Find partners
QPC Security - Breakfast Bytes

QPC Security - Breakfast Bytes

Hosted by qpcsecurity

Episodes

100

Latest episode

Jul 2026

Language

EN

About the show

Felicia King is an internationally recognized CISO and considered to be one of the top network layer security strategists in the U.S. Since launching in 2004 on the WGTD network, her Breakfast Bytes podcast has focused on information security risk management and the issues business leaders need to be aware of to benefit from the challenges others have faced. Learn about the most effective approaches, what you can do to mitigate risk, and how to protect your most valuable assets, your data, and your time. Felicia is the vCISO and security architect at QPC Security / Quality Plus Consulting. 🎧 Let’s Talk Cybersecurity—Together With over 25 years of hands-on experience in network-layer protection and cybersecurity strategy, we’re here to make security simple and accessible. Whether you’re a homeowner, a family, a retired professional, or running a small to medium-sized business, we’ve got solutions tailored just for you. 💡 No minimum seat count required—if you need help, we’re here for you. 🔒 Tune in, subscribe at qpcsecurity.podbean.com, and let’s build a safer digital world—one episode at a time. 🌐 Visit our website at qpcsecurity.com to learn more and book your appointment today!

Listen to episodes

60 recent
July 8, 2026Episode 17628 min

Leveraging AI in Software Development Responsibly

Felicia King interviewed Robin Grayson of Redcliffe Technology Services about artificial intelligence in software development. Robin, a programmer with 30 years of experience, discussed the importance of maintaining rigorous software development practices when using AI tools like Claude, emphasizing the need for proper guardrails, documentation, and security reviews. He explained his approach of treating AI-assisted development like working with a highly skilled junior developer, including using Azure DevOps for enterprise applications and setting up markdown files with instructions for AI to follow. Robin highlighted significant security concerns when non-technical people use AI to develop applications without proper oversight, potentially exposing sensitive systems and data to risks. He also discussed the importance of security-first development and using AI for code reviews to identify security vulnerabilities in existing codebases. https://www.redcliffesystems.com/ Software Development Evolution Discussion Robin discussed the evolution of software development practices, highlighting how developers in the past had to be more meticulous due to limited resources and the absence of modern tools like Stack Overflow. He emphasized the importance of understanding hardware, networking, and security, which many current software developers lack due to their limited exposure to physical infrastructure. Felicia agreed with Robin's points, noting the challenges faced by developers with limited real-world experience in networking and server management. Software Development Best Practices Robin discussed challenges with software development, particularly when projects are rushed into production without proper planning. He explained his approach to AI development by treating it like a highly skilled junior developer, emphasizing the importance of following proper development processes including isolated branches, pull requests, and code review. Robin highlighted that while some developers adequately review code, others simply approve pull requests without properly examining the changes. AI Integration in DevOps Workflow Robin described his approach to integrating AI, specifically Claude, into his software development workflow by establishing clear processes and requirements. He demonstrated this by setting up a DevOps board in Microsoft Azure and configuring Claude to follow specific steps, including accessing the board, moving items through development stages, and creating pull requests. Robin also explained the use of markdown files for documentation, which allows for easy tracking of changes, reviews, and testing evidence within the source control system. Markdown Documentation Process Implementation Robin explained that markdown files serve as source instructions and guardrails for Claude's work, making it more efficient than using Word documents and easier for team members to review. Robin also described implementing a system where Claude generates documentation for every change, which is checked in alongside pull requests for team review. The discussion concluded with Robin expressing concerns about "vibe coding" where non-technical users create applications without understanding the security implications, leading to potential security vulnerabilities like hardcoded credentials in source control. AI Code Development Security Guidelines Felicia and Robin discussed the importance of proper guardrails and instructions when using AI for code development assistance to prevent security risks. Robin highlighted concerns about developers giving AI systems excessive permissions without understanding the implications, while Felicia emphasized the need for better oversight processes, particularly regarding third-party information security risks when businesses use external partners' services. Both agreed that the current lack of proper review and consent processes creates significant security vulnerabilities when non-developers implement and deploy applications connected to critical systems like Microsoft 365 tenants. Data Security Governance Requirements Felicia and Robin discussed governance oversight and regulatory requirements around data security and disclosure in the UK and US. They highlighted the severity of failing to disclose material security facts, referencing regulations like GDPR and FTC regulations, and emphasized the importance of security in software development, particularly with AI and IoT devices. The conversation ended with Felicia asking Robin about their thoughts on using Azure DevOps versus GitHub, but this part of the discussion was not captured in the transcript. AI-Driven Application Security Assessment Robin advised using Azure DevOps for closed-source enterprise applications and GitHub for open-source projects. When asked about application security assessment, Robin suggested using AI tools like Claude with appropriate security standards and noted that AI can perform comprehensive security reviews of code bases, though it's important to monitor token usage during these reviews. Source Code Review and Issues Robin reviewed the source code and identified top issues that need immediate fixes, along with additional concerns to address in the future. Felicia expressed appreciation for the discussion about empowering developers with AI capabilities, noting how this could help overcome limitations in existing third-party tools.

