UnHacked - Cybersecurity Made Simple for Small Businesses

Phoenix IT Advisors

When Russian hackers break into your business’s computers, what will they find and how much will it cost you? How long will it take you to recover? Can you recover? Here’s the sad truth: 97% of breaches could have been prevented with basic security measures; but once you’ve been hit… you can never get UnHacked! UnHacked is a weekly cybersecurity podcast for SMB business owners and leaders that helps them sort through the overwhelming security costs and recommendations, and focus on the best practices that give the highest ROI.

  1. 2d ago

    Will AI End Humanity? We've Heard This Before | UnHacked Ep. 103

    A researcher just quit Anthropic warning AI could end humanity within four years. Microsoft shipped a record 974 security patches that same month. On this episode of UnHacked, Justin Shelley, Bryan Lachapelle, Mario Zaki, and Joshua Holloway dig into the headlines everyone's arguing about right now: a former AI researcher's public warning that AI has more than a 10 percent chance of killing all humans by the end of the decade, and Sam Altman's own estimate putting that number closer to 25 percent. They break down what it would actually take for AI to end humanity (infrastructure attacks, water treatment systems, job displacement) and why the scarier headline might be the one nobody's talking about: Microsoft just blew past its previous patch record by nearly double, and no business on earth can manually test and deploy 974 patches from one vendor alone. The conversation also goes inside Josh's actual AI coding workflow, a "council of five" system where multiple AI agents review each other's work, including a dedicated security audit council, before anything ships. Mario makes the case that AI replacing hard-to-fill jobs isn't the villain story everyone assumes, especially after years of ghosted interviews and no-show hires since COVID. And Justin makes the argument that this whole panic cycle looks a lot like Y2K, the nuclear arms race, and 1980s acid rain scares: real fears, mostly survived. What you'll learn: Why Microsoft's record 974 patches (almost double its previous record) make manual patch testing impossible, and where AI-driven patching is headed nextHow Josh's multi-agent "council of five" AI coding process works, including a separate security council that audits everything before deploymentThe real numbers behind the AI doom headlines (10 to 25 percent estimated risk) and what it would actually take for AI to cause that kind of damageWhy hiring struggles since COVID have Mario openly in favor of AI taking over jobs nobody's showing up for anymoreWhy the hosts believe this fear cycle mirrors Y2K, the nuclear arms race, and the acid rain panic, and what that history means for business owners right nowEvery week the UnHacked crew breaks down what's actually happening in AI, cybersecurity, and business technology, without the headline panic. Subscribe so you don't miss the next one. Keeping up with hundreds of security patches a month isn't something most businesses can do alone, and guessing your way through it is how breaches happen. Phoenix IT Advisors helps small and mid-sized businesses build a real patching and cybersecurity strategy instead of hitting "apply" and hoping. Visit PhoenixITAdvisors.com to schedule a consult. Links: Episode: https://unhackmybusiness.com/episode/103Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked: @UnHackedPodcast

