can save 6 to 24 hours per week by parsing bids, filing documents, and extracting dataWhy consistency wins: how a repeatable folder structure made automation dramatically easierHow to add a “go or no-go” decision step using business criteria, with a human proofing loopWhy agents can degrade over time, and how to reduce risk with narrow prompts, hard-coded steps, and guardrailsA real warning story: how AI can accidentally propose super-admin access, and what to do insteadSubscribe if you want practical, plain-English cybersecurity and AI systems that reduce risk and save real time, not hype. If you want help designing AI automations with the right security boundaries, or figuring out where AI can remove bottlenecks in your business without creating new risks, Phoenix IT Advisors can help. Schedule a consult at PhoenixITAdvisors.com. LinksEpisode: https://unhackmybusiness.com/episode/95https://PhoenixITAdvisors.com@UnHackedPodcast

  7. Jul 7

    How Vibe Coding Cut a 4-Hour Task Down to 10 Minutes | UnHacked Ep. 94

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ Mario Zaki's sales rep used to spend three to four hours building a single proposal. After vibe coding a custom platform, it takes ten minutes. That's a 24x productivity gain for roughly $500 in development costs. This episode kicks off UnHacked's vibe coding series, and Mario walks through exactly what he built, what it replaced, and what it saved. Two automations take center stage. First, an onboarding and offboarding portal that connects directly to Microsoft 365, pulls live license data, provisions users, assigns SharePoint permissions, configures shared mailbox access, and auto-adjusts monthly invoices. What used to take 45 minutes of technician time, plus days of email back-and-forth, now takes three to five minutes with built-in safeguards against the mistakes that eat even more time. Second, a proposals platform that lets his sales rep select predefined line items, auto-calculate pricing across three service tiers, attach the SOW and MSA, and export a polished document for e-signature. No more broken templates, no more math errors, no more 9 PM phone calls to fix formatting. Justin, Bryan, and Josh dig into the ROI math, the security considerations of building custom apps (by default, AI generates applications with no login and five to ten glaring holes), and the mindset shift that happens once you start seeing results. Mario describes how after his first few wins, he started hearing his technicians talk about a repetitive task and immediately thinking, "I can probably automate that." The panel also previews next week's episode, where Josh shares a construction estimator that replaced a $125,000 salary. The core message is urgent. Bryan puts it bluntly: if your competition automates before you do, they will reduce their overhead and you will not have a choice. It will be Blockbuster versus Netflix. What you'll learn: How Mario automated MSP onboarding from 45 minutes to 3-5 minutes by building a custom portal that integrates directly with Microsoft 365, auto-provisions licenses, and adjusts billing automaticallyHow a custom proposals platform cut proposal generation from 3-4 hours to 10 minutes while eliminating math errors and broken document templatesThe real cost of development: approximately $10 in AI tokens plus roughly an hour of an owner's time, yielding a 24x productivity gainWhy AI-generated applications ship with no authentication and multiple security holes by default, and why security has to be the first thing you plan forHow to identify automation opportunities in your own business by listening for tasks that are repetitive, error-prone, or dreaded by your teamNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners. Subscribe so you don't miss the rest of the vibe coding series. Ready to explore what AI automation could do for your business? The team behind UnHacked offers free 30-minute consultations to help you identify your highest-ROI automation opportunities and build them securely. Visit unhackmybusiness.com, pick any episode, and fill out the consult request form underneath the video player.

  8. Jun 30

    93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in Revenue

    Hosts:Justin Shelley | https://www.phoenixitadvisors.comMario Zaki | https://www.mazteck.com/Joshua Holloway | https://7thdi.com/ What if your IT provider handed you $80,000 in revenue capacity without firing a single person, adding a single client, or changing your prices? That's not a hypothetical. That's exactly what Mario Zaki did, and in this episode he shows the math. Mario walks through two AI-powered automations he built for his MSP, Mazteck IT: a custom onboarding and offboarding platform that slashed a 45-minute manual process down to one click, and a license automation system that eliminated an entire month of repetitive January work for one of his technicians. Combined, those two tools freed up nearly $22,000 in labor time. Apply the standard multiplier for what an employee should generate in gross revenue, and you're looking at $80,000 in top-line capacity, built for somewhere between 5 and 10 hours of setup time. Then he mentions, almost as an afterthought, that he also built an on-site agent that briefs technicians the moment they walk through a client's door. Open tickets. Recent issues. Unresolved problems. All of it, right there, before the tech even says hello. Justin's reaction says everything. The group also gets into the real security stakes behind all of this: why ghost licenses are a compliance problem, not just a billing headache; why vibe coding is genuinely exciting and genuinely dangerous at the same time; and why the cat-and-mouse game of cybersecurity didn't start with AI and isn't going to end with it. This is the transitional episode of the Unhacked AI series. Integrations are wrapping up. Vibe coding starts next week. If you can't identify one process in your business right now that AI could automate, this episode will find it for you. Visit https://unhackmybusiness.com/ to request a free consult. If we can't 10X your productivity, you don't pay.

Ratings & Reviews

5
out of 5
3 Ratings

About

When Russian hackers break into your business’s computers, what will they find and how much will it cost you? How long will it take you to recover? Can you recover? Here’s the sad truth: 97% of breaches could have been prevented with basic security measures; but once you’ve been hit… you can never get UnHacked! UnHacked is a weekly cybersecurity podcast for SMB business owners and leaders that helps them sort through the overwhelming security costs and recommendations, and focus on the best practices that give the highest ROI.

You Might Also Like