June 30, 2026Episode 17528 min

Don't Get Bill-Baited: Spot Vendor Billing Red Flags Before You Sign

Felicia King opens Breakfast Bytes with two vivid vendor-vetting stories: a positive case involving a law firm engagement where clear communication and economic impact assessment resolved concerns before moving forward, and a negative case involving a UK-based consultancy reselling SaaS licenses where fraudulent billing practices occurred. Through these contrasting narratives—responsive attorneys who clarified costs versus a buggy reseller that billed months later—Felicia lays out the simple, powerful checks that prevent disputes: ask scenario questions, demand sample invoices, review service-attach schedules and data subprocessors, and get commitments in writing. Remember: payment is acceptance; lack of payment is lack of consent. Short, practical, and sharply told, this episode gives you the red flags to watch for and the exact questions to ask so you never get stuck paying for a service you never agreed to. Felicia emphasized the importance of reviewing vendor agreements carefully, asking scenario-based questions about billing processes, requesting sample invoices, understanding data subprocessors, and payment collection methods. She stressed that legitimate businesses should disconnect services immediately when payment is not received, avoid using collections agencies, and provide clear renewal processes, warning that red flags include unclear billing terms, hidden auto-renewal clauses, and refusal to share service attached schedules. Ask prospective vendors scenario-based questions about billing, non-payment consequences, and service continuation before accepting their agreement. Request a sample invoice from the vendor to ensure clarity and transparency in billing practices. Inquire about the vendor's service attached schedule and data subprocessors before engaging in business. Ask the vendor about their payment processing system and how they handle collections. Verify the vendor's policy on non-renewal and service deprovisioning in case of non-payment. Vendor Risk Assessment Process Felicia discussed vendor risk pre-assessment and billing discrepancy issues, using a personal injury law firm case as an example of effective vendor vetting. She described how they developed criteria to evaluate law firms, scheduled calls, reviewed agreements, and addressed unclear terms regarding reimbursable expenses. The process included engaging with the attorney and their staff to clarify costs and ensure alignment before moving forward with the engagement. UK Consultancy Software License Issues Felicia discussed a negative experience with a UK-based consultancy that was reselling software licenses and providing consulting services to U.S. companies. She identified a key red flag that should have prompted ending the engagement: a disconnect between the consultancy and their software vendor, including conflicting requests about demo data in the tenant. Felicia noted that these issues could have been detected earlier to avoid problems. UK Software Vendor Billing Issues Felicia discussed issues with a software vendor from the UK that had numerous bugs and problematic billing terms. She explained that the vendor's billing agreement allowed them to bill customers irregularly and potentially not at all, which is unacceptable for month-to-month services in the United States. Felicia highlighted examples of confusing invoices with identical service terms but different invoice numbers, describing this as intentional misrepresentation. She recommended that companies should ask potential vendors about their billing practices before starting business relationships. IT Billing and Payment Policies Felicia discussed billing practices and payment policies for IT services, explaining that services are turned off when payment is not received and emphasizing the importance of clear invoicing and consent. She advised reviewing vendor agreements, asking scenario questions, and obtaining sample invoices to ensure transparency. Felicia also highlighted the significance of reviewing service attached schedules to understand third-party risk management and data subprocessors in the supply chain. Transparent Vendor Billing Practices Felicia discussed the importance of transparent billing practices and payment structures in vendor relationships. She emphasized that the use of collections agencies should be a red flag, particularly for smaller consulting firms, as it often indicates poor business practices or fraudulent billing. Felicia recommended a straightforward approach where services are billed upfront or monthly, with disconnection if payment is not received, and suggested providing 90-day advance notice for renewals. Vendor Non-Renewal Policy Discussion Felicia discussed the importance of understanding vendor policies for non-renewal processes, emphasizing that vendors should make it easy for customers to self-manage if they don't want to renew. She highlighted the need to inquire about data handling when services are discontinued due to non-payment, warning that some vendors may retain customer data even after services are turned off, which she described as mismanagement.