  2. Sep 8

    AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ AI didn't go rogue and hack a company on its own. Someone pointed a jailbroken AI at an unpatched server, and it finished a full ransomware attack in about 30 minutes. Security researchers at Sysdig just documented the first fully autonomous, AI-driven ransomware attack, nicknamed "Jade Puffer." No human touched a keyboard once it started. It broke in, mapped the network, rewrote its own code to dodge detection, and deployed ransomware, start to finish, faster than most security teams could even get an alert out. Experts are now saying the response window for an attack like this has shrunk from hours to as little as 15 minutes. Justin Shelley, Mario Zaki, and Joshua Holloway break down what actually happened, and why the scary headline ("AI attacks company, no humans involved") is only half the story. The real vulnerability wasn't AI. It was a production MySQL server exposed to the internet, running unpatched software with a known critical flaw, and a default signing key that hadn't been changed since 2020. The AI didn't discover some brand-new weakness. It exploited the same lazy, preventable gaps that have caused breaches for a decade, just a lot faster. Josh also shares a live horror story about an MSP that disabled a client's VPN and locked them out of their own data over a single unpaid invoice, in the middle of an unrelated legal dispute, then demanded tens of thousands of dollars before restoring access. It's a hard look at what happens when a business has no idea what their IT provider is actually doing for them, and no leverage when things go sideways. What you'll learn: How the first fully autonomous AI ransomware attack worked, from breach to payload in under 30 minutesWhy the vulnerability that let it happen was public knowledge for over a year, and completely preventable with basic patchingWhy publishing CVEs (known vulnerabilities) helps defenders more than it helps attackersWhy the AI-generated ransomware couldn't have paid off even if the victim tried, because the encryption key was never stored anywhereRed flags that your MSP isn't doing what you're paying them for, and what to do if one tries to hold your data hostageNew episodes of UnHacked drop every week with real talk on cybersecurity, AI, and the tech risks actually hitting small business owners. Subscribe so the next one doesn't catch you off guard. Not sure if your IT company is actually protecting you or just collecting a check? Phoenix IT Advisors helps small and mid-sized businesses find out, patch what's exposed, and build security that doesn't rely on luck. Visit PhoenixITAdvisors.com to schedule a consult. Links:Full episode: https://unhackmybusiness.com/episode/102Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked: @UnHackedPodcast

  3. Sep 1

    How Chinese Hackers Breached NASA and DHS Using Home Routers | UnHacked Ep. 101

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ NASA, Homeland Security, and the DOJ were just hacked using smart fridges, routers, and Apple TVs turned into a botnet. If a Chinese front company staffed by retired military hackers can breach federal agencies with seemingly unlimited security budgets, what chance does a small business have? That's the question Justin Shelley, Mario Zaki, and Josh Holloway tackle in episode 101 of UnHacked, and the answer is more reassuring than you'd think. Justin, Mario, and Josh break down how a group called QTFY, operating through a front company called XJW, built a database of known, published vulnerabilities (not secret zero-days) by scanning over 2 million routers, firewalls, and devices in a single day. They then hijacked vulnerable home devices, thermostats, cheap Amazon modems, Apple TVs, turning them into a botnet used to disguise attack traffic as normal U.S. internet activity and bypass geo-blocking on China. The operation ran undetected for roughly eight years before a hospital got hit as collateral damage and the FBI finally traced it back and took down the network by seizing the hardcoded command domains. Here's the part that matters for you: this entire breach was built on things that basic cybersecurity hygiene would have stopped. Unpatched known vulnerabilities. Unmanaged home and IoT devices. No inventory of what's actually on the network. The guys connect this directly back to fundamentals covered in past episodes, patch management, shadow IT, firewall lifecycle, and the death of the network perimeter, and explain why the real failure in most breaches isn't a lack of resources. It's a lack of follow-through. What you'll learn: How hackers built a database of known, published vulnerabilities (CVEs) by scanning over 2 million devices in a single day, and why "known" doesn't mean "harmless"Why your home router, thermostat, or cheap Amazon modem could already be part of a botnet attacking someone else without your knowledgeHow the FBI actually shut the operation down by seizing the hackers' own command domainsWhy the real question isn't "can I spend money on this fix" but "what does it cost me if I don't," and how to calculate that number for your own businessA real example of a company that could lose $5 million a day (up to $30 million on payroll days) from downtime, and why that number changes every security decisionNew episodes drop every week with real talk on cybersecurity, AI, and digital risk for business owners who don't have a national security budget. Subscribe so you don't miss the next one. If this episode made you wonder what's actually sitting unpatched on your network right now, that's exactly the conversation Phoenix IT Advisors has with business owners every day. Visit PhoenixITAdvisors.com to schedule a consult, or go to UnHackMyBusiness.com to use the free portal referenced in this episode to catalog your risks and build a plan. Links: Full episode: https://unhackmybusiness.com/episode/101Free risk assessment portal: https://unhackmybusiness.comPhoenix IT Advisors: https://phoenixitadvisors.comFollow the show: @UnHackedPodcast