May 21, 2026Episode 17428 min

Take Back Your Website: Stop Abdicating Ownership

Join Felicia King on Breakfast Bytes as she exposes the broken paradigms behind how small and medium businesses manage their websites. Through clear, hard-earned advice and real-world examples, she shows why handing everything to a web vendor leads to lost continuity, failed deliverability, and missed sales — and how a shared-responsibility approach with the right CTO and tools restores control and effectiveness. From domain ownership and DNS to WordPress hosting, contact-form delivery, and email authentication (DMARC, DKIM, SPF), Felicia walks listeners through the practical steps to secure and optimize a website that actually connects with prospects. Whether you’re deciding between affordable managed WordPress plans or choosing the right frameworks, you’ll leave with a framework for ownership, documentation, and a small, sustainable maintenance plan that preserves business continuity and boosts outcomes. Website Management Challenges for SMBs Felicia discussed the common challenges small to medium businesses face with their websites, emphasizing that it's a paradigm issue rather than just a vendor selection problem. She identified key concerns including business continuity, ownership, and understanding risk associated with websites as critical public-facing organizational presence. Felicia noted that past paradigms for website management no longer work effectively and haven't been functional for at least the last six years. Website Effectiveness and Optimization Felicia discussed website effectiveness and shared insights about what doesn't work well, mentioning Matt Diggity as an authoritative resource on website optimization. She explained that website effectiveness involves connecting with prospects, accurately representing the organization's activities, and facilitating business objectives like email marketing and CRM systems. Felicia specifically highlighted that contact forms are often problematic and can reveal inadequate technology providers or website consultants. Domain Hosting Best Practices Felicia strongly advised against having website development or management companies host domain and DNS, warning that this creates migration issues and potential problems if separating from the company. She emphasized her 30 years of experience in recommending that domain and DNS hosting should be either internally owned or managed by a chief technology officer rather than outsourced to web development companies. WordPress CMS Benefits Discussion Felicia discussed the benefits of using WordPress as a content management system, highlighting its market share and security improvements. She emphasized that businesses should own their WordPress.com accounts rather than paying monthly fees to manage basic features like automated backups and security. Felicia recommended quarterly check-ins with a CTO for website health monitoring and suggested a total annual cost for website hosting and tooling ranging from $1,200 to $3,000. Website Management and WordPress Strategy Felicia discussed the importance of maintaining direct involvement in website management rather than delegating it entirely to others, emphasizing that outsourcing key aspects like SEO is ineffective due to constant changes in the field. She highlighted the benefits of using WordPress.com, including built-in features like WooCommerce and Stripe integration, which are not commonly promoted by web developers whose business model relies on delegation. Felicia also warned about the potential negative impact on website performance when switching to third-party services, citing examples of companies whose statistics declined after using website mills. Website Contact Form Email Configurations Felicia discussed the importance of having effective contact forms on websites, emphasizing the need for proper email deliverability and anti-spam protections. She highlighted common issues with third-party web developers' inadequate handling of DMARC, DKIM, and SPF configurations, which can lead to undelivered emails. Felicia also criticized the use of certain email services like SendGrid, suggesting they are poorly configured for effective communication. Email Deliverability and Security Issues Felicia discussed email deliverability issues, specifically highlighting problems with a website using SendGrid for multi-factor authentication (MFA) that resulted in 100% undeliverable emails due to improper implementation. She emphasized that most organizations fail basic email security standards like DMARC, DKIM, and SPF, and criticized the widespread technical incompetence in email deliverability management despite these standards being established over a decade ago. AI Search Optimization and Control Felicia discussed the importance of AI search optimization for websites and criticized the practice of delegating website management entirely to external third parties. She argued that spending significant monthly fees on SEO management without proper expertise or results constitutes fraud, describing it as a "dead paradigm." Felicia emphasized that business owners should remain involved in their website management rather than abdicating all responsibility to external companies. Shared Website Management Responsibility Felicia discussed the importance of a shared responsibility paradigm for website management, emphasizing that outsourcing everything or trying to do it all independently doesn't work effectively. She explained that the ideal approach involves working with a CTO on a project to set up the website, with monthly check-ins to support internal team members in learning SEO and content management. Felicia stressed the need to start with clear requirements before seeking proposals from vendors and highlighted the importance of maintaining a professional public-facing security posture through proper website and email configuration.

April 28, 2026Episode 17328 min

When Your Desktop Lives in the Cloud: Real-World Windows 365 Use Cases

Felicia King pulls back the curtain on Windows 365 Cloud PCs and takes you on a journey from the chaos of shipping laptops to the precision of cloud-hosted workstations. Through real-world examples—remote hires across continents, a surveillance system rescued from theft, and the thorny case of legacy apps—she shows how moving the PC to the cloud transforms logistics, security, and performance. The episode dramatizes the stakes: stolen hardware, data exfiltration, and transatlantic latency versus a low-latency Microsoft backbone, regional Cloud PC placement, and tight policy controls. Felicia balances costs, practical limits (hello, South Africa), and alternatives like Azure Virtual Desktop, turning technical tradeoffs into human-centered decisions. Listen in for clear, no-nonsense guidance, vivid field-tested anecdotes, and a final note: the right rollout needs networking wizards. If you manage remote teams or sensitive data, this episode reframes what a desktop can be—and what it should cost you to keep your business safe. Felicia King discussed Windows 365 Cloud PCs, explaining their costs, use cases, and limitations. She outlined that Cloud PCs are suitable for remote workers, particularly those in foreign countries, as they allow for better performance and security without the need to deploy physical hardware. Felicia highlighted the importance of selecting the correct region to minimize latency and discussed the challenges of using Cloud PCs in areas like South Africa due to poor connectivity. She also explained the benefits of using Azure Virtual Desktop for larger-scale deployments or legacy applications requiring Active Directory. Felicia emphasized the security advantages of Cloud PCs, including the ability to control network connections and prevent data exfiltration, and suggested that they could be a cost-effective solution for remote workers when combined with devices like the Microsoft 365 Link. Windows 365 Cloud PCs Overview Felicia discussed Windows 365 Cloud PCs, explaining that they are cloud-based computers accessible only through a business's Microsoft 365 tenant and Azure Active Directory. She noted that the baseline cost for a suitable business implementation is over $2,000 per year, requiring proper management and maintenance. Felicia mentioned that Windows 365 Cloud PCs are particularly beneficial for remote workers in business environments. Remote Work Challenges and Solutions Felicia discussed the challenges organizations face with remote working, particularly regarding equipment deployment and recovery for employees in different countries. She explained how Windows 365 cloud PCs could address these issues by allowing organizations to host virtual desktops in region-specific data centers, which would improve performance and reduce latency for remote workers. Cloud PC Regional Positioning Strategy Felicia discussed the benefits of positioning cloud PCs in regions near workers, explaining how this reduces latency and improves performance. She emphasized the importance of being on the Microsoft backbone for enhanced connectivity to Microsoft services and other cloud resources. Felicia noted that while this approach significantly improves performance, there is currently no South Africa region available for Windows 365 cloud PCs. Microsoft Teams Connectivity Challenges Felicia explained that Microsoft cannot currently make Microsoft Teams work effectively for South Africa due to poor connectivity between South Africa and the United States, with data routes going through Europe or taking a high-latency route through Brazil. She noted that Azure Virtual Desktop could be a solution but only becomes economically feasible for 15-20 endpoints or more, requiring significant administrative overhead. Felicia identified two main use cases for Azure Virtual Desktop: when organizations need large quantities of low-latency workstations close to users, or when they are using legacy technology requiring Active Directory like Great Plains or Solomon systems. Windows 365 Cloud PC Limitations Felicia discussed the limitations of Windows 365 Cloud PCs, noting that they cannot be joined to Active Directory unlike Azure Virtual Desktop. She explained her current use of Windows 365 Cloud PC for printing and accessing on-premises resources through custom networking and secure edge agents. Felicia also shared an example of using cloud servers for a business that wanted to avoid on-premises hardware after experiencing a break-in, implementing a solution with microSD card caching for camera recordings. Windows 365 Cloud PC Implementation Felicia explained the implementation of a Windows 365 cloud PC for a customer, which provides secure high-performance access to their video management system and other applications from anywhere. She described how this solution allows users to access a full desktop experience from any device while maintaining security through restrictions on copy-paste functionality between the local and cloud environments. Felicia noted that while complete data security is impossible, the cloud PC provides significant protection against data exfiltration compared to traditional local computing. Cloud PC and Microsoft 365 Link Felicia discussed the benefits of cloud PCs, highlighting their security features and ease of management compared to traditional hardware. She introduced Microsoft 365 Link, a new device with a downsized operating system priced around $400 with an optional $100 warranty, which can support up to two monitors. Felicia explained that these devices can be accessed with Microsoft 365 accounts, similar to Google Workspace. Windows 365 Cloud PC Implementation Felicia discussed the use case for Windows 365 cloud PCs, particularly for remote workers, emphasizing enhanced security and control over data and network connections. She explained how cloud PCs can mitigate risks associated with data exfiltration and hardware security, especially for sensitive roles like accounting. Felicia noted that while cloud PCs may be more expensive than traditional hardware, they offer better security and compliance benefits and suggested using them in conjunction with Microsoft 365 Link PCs for remote workers.

March 24, 2026Episode 17228 min

Why assessments and audits are likely a waste of time and money

Host Felicia King sits down with Rick Hernandez, CEO of N2Con, to unravel a common but dangerous IT story: assessments that miss the point and audits that leave companies exposed. Through candid examples—lost laptops, stale Active Directory entries, and policies that never existed—they set the stage for a real-world investigation into how businesses really manage (or mismanage) their digital assets. As the conversation deepens, the tension grows: accounting firms deliver check-the-box reports, old tools miss cloud realities, and well-meaning assessments become expensive paperweights. Felicia and Rick walk listeners through the messy discoveries they encounter when onboarding clients, and the moment when a seemingly small gap in inventory can lead to a major security and financial risk. Instead of one-off reports, the episode offers a roadmap—pick a practical framework, insist on executive buy-in, adopt continuous vulnerability management, and own your asset and compliance data. Short, vivid, and tactical, this episode turns audit horror stories into clear next steps for any organization ready to take responsibility for its security. Quick recap Felicia King and Rick Hernandez discussed challenges around assessments and audits in cybersecurity, particularly focusing on the issues that arise when clients approach MSPs after undergoing assessments with accounting firms. They explored how many organizations lack proper asset inventories and off-boarding processes for equipment, leading to security gaps and compliance challenges. The conversation highlighted the problems with one-time security assessments, with both speakers agreeing that a more effective approach involves implementing continuous monitoring tools and establishing proper frameworks like NIST or CMMC before seeking external assessments. They discussed how many organizations waste money on incomplete assessments from firms lacking proper cybersecurity expertise, and emphasized the importance of executive buy-in and proper risk prioritization for successful security implementations. Asset Inventory Management Challenges Felicia and Rick discussed challenges with asset inventory and management in businesses. They highlighted the importance of having an accurate inventory for security purposes and noted that assets are often tracked in various systems, including accounting, spreadsheets, and ticketing systems. They also addressed the issue of tracking assets allocated to employees, particularly when they leave the company, emphasizing the need to reclaim company property, especially devices containing sensitive data. https://www.watchguard.com/wgrd-security-hub/secplicity-blog/security-gap-lets-attackers-walk-right Equipment Disposal and Data Security Rick and Felicia discussed the implementation of a new policy regarding equipment disposal and data security. The policy now requires proper wiping and decommissioning of equipment before it can be given to departing employees, who can then purchase it if desired. They emphasized that the previous approach of simply giving equipment to employees without proper data wiping was ineffective and potentially harmful to the company's data security. Asset Inventory and Off-boarding Processes Felicia and Rick discussed the importance of maintaining an accurate asset inventory and proper off-boarding processes for systems. They highlighted how common it is to find stale data and unmanaged assets in systems like Active Directory and Bitdefender platforms, often due to lack of formal off-boarding procedures. Felicia emphasized that an asset management platform can be cost-effective and significantly improve system maintenance efficiency. IT Asset Inventory Management Discussion Felicia and Rick discussed the importance of maintaining accurate IT asset inventory and lifecycle tracking, emphasizing that relying solely on IT vendors for documentation is insufficient. They highlighted how understanding equipment lifecycles can help IT managers forecast future replacement costs and plan accordingly. The conversation then shifted to addressing challenges when dealing with clients who approach Managed Service Providers (MSPs) after undergoing formal assessments or audits conducted by accounting firms, with Felicia noting the need to distinguish between assessments and audits in the IT context. Traditional Security Assessment Limitations Rick and Felicia discussed the limitations of traditional security assessments conducted by accounting firms and less experienced providers. They agreed that many existing assessment tools and methods are outdated, particularly in modern cloud environments where traditional network discovery techniques no longer work effectively. Both expressed skepticism about the reliability of assessment data from less experienced firms, with Rick noting he always questions the tools used in such assessments. Assessment Report Scope Issues Rick and Felicia discussed issues with assessment reports, particularly when the scope and intent of the assessment are unclear. Rick explained that while this information might be found in the initial statement of work, it's not typically included in the final report, which can lead to questions about the report's legitimacy. Felicia expressed concern about the lack of clear scope information in reports, describing the situation as potentially indicating "amateur hour" work. Risk Assessment Method Discussion Felicia and Rick discussed their concerns about assessment approaches, with Felicia expressing that she prefers a focused risk-prioritization method rather than comprehensive audits. They agreed that organizations typically already know their major risks, and leadership interviews can quickly identify key concerns. The conversation ended with them beginning to discuss how to approach clients who come seeking help after an audit, though the specific details were not captured in the transcript. Security Implementation Challenges Discussion Felicia and Rick discussed common scenarios where organizations seek help after conducting initial assessments with other firms that lacked proper implementation expertise. Rick explained that when clients approach his team, they often have gaps in their previous assessments and have become overwhelmed. They both emphasized the importance of executive management buy-in for successful implementation of security controls, with Rick noting that his team will walk away if they don't have proper support from the top leadership. Cybersecurity Framework Implementation Discussion Rick and Felicia discussed the importance of proper cybersecurity framework implementation and the pitfalls of one-time vulnerability assessments. They agreed that organizations should first establish a policy and framework, then implement continuous monitoring tools rather than paying for external assessments. Felicia emphasized that organizations should own their tools and processes, while Rick acknowledged that most IT personnel and MSPs lack the security expertise to properly implement complex controls without creating additional risks.