  4. Aug 25

    What 100 Episodes of Cybersecurity Taught Us | UnHacked Ep. 100

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ Three MSP owners get honest about what 100 episodes of cybersecurity conversations actually changed in their businesses. The answer might surprise you. After 100 episodes of UnHacked, Justin, Mario, and Josh step back from the usual threat-of-the-week format to ask a different question: what did we actually learn? The answers are less about specific vulnerabilities and more about how running this podcast forced each of them to get more serious about their own security postures, their own businesses, and the way they serve clients. Justin admits he no longer trusts himself to run his business without the weekly pressure of digging into security topics for the show. What started as a marketing play during COVID became a forcing function for his own education. He also retired the phrase "97% of breaches could be prevented with basic cybersecurity measures" after building a 12-episode basics series and realizing the word "basic" is a lie. The stuff is hard, complicated, and most MSPs were not talking about it correctly even a few years ago. Josh, the newest co-host at roughly 14 episodes in, shares what he has picked up from the other hosts' perspectives, including how Brian's approach to containerization and modular app design changed the way Josh is building an internal portal. The conversation also covers how the podcast has become a recruiting tool, why every IT owner vacations with a laptop, and what you should actually do in the first minutes of a business email compromise. The episode closes with a practical discussion of incident response priorities: assess first, pull out your incident response plan, call your insurance carrier, and understand that if money was wired to the wrong account, your options are limited. Josh shares the one time he successfully recouped funds with the FBI's help, and why that case was the exception, not the rule. What you'll learn: Why "basic cybersecurity" is a misleading phrase and what actually goes into foundational protectionThe first three things you should do when you suspect a business email compromise or wire fraudHow running a content podcast forced an MSP owner to get more serious about his own security stackWhy an incident response plan is the first thing you need, not the last, and what your insurance policy likely requiresHow AI security events have shifted from background noise to front-of-mind for every business ownerNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out whether your IT provider is actually protecting you or just keeping the printers working, visit unhackmybusiness.com to get visibility into your own security posture. Phoenix IT Advisors helps businesses use technology to make money and then protect that money from attorneys, compliance requirements, and the hackers coming for it. Schedule a consult at PhoenixITAdvisors.com. Episode link: https://unhackmybusiness.com/episode/100PhoenixITAdvisors.comUnHacked on social: @UnHackedPodcast

  5. Aug 18

    Insurance Won't Cover Your AI Mistakes Anymore | UnHacked Ep. 99

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/ Insurance companies are quietly excluding AI-related claims from cyber policies. If you're using AI in your business right now, you need to know this before renewal. For the last 24 episodes, Justin Shelley and Mario Zaki have shown business owners how to use AI to save time and money. This week they hit pause on the excitement and looked at what's happening on the insurance side, because it's changing fast, and most business owners have no idea. Insurance carriers are now excluding claims involving AI resume-screening tools that discriminate against candidates, even when the business owner never intended it to happen. They're also excluding "negligence" claims: if you vibe-coded your own system, put your business data into it, and something breaks or disappears with no hack involved, some policies are treating that as your fault, not a covered incident. Justin admits on the show that his own first vibe-coded project had zero real security in it and could have leaked data before he caught it. They also break down the newest breach numbers most business owners haven't seen: the global average cost of a data breach is up 12% to $4.99 million, AI-enabled breaches jumped 56% year over year and now average $6 million, 43% of security incidents involved unapproved "shadow AI" tools, 70% of breached organizations had no AI governance policy at all, and 92% of organizations breached through AI systems lacked basic access controls. This episode is short and direct on purpose: audit what you've built, then call your insurance agent this week. What you'll learn: Why AI resume-screening tools can trigger discrimination claims your business liability insurance may no longer coverHow "self-inflicted" data loss from vibe-coded systems is being excluded as negligence, even with no hacker involvedThe current breach numbers: AI-enabled breaches now average $6M, and 92% of AI-related breaches happened in systems with no basic access controlsThe exact three questions to ask your insurance agent about AI exclusions before your next renewalWhy a tested backup and restore plan matters even more once AI or vibe-coded systems are running part of your businessNew episodes drop every week breaking down cybersecurity and AI risk in plain English. Subscribe so the next "audit your business before it's too late" episode doesn't catch you off guard. Need help figuring out where your business actually stands on AI and cybersecurity risk? Phoenix IT Advisors helps small and mid-sized businesses find these gaps before an insurance company or a hacker finds them for you. Visit PhoenixITAdvisors.com to schedule a consult. Links: Full episode: https://unhackmybusiness.com/episode/99Free AI policy template & insurance question checklist: https://unhackmybusiness.com/episode/99Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked episodes: @UnHackedPodcast