February 26, 2026Episode 17122 min

M365 Secure Score: Unpacking the Hype vs. Reality

Topics Summary Join CTOs Felicia King and Shimon Magal for a candid, off-the-cuff conversation that pulls back the curtain on Microsoft Secure Score. They explore its strengths and sharp limitations—where it guides security improvements, where it pushes licensing, and why it falls short for real compliance and legal attestation. Through real-world MSP and enterprise scenarios, they reveal the importance of risk-prioritized, continuous configuration management, explain how compensating controls and human workflows matter, and outline why non-tamperable reporting and the right licensing are critical. Whether you’re an MSP or an in-house security leader, this episode challenges assumptions and offers a practical roadmap to turn Microsoft security metrics into defensible, actionable posture management. Shimon is the CTO for Optimize365.io https://www.optimize365.io/ Microsoft Secure Score Limitations Shimon and Felicia discussed the limitations of Microsoft's Secure Score tool, which Felicia described as being Microsoft-centric and not providing comprehensive compliance reports. They agreed that while Secure Score could be useful as a baseline assessment, organizations need more specific controls for compliance with frameworks like CIS, NIST, or HIPAA. Felicia emphasized that the tool's accuracy is crucial for meaningful risk assessment, though she acknowledged that technology assessments must evolve as the tools themselves change. Challenges with Secure Score Assessment Shimon and Felicia discussed the limitations and challenges of Secure Score, a Microsoft tool for assessing security posture. They highlighted that Secure Score's scoring system is not equally weighted across all aspects, making it difficult for organizations to improve in specific areas. Felicia emphasized that Secure Score is primarily used to sell more Microsoft licensing rather than providing meaningful insights for improving security. They also discussed the importance of generating legal attestation reports and tracking changes over time, which Secure Score does not support effectively. Felicia suggested the need for a more comprehensive assessment platform that can produce meaningful reports, facilitate workflows, and provide a customer-facing portal for better visibility and control. Enhancing Risk Assessment Tools Felicia and Shimon discussed the limitations of Secure Score, noting that it does not account for complementary tools or manual processes, which are crucial for compensating controls. They emphasized the importance of incorporating both technical and human components into risk-prioritized assessments and attestation workflows. Secure Score Compliance Challenges Felicia expressed deep concern about MSPs using Secure Score as a fee-based service without generating legally valid attestation reports, emphasizing the importance of non-tamperable documentation for legal proof and compliance. She highlighted the need for automated systems to generate and publish reports to a secure repository, ensuring retention policies align with legal requirements. Shimon agreed on the shortcomings of Secure Score for MSPs and the need for a robust workflow that includes documentation repositories to meet business and legal needs. M365 Licensing and Security Management Felicia discussed the importance of having the right licensing, such as Entra IDP2, to access proactive real-time controls and data from Microsoft 365. She emphasized that alerting and diagnostics tools like Petra Security and Optimize can be beneficial for MSPs, but they should not replace Entra IDP2 licensing. Felicia also stressed the need for consistent, regular proactive secure configuration management as a service, not a one-time project, and advised MSPs to ensure their M365 tenants have this service or have explicitly declined it.