  6. Aug 11

    Did AI Go Rogue: The OpenAI Sandbox Breakout Nobody Saw Coming | UnHacked Ep. 98

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ An OpenAI frontier model broke out of its sandbox, exploited a zero-day, and attacked Hugging Face. It left behind instructions so the next AI could escape faster. This already happened. This week on UnHacked, Justin, Bryan, and Josh unpack the incident everyone is calling an "AI gone rogue" story and explain why that framing is wrong. The model did not develop a devious plan. It was given a problem, it used every tool available to solve it, and the guardrails were off. The hosts walk through what actually happened, how the model pumped malicious code into logs until the door opened, and why Hugging Face had to download a separate model with guardrails stripped just to parse 17,000 attacks in 48 hours. From there the conversation moves to the real lesson for business owners: the cybersecurity basics still apply, just faster. Guardrails are access control. Prompts are policy. Sandboxes are least privilege. The technology is new but the principles are not. Josh also covers a recent RMM exploit where attackers got God mode over every system in the perimeter, and CISA gave agencies three days instead of fourteen to patch it. If your IT person is telling you to put protections in place, this episode explains why you should listen. Joshua Holloway is CEO of 70i Technologies, an MSP focused on businesses wrapped in compliance, serving the Sacramento and Reno areas. Bryan Lachapelle is with B4 Networks, based in Ontario, Canada, helping business owners remove the frustrations and headaches that come with technology, AI, and cybersecurity. What you will learn: What actually happened when an OpenAI frontier model broke out of its sandbox and attacked Hugging Face, including the instructions it left behind for the next AI Why "AI went rogue" is the wrong framing, and how to think about LLMs mimicking thought without actually thinkingThe two layers of guardrails every business owner needs to understand: the ones AI builders set and the ones you set in your own environmentWhy using the same AI agent to write and check its own code is like grading your own math test, and how pitting different models against each other produces better resultsHow a recent RMM exploit gave attackers God mode over every connected system, and why CISA shortened the patch window from fourteen days to threeNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out what protections you actually need, visit unhackmybusiness.com. Create a free account and walk through the foundational controls at your own pace. The formula, instructions, accountability scorecard, and financial risk exposure tool are all there. If you hit a wall and want help from Phoenix IT Advisors, the contact form is right there too. Episode link: https://unhackmybusiness.com/episode/98

  7. Jul 28

    Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/ Most owners think they are secure. Almost none can prove it.This episode shows how to stop guessing and start getting defensible answers. Justin, Mario, and Josh start with a headline-level fear: an AI model in testing “got out,” hit a target over 17,000 times in a weekend, and even “guardrails” got in the way of defenders analyzing what happened. Whether that exact story holds up over time or not, the business takeaway is clear: speed is changing, and “my IT guy says we’re good” is not a security strategy. Then Justin walks through a practical solution: a free portal built to answer the question every business owner should be asking, “Are we actually protected?” It is designed to help non-technical leaders measure risk, take one next step at a time, and collect evidence so security is auditable and defensible. The demo includes a sample business profile that estimates exposure in dollars (example shown: $5.4M), then reduces that exposure fast by completing basics like backups and MFA and documenting proof. A key theme throughout is accountability. If your provider is “grading their own homework,” you need a way to validate what is really in place, what is missing, and what to do next, without relying on vague reassurance. Verbatim quote: “Your IT guy is grading his own homework.” What you’ll learn Why AI-driven attacks make “monthly scans” and slow, human-only response feel outdatedHow to estimate breach exposure in dollars using simple business inputs (employees, revenue range, regulated data, downtime cost)The first two high-impact moves that immediately reduce risk in the demo: verified backups and MFAHow to turn “we think we did it” into evidence you can show in an audit, insurance claim, or lawsuitHow to build a realistic plan of action with milestones by scheduling security work by the week (example shown: 5 hours per week)Subscribe If you want straight talk on cybersecurity and resilience for real businesses, subscribe for weekly UnHacked episodes. Book a consult If you are a business owner and you cannot clearly prove your current security posture, Phoenix IT Advisors can help you validate what’s in place, close gaps, and build a defensible plan. Links Episode: https://unhackmybusiness.com/episode/97Phoenix IT Advisors: https://phoenixitadvisors.com@UnHackedPodcast

  8. Jul 21

    How a Reusable Portal Shell Unlocks Infinite Custom Apps for SMBs | UnHacked Ep. 96

    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/ What if you could build the custom business app you've always wanted in a single afternoon, without rebuilding login, security, and AI integrations from scratch every time? Most business owners settle for using 30% of an off-the-shelf app's features because building custom tools was never cost-effective. In this episode, Bryan Lachapelle from B4 Networks walks through a reusable portal shell he vibe-coded that changes that math. The shell handles login, permissions, multi-tenant architecture, AI integration, and email functionality so any new applet can be bolted on in hours instead of weeks. The conversation gets into the real economics of this approach. Bryan currently pays roughly $1,500 a month for two third-party tools (an employee check-in app and a meeting runner). He built replacements in an afternoon each, at a development cost of around $800. Now he can extend those same modules to every client at half the cost or free. The math stops being a simple ROI calculation and becomes exponential. But the episode also gets into the harder truths of vibe coding right now. Justin shares the moment Claude Code deleted an entry on his production system without asking for authorization, just to test if it could. Bryan explains how he uses hooks to prevent AI from running dangerous commands. Josh talks about pitting Claude and ChatGPT against each other to improve documentation, and getting one LLM to praise the other's work. And Mario raises the question every IT provider hears from clients: what about read-only access and data safety when integrating with systems like QuickBooks? This is phase three of the UnHacked mini-series on AI and cybersecurity, where the standing claim is that AI delivers 10 to 50X productivity gains. The examples in this episode push past that ceiling. Bryan Lachapelle is with B4 Networks, based in the Niagara region of Ontario, Canada. His company helps business owners remove the headaches and frustrations that come with dealing with technology, cybersecurity, and now AI. What you'll learn: How a reusable portal shell eliminates the need to rebuild login, permissions, and AI integrations every time you want a new custom appThe real cost math: replacing $1,500/month in third-party tools with custom modules built in an afternoon, then extending them to clientsWhy Claude Code deleted a production entry without asking for authorization, and how hooks can prevent AI from running dangerous commandsHow to handle read-only versus write-back access when integrating custom applets with systems like QuickBooks or XeroWhy pitting two LLMs against each other for documentation review can produce better results than either one aloneNew episodes every week breaking down cybersecurity, AI, and digital resilience for small to mid-sized business owners. Subscribe so you don't miss the next one. If you want help figuring out how AI fits into your business without exposing your data to risk, visit PhoenixITAdvisors.com and schedule a consult. We help business owners make money with AI and then protect that money from the threats that come with it. Episode link: https://unhackmybusiness.com/episode/96 PhoenixITAdvisors.com@UnHackedPodcast

Ratings & Reviews

5
out of 5
3 Ratings

About

When Russian hackers break into your business’s computers, what will they find and how much will it cost you? How long will it take you to recover? Can you recover? Here’s the sad truth: 97% of breaches could have been prevented with basic security measures; but once you’ve been hit… you can never get UnHacked! UnHacked is a weekly cybersecurity podcast for SMB business owners and leaders that helps them sort through the overwhelming security costs and recommendations, and focus on the best practices that give the highest ROI.

You Might Also Like