February 23, 2026Episode 17028 min

When Contracts Fight Back: SMB Survival Strategies for Vendor Disputes

On Breakfast Bytes, host Felicia King sits down with Jane Conners—a California attorney with deep expertise in governance, risk, compliance, and the new frontier of AI privacy—to unpack a hidden threat stalking small and medium businesses: asymmetrical contract power. From click‑wrap traps and rogue shadow IT to agentic AI that quietly folds your data into someone else’s model, Jane frames a vivid narrative of how everyday procurement decisions can become serious legal battles. Through sharp anecdotes and practical rules of thumb—start renewals six months early, demand clear SLAs and exit language, insist on an ‘unlearn’ right, and adopt a stepped early dispute resolution process—Jane maps a fast, pragmatic path out of years‑long litigation nightmares. Tune in to learn how to turn diffuse legal risk into focused strategy and get back to running your business. Quick recap Felicia and Jane discussed dispute resolution mechanisms for small and medium-sized businesses (SMBs) in the context of vendor contracts, particularly focusing on asymmetrical bargaining power and the challenges SMBs face when negotiating with larger technology vendors. Jane explained the importance of implementing a structured procurement process and highlighted the benefits of early dispute resolution frameworks, which can help resolve disputes within 100 days through a four-step process involving executive-level negotiations and risk-adjusted value analysis. They discussed specific strategies for SMBs, including negotiating renewal terms 6 months in advance, being cautious with shadow IT that can lead to binding legal traps, and ensuring clear definitions around service security failures versus data breaches in contracts with MSPs and MSSPs. Jane also emphasized the need for SMBs to negotiate the right to "unlearn" their proprietary data from AI systems and to explicitly define liability caps in contracts. Small Business Contract Negotiation Strategies Jane discussed her background in dispute resolution and highlighted the challenges small businesses face when negotiating contracts with SaaS vendors and other service providers. She emphasized the increasing asymmetry in bargaining power, particularly with the rise of agentic AI, and the issue of click-wrap agreements that small businesses often accept without legal review. Jane suggested that small businesses should focus on developing effective strategies to protect themselves from liability and navigate disputes with vendors. Vendor Negotiation Strategies and Policies Felicia emphasized the impact of asymmetrical bargaining power in vendor relationships, urging small to medium businesses to develop rigorous procurement policies. Jane shared strategies for negotiating with vendors, highlighting the potential for significant price reductions if renewals are planned six months in advance. She also advised focusing on aspects beyond pricing, such as data privacy and security standards, and emphasized the need for clear exit strategies, particularly in the context of agentic AI. Negotiation Clauses for Business Contracts Jane and Felicia discussed the importance of negotiating clauses for unlearning and controlling costs in business contracts, particularly for enterprise clients and early-stage startups. They highlighted the need for clear processes around procurement to avoid unexpected expenses and risks. Jane also explained the different types of dispute resolution mechanisms available, including mediation, arbitration, and neutral case evaluation, emphasizing the importance of choosing the right process to resolve disputes efficiently. AI Dispute Resolution Platforms Jane explained a dispute resolution methodology that aims to resolve cases within 60 days, involving risk-adjusted value analysis and structured negotiations. She highlighted the use of digital first arbitration platforms, including JAMS, which have implemented new rules for AI and machine learning disputes. These platforms help contain technical discovery, manage security, and address unique conflicts related to AI training and utilization. Enhancing EDR for Business Success Jane discussed the challenges and inefficiencies of traditional arbitration and litigation, particularly for small and medium-sized businesses. She highlighted the benefits of early dispute resolution (EDR) frameworks, which involve a structured process to identify issues, assess risks, and facilitate principled negotiations. Jane emphasized the importance of clear contract terms, including specific service level agreements (SLAs) and liability caps, to protect businesses from vendor leverage and unexpected costs. She recommended that businesses review and modernize contracts 6 months before renewals, be vigilant about shadow IT, negotiate stepped ADR processes, and ensure the right to unlearn AI-driven data.

February 5, 2026Episode 16927 min

Don't Get Burned by AI: Governance Lessons for Small Business

Felicia King takes you inside a cautionary tale — from the head of a major cybersecurity agency accidentally feeding confidential memos into a public AI, to small businesses unknowingly making their data the price of a "free" account. Through sharp examples and blunt truth, she shows how missing policies, licenses, and training turn promising tools into breach vectors. Then she guides you through a practical playbook: the shared-responsibility model, paid licensing, demonstrable due care, and professional operational maturity. With vivid stories of project estimates, productivity boosts, and AI acting as an engineering assistant, Felicia reveals how the right guardrails can transform AI from a liability into the competitive edge that moves the impossible into the possible. Felicia discussed the importance of implementing proper governance structures and training for artificial intelligence technologies to prevent businesses from being victimized by them, highlighting the role of employees as potential security risks. She emphasized the need for consistent policies and risk management when using AI tools like ChatGPT and Copilot, while also addressing concerns about data privacy and proper licensing in financial technology. Felicia stressed the importance of operational maturity and shared responsibility in managing resources securely, particularly for small organizations, and discussed how AI can enhance business productivity and enable better project planning when guided by experienced professionals. Summary AI Governance and Employee Training Felicia discussed the importance of implementing governance structures and providing training for artificial intelligence technologies to prevent businesses from being victimized by them. She highlighted that employees often serve as the weakest link in cybersecurity, using a recent incident involving the head of CISA as an example. Felicia emphasized the need for consistent policies and training, even for high-ranking officials, to avoid exceptions that can lead to security breaches. AI Risk Management Strategies Felicia discussed the risks associated with using AI tools like ChatGPT and Copilot, emphasizing the need for proper risk management and operational maturity when implementing such technologies. She highlighted that while these tools can be beneficial, they also pose potential risks that need to be addressed through appropriate governance, controls, and training. Felicia used the example of bank wire transfers to illustrate how even basic technologies require risk management, and she suggested that similar principles should apply to AI usage in businesses. AI Licensing and Data Protection Felicia explained that using AI tools like ChatGPT requires a paid plan rather than a free one, as free plans often exploit user data. She used the example of Better Tracker, a tool designed for CFOs to automate and categorize technology expenses, emphasizing the importance of proper licensing and data protection in financial technology. FinTech Privacy and Security Concerns Felicia discussed the functionality of FinTech tools like Better Tracker, which connects to digital banking accounts to automate transaction data population into expense management platforms. She emphasized her decision not to use Better Tracker due to concerns about data privacy, as the service required connecting bank and credit card accounts, making users the product. Felicia also shared experiences of recent data breaches involving Microsoft 365 tenants, highlighting the importance of proper licensing and security measures for businesses. Shared Responsibility in Cloud Services Felicia explained the shared responsibility model between service providers like Microsoft and Google, and their customers, emphasizing that customers are primarily responsible for managing their rented accounts securely and professionally. She clarified that issues with Microsoft 365 tenants cannot be resolved by switching to Google Workspace, as both platforms follow similar shared responsibility models. Felicia also highlighted that customers need to ensure proper management of their resources to maintain privacy, security, and data availability. Operational Maturity and Security Management Felicia discussed the importance of operational maturity and shared responsibility in managing resources, emphasizing that businesses need to meet certain expectations to avoid higher costs and inconveniences due to outages and compromises. She highlighted the need for businesses to demonstrate due care and due diligence through technical controls and regular gaps assessments with implementation plans to limit liability in case of a breach. Felicia also mentioned her previous work on legal defensibility and security models, as well as insights from a breach attorney about the importance of proving demonstrable progress in security improvements over time. Cybersecurity Investment for Small Organizations Felicia discussed the importance of data protection and operational maturity for small organizations, highlighting that investing in cybersecurity measures, such as professional maintenance, can significantly impact an organization's security posture and readiness for technologies like AI. She emphasized that the cost of proactive cybersecurity measures, which she compared to maintaining a car for emergency situations, is minimal compared to the potential benefits, including improved operational stability and readiness for future opportunities. AI for Business Productivity Enhancement Felicia discussed the importance of AI in business survival, particularly in the face of a competitive squeeze that began in 2025. She emphasized that AI should be used to enhance the productivity of existing employees rather than focusing solely on hiring younger workers. Felicia explained that by providing AI tools like Copilot, along with customized training and fractional CTO guidance, companies can effectively double the value of their employees, particularly those earning higher salaries. AI and Experienced Engineers Collaboration Felicia discussed the importance of experienced engineers in leveraging AI for feasibility assessments and project planning. She emphasized that AI, when guided by experienced professionals, can transform impractical or impossible tasks into manageable ones by providing accurate time estimates and project plans. Felicia also highlighted that AI can reduce risks, boost staff productivity, and enable the development of in-house software, thereby reducing dependency on commercial off-the-shelf solutions.

January 5, 2026Episode 16827 min

Is the Signature Worth the Squeeze? The Truth About Centralized Email Signatures

Felicia King opens Breakfast Bytes with a sharp, practical question: is the “juice” you get from a centralized email signature platform worth the “squeeze” it takes to implement it? Through a series of real-world examples and clear stakes, she walks listeners from small teams that should keep signatures simple to larger organizations that need policy, tooling, and operational rigor. Along the way she exposes the conflict: marketing wants shiny banners, IT worries about deliverability and DNS changes, and third parties may see your outbound mail or inject tracking pixels. When signatures are mishandled, the consequence is not just ugly formatting — it can become a genuine business problem, even a “sales prevention” issue. Felicia closes with practical resolution: write a policy, empower managers, and choose platforms that preserve data sovereignty and utilize role-based control. It’s a compact, candid roadmap for anyone deciding whether to centralize email signatures — and how to do it without breaking email. Felicia discussed the implications of email signature management platforms, highlighting security risks and operational challenges while emphasizing the need for organizations to weigh benefits against potential drawbacks. She provided guidance on email signature policies, recommending manual management for small organizations and centralized systems for larger ones, while stressing the importance of written policies and technical implementation tools. Felicia advocated for empowering managers to independently handle email signatures through appropriate training and accountability, contrasting this approach with organizations that rely on IT support, and emphasized the benefits of centralized platforms for branding, compliance, and data integrity. Email Signature Management Security Risks Felicia discussed the implications of using email signature management platforms, emphasizing the need to weigh the benefits against potential security risks and operational challenges. She highlighted that email signatures can affect email deliverability, as elements like hyperlinks and embedded graphics are subject to security scanning by recipient email systems, potentially leading to emails being marked as spam or blocked. Felicia also noted that many platforms are IT-centric, limiting staff involvement, and suggested considering whether department managers could handle email signature management effectively. Email Signature Management Guidelines Felicia discussed email signature policies, explaining that organizations with fewer than 10 employees should manage signatures manually through a written policy and staff training. For larger organizations, she recommended implementing a centralized email signature management system to handle the increased volume of business. Email Signature Policy Implementation Felicia emphasized the importance of having a written email signature policy, especially for organizations with 10 or more employees, to prevent the inclusion of excessive hyperlinks in outbound emails, which can lead to poor email scores. She highlighted the need for technical policy implementation tools and advised against attempting to configure email security settings like SPF, DKIM, and DMARC without involving a CTO, as many IT professionals still struggle with these configurations. Felicia also stressed that requesting whitelisting from recipients due to poor email deliverability is counterproductive and undermines an organization's security posture. Email Signature Management Best Practices Felicia emphasized the importance of professional assistance for DNS record and email signature implementations, warning against self-service approaches that often lead to poor outcomes. She highlighted the need for organizations to remove existing email signatures from end-user devices and modify onboarding policies to prevent signature-related issues. Felicia also raised concerns about third-party email signature platforms' practices of injecting tracking pixels, suggesting that Crossware offers a more privacy-friendly solution by deploying its platform in the client's own Azure tenant. Email Signature Management Empowerment Felicia discussed the benefits of hosting email management platforms, emphasizing data sovereignty and control over email visibility. She highlighted the importance of empowering managers to directly manage email signatures for their teams, rather than relying on the IT department. Felicia suggested a tool that allows authorized individuals to manage email signatures for specific groups within an organization, avoiding broad administrative access that could lead to inefficiencies in larger or more complex entities. Email Signature Management Empowerment Felicia emphasized the importance of empowering employees to manage their email signatures independently, requiring operational maturity and clear policies. She argued against the common practice of involving IT to assist managers with email signature management, advocating instead for mandatory training and accountability for managers to handle this responsibility themselves. Felicia contrasted this approach with organizations that rely on IT for support, highlighting that the latter approach does not lead to sustainable improvements and fosters inefficiency. Centralized Email Signature Management Platform Felicia discussed the importance of implementing a centralized email signature management platform, emphasizing the need for empowerment and accountability rather than IT-led support. She highlighted the benefits of such a platform, including consistent branding, legal compliance, and data integrity, while also addressing potential challenges like marketing overreach and rogue employee behavior. Felicia recommended a self-hosted Azure instance for data sovereignty, outlined cost considerations, and stressed the importance of proper implementation and staff accountability. She concluded by encouraging thoughtful planning and the use of good criteria to differentiate between platforms.

December 4, 2025Episode 16728 min

AI, Fraud & the CTO: Navigating Counterparty Risk

Host Felicia King weaves a sharp, personal narrative that ties together AI, fraud, vendor selection, and the critical role of a competent CTO. With candid anecdotes and hard-earned lessons, she explains why tightly-scoped AI — used by skilled experts with robust governance — can feel like a $150K colleague, and why poorly governed AI or flashy vendor promises can be catastrophic. Felicia recounts real examples: AI misestimating project hours, DDoS services sold as a bargain that hide downstream costs, and an enterprise outsourcing APIs to a freelance developer — each story revealing the hidden risks that lurk when counterparty relationships, transparency, and technical competency are ignored. Through clear guidance and provocative questions about trust and vendor behavior, she urges listeners to prioritize people they know, insist on disclosure, and secure CTO-level expertise to interpret AI claims and perform rigorous risk assessments. This episode is a practical wake-up call for leaders navigating the modern intersection of AI and operational risk. Quick recap Felicia discussed the proper implementation of artificial intelligence in business operations, emphasizing its value as a tool when used correctly under human oversight. She addressed the growing threat of AI-driven fraud and the importance of robust identity verification processes, introducing a service to help build trust between service providers and customers. Felicia stressed the significance of selecting IT vendors based on trust and transparency, advocating for the role of a Chief Technology Officer to navigate complex technical and business risks while ensuring proper risk management and security standards are maintained. AI Implementation and Human Oversight Felicia discussed the convergence of several interconnected topics, including artificial intelligence, fraud detection, and vendor selection. She emphasized the importance of proper AI implementation, highlighting its potential to act as a valuable asset when used correctly. Felicia also addressed the limitations of AI, noting that it excels at analyzing pre-engineered designs but should not be relied upon to create them. She stressed the need for human oversight and expertise when using AI tools, cautioning against the dangers of substituting AI for skilled professionals in critical roles. AI Fraud Prevention Strategies Felicia discussed the increasing threat of AI-driven fraud, highlighting the low financial and time investment required for criminals to create convincing deepfakes. She emphasized the importance of robust Know Your Customer (KYC) processes and multi-factor authentication, noting that these systems often create unnecessary friction for non-technical users. Felicia introduced a service called Professional Residential to address these issues, providing ongoing training and support to build trust between service providers and customers. She also explained the importance of validating customer identities, particularly for sensitive operations like vault access, and stressed that effective fraud prevention relies on maintaining consistent, human relationships with customers. Trust and Transparency in IT Vendors Felicia discussed the importance of selecting IT service providers based on trust and transparency rather than solely on technical metrics or past performance. She emphasized the need for open communication and mutual trust, warning against vendors who might be dishonest or introduce counterparty risk. Felicia also highlighted the importance of understanding the technical details of a vendor's offerings, using an example of a UCAS system where she discovered undisclosed technology through AI analysis. CTO's Role in Risk Management Felicia discussed the importance of having a Chief Technology Officer (CTO) to navigate complex technical and business risks. She shared examples of issues that could arise without proper risk assessment, such as high costs for unneeded services and lack of visibility into traffic. Felicia emphasized that only a CTO could identify these risks and make informed decisions. She also highlighted the dangers of using APIs without adhering to security standards and the importance of supply chain risk management. Felicia concluded that organizations need a CTO to help navigate these complex issues and avoid being vulnerable to potential threats.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts