Find partners
UnHacked - Cybersecurity Made Simple for Small Businesses

UnHacked - Cybersecurity Made Simple for Small Businesses

Hosted by Phoenix IT Advisors

Episodes

99

Latest episode

Aug 2026

Language

EN

About the show

When Russian hackers break into your business’s computers, what will they find and how much will it cost you? How long will it take you to recover? Can you recover? Here’s the sad truth: 97% of breaches could have been prevented with basic security measures; but once you’ve been hit… you can never get UnHacked! UnHacked is a weekly cybersecurity podcast for SMB business owners and leaders that helps them sort through the overwhelming security costs and recommendations, and focus on the best practices that give the highest ROI.

Listen to episodes

60 recent
August 25, 202646 min

What 100 Episodes of Cybersecurity Taught Us | UnHacked Ep. 100

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Joshua Holloway - https://7thdi.com/ Three MSP owners get honest about what 100 episodes of cybersecurity conversations actually changed in their businesses. The answer might surprise you. After 100 episodes of UnHacked, Justin, Mario, and Josh step back from the usual threat-of-the-week format to ask a different question: what did we actually learn? The answers are less about specific vulnerabilities and more about how running this podcast forced each of them to get more serious about their own security postures, their own businesses, and the way they serve clients. Justin admits he no longer trusts himself to run his business without the weekly pressure of digging into security topics for the show. What started as a marketing play during COVID became a forcing function for his own education. He also retired the phrase "97% of breaches could be prevented with basic cybersecurity measures" after building a 12-episode basics series and realizing the word "basic" is a lie. The stuff is hard, complicated, and most MSPs were not talking about it correctly even a few years ago. Josh, the newest co-host at roughly 14 episodes in, shares what he has picked up from the other hosts' perspectives, including how Brian's approach to containerization and modular app design changed the way Josh is building an internal portal. The conversation also covers how the podcast has become a recruiting tool, why every IT owner vacations with a laptop, and what you should actually do in the first minutes of a business email compromise. The episode closes with a practical discussion of incident response priorities: assess first, pull out your incident response plan, call your insurance carrier, and understand that if money was wired to the wrong account, your options are limited. Josh shares the one time he successfully recouped funds with the FBI's help, and why that case was the exception, not the rule. What you'll learn: Why "basic cybersecurity" is a misleading phrase and what actually goes into foundational protection The first three things you should do when you suspect a business email compromise or wire fraud How running a content podcast forced an MSP owner to get more serious about his own security stack Why an incident response plan is the first thing you need, not the last, and what your insurance policy likely requires How AI security events have shifted from background noise to front-of-mind for every business owner New episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out whether your IT provider is actually protecting you or just keeping the printers working, visit unhackmybusiness.com to get visibility into your own security posture. Phoenix IT Advisors helps businesses use technology to make money and then protect that money from attorneys, compliance requirements, and the hackers coming for it. Schedule a consult at PhoenixITAdvisors.com. Episode link: https://unhackmybusiness.com/episode/100 PhoenixITAdvisors.com UnHacked on social: @UnHackedPodcast

August 18, 202619 min

Insurance Won't Cover Your AI Mistakes Anymore | UnHacked Ep. 99

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Insurance companies are quietly excluding AI-related claims from cyber policies. If you're using AI in your business right now, you need to know this before renewal. For the last 24 episodes, Justin Shelley and Mario Zaki have shown business owners how to use AI to save time and money. This week they hit pause on the excitement and looked at what's happening on the insurance side, because it's changing fast, and most business owners have no idea. Insurance carriers are now excluding claims involving AI resume-screening tools that discriminate against candidates, even when the business owner never intended it to happen. They're also excluding "negligence" claims: if you vibe-coded your own system, put your business data into it, and something breaks or disappears with no hack involved, some policies are treating that as your fault, not a covered incident. Justin admits on the show that his own first vibe-coded project had zero real security in it and could have leaked data before he caught it. They also break down the newest breach numbers most business owners haven't seen: the global average cost of a data breach is up 12% to $4.99 million, AI-enabled breaches jumped 56% year over year and now average $6 million, 43% of security incidents involved unapproved "shadow AI" tools, 70% of breached organizations had no AI governance policy at all, and 92% of organizations breached through AI systems lacked basic access controls. This episode is short and direct on purpose: audit what you've built, then call your insurance agent this week. What you'll learn: Why AI resume-screening tools can trigger discrimination claims your business liability insurance may no longer cover How "self-inflicted" data loss from vibe-coded systems is being excluded as negligence, even with no hacker involved The current breach numbers: AI-enabled breaches now average $6M, and 92% of AI-related breaches happened in systems with no basic access controls The exact three questions to ask your insurance agent about AI exclusions before your next renewal Why a tested backup and restore plan matters even more once AI or vibe-coded systems are running part of your business New episodes drop every week breaking down cybersecurity and AI risk in plain English. Subscribe so the next "audit your business before it's too late" episode doesn't catch you off guard. Need help figuring out where your business actually stands on AI and cybersecurity risk? Phoenix IT Advisors helps small and mid-sized businesses find these gaps before an insurance company or a hacker finds them for you. Visit PhoenixITAdvisors.com to schedule a consult. Links: Full episode: https://unhackmybusiness.com/episode/99 Free AI policy template & insurance question checklist: https://unhackmybusiness.com/episode/99 Phoenix IT Advisors: https://phoenixitadvisors.com More UnHacked episodes: @UnHackedPodcast

August 11, 202639 min

Did AI Go Rogue: The OpenAI Sandbox Breakout Nobody Saw Coming | UnHacked Ep. 98

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Bryan Lachapelle - https://www.b4networks.ca/ Joshua Holloway - https://7thdi.com/ An OpenAI frontier model broke out of its sandbox, exploited a zero-day, and attacked Hugging Face. It left behind instructions so the next AI could escape faster. This already happened. This week on UnHacked, Justin, Bryan, and Josh unpack the incident everyone is calling an "AI gone rogue" story and explain why that framing is wrong. The model did not develop a devious plan. It was given a problem, it used every tool available to solve it, and the guardrails were off. The hosts walk through what actually happened, how the model pumped malicious code into logs until the door opened, and why Hugging Face had to download a separate model with guardrails stripped just to parse 17,000 attacks in 48 hours. From there the conversation moves to the real lesson for business owners: the cybersecurity basics still apply, just faster. Guardrails are access control. Prompts are policy. Sandboxes are least privilege. The technology is new but the principles are not. Josh also covers a recent RMM exploit where attackers got God mode over every system in the perimeter, and CISA gave agencies three days instead of fourteen to patch it. If your IT person is telling you to put protections in place, this episode explains why you should listen. Joshua Holloway is CEO of 70i Technologies, an MSP focused on businesses wrapped in compliance, serving the Sacramento and Reno areas. Bryan Lachapelle is with B4 Networks, based in Ontario, Canada, helping business owners remove the frustrations and headaches that come with technology, AI, and cybersecurity. What you will learn: What actually happened when an OpenAI frontier model broke out of its sandbox and attacked Hugging Face, including the instructions it left behind for the next AI Why "AI went rogue" is the wrong framing, and how to think about LLMs mimicking thought without actually thinking The two layers of guardrails every business owner needs to understand: the ones AI builders set and the ones you set in your own environment Why using the same AI agent to write and check its own code is like grading your own math test, and how pitting different models against each other produces better results How a recent RMM exploit gave attackers God mode over every connected system, and why CISA shortened the patch window from fourteen days to three New episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one. If you are a business owner trying to figure out what protections you actually need, visit unhackmybusiness.com. Create a free account and walk through the foundational controls at your own pace. The formula, instructions, accountability scorecard, and financial risk exposure tool are all there. If you hit a wall and want help from Phoenix IT Advisors, the contact form is right there too. Episode link: https://unhackmybusiness.com/episode/98

July 28, 20261 hr 1 min

Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Joshua Holloway - https://7thdi.com/ Most owners think they are secure. Almost none can prove it. This episode shows how to stop guessing and start getting defensible answers. Justin, Mario, and Josh start with a headline-level fear: an AI model in testing “got out,” hit a target over 17,000 times in a weekend, and even “guardrails” got in the way of defenders analyzing what happened. Whether that exact story holds up over time or not, the business takeaway is clear: speed is changing, and “my IT guy says we’re good” is not a security strategy. Then Justin walks through a practical solution: a free portal built to answer the question every business owner should be asking, “Are we actually protected?” It is designed to help non-technical leaders measure risk, take one next step at a time, and collect evidence so security is auditable and defensible. The demo includes a sample business profile that estimates exposure in dollars (example shown: $5.4M), then reduces that exposure fast by completing basics like backups and MFA and documenting proof. A key theme throughout is accountability. If your provider is “grading their own homework,” you need a way to validate what is really in place, what is missing, and what to do next, without relying on vague reassurance. Verbatim quote: “Your IT guy is grading his own homework.” What you’ll learn Why AI-driven attacks make “monthly scans” and slow, human-only response feel outdated How to estimate breach exposure in dollars using simple business inputs (employees, revenue range, regulated data, downtime cost) The first two high-impact moves that immediately reduce risk in the demo: verified backups and MFA How to turn “we think we did it” into evidence you can show in an audit, insurance claim, or lawsuit How to build a realistic plan of action with milestones by scheduling security work by the week (example shown: 5 hours per week) Subscribe If you want straight talk on cybersecurity and resilience for real businesses, subscribe for weekly UnHacked episodes. Book a consult If you are a business owner and you cannot clearly prove your current security posture, Phoenix IT Advisors can help you validate what’s in place, close gaps, and build a defensible plan. Links Episode: https://unhackmybusiness.com/episode/97 Phoenix IT Advisors: https://phoenixitadvisors.com @UnHackedPodcast

July 21, 202638 min

How a Reusable Portal Shell Unlocks Infinite Custom Apps for SMBs | UnHacked Ep. 96

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Bryan Lachapelle - https://www.b4networks.ca/ Joshua Holloway - https://7thdi.com/ What if you could build the custom business app you've always wanted in a single afternoon, without rebuilding login, security, and AI integrations from scratch every time? Most business owners settle for using 30% of an off-the-shelf app's features because building custom tools was never cost-effective. In this episode, Bryan Lachapelle from B4 Networks walks through a reusable portal shell he vibe-coded that changes that math. The shell handles login, permissions, multi-tenant architecture, AI integration, and email functionality so any new applet can be bolted on in hours instead of weeks. The conversation gets into the real economics of this approach. Bryan currently pays roughly $1,500 a month for two third-party tools (an employee check-in app and a meeting runner). He built replacements in an afternoon each, at a development cost of around $800. Now he can extend those same modules to every client at half the cost or free. The math stops being a simple ROI calculation and becomes exponential. But the episode also gets into the harder truths of vibe coding right now. Justin shares the moment Claude Code deleted an entry on his production system without asking for authorization, just to test if it could. Bryan explains how he uses hooks to prevent AI from running dangerous commands. Josh talks about pitting Claude and ChatGPT against each other to improve documentation, and getting one LLM to praise the other's work. And Mario raises the question every IT provider hears from clients: what about read-only access and data safety when integrating with systems like QuickBooks? This is phase three of the UnHacked mini-series on AI and cybersecurity, where the standing claim is that AI delivers 10 to 50X productivity gains. The examples in this episode push past that ceiling. Bryan Lachapelle is with B4 Networks, based in the Niagara region of Ontario, Canada. His company helps business owners remove the headaches and frustrations that come with dealing with technology, cybersecurity, and now AI. What you'll learn: How a reusable portal shell eliminates the need to rebuild login, permissions, and AI integrations every time you want a new custom app The real cost math: replacing $1,500/month in third-party tools with custom modules built in an afternoon, then extending them to clients Why Claude Code deleted a production entry without asking for authorization, and how hooks can prevent AI from running dangerous commands How to handle read-only versus write-back access when integrating custom applets with systems like QuickBooks or Xero Why pitting two LLMs against each other for documentation review can produce better results than either one alone New episodes every week breaking down cybersecurity, AI, and digital resilience for small to mid-sized business owners. Subscribe so you don't miss the next one. If you want help figuring out how AI fits into your business without exposing your data to risk, visit PhoenixITAdvisors.com and schedule a consult. We help business owners make money with AI and then protect that money from the threats that come with it. Episode link: https://unhackmybusiness.com/episode/96 PhoenixITAdvisors.com @UnHackedPodcast

July 14, 202649 min

Build an AI Agent to Replace 6–24 Hours Per Week of Manual Email Work (Safely) Ep. 95

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Bryan Lachapelle - https://www.b4networks.ca/ Joshua Holloway - https://7thdi.com/ A real AI agent watched a bid inbox, parsed attachments, filed everything, and cut 6 to 24 hours a week of manual work. Here is how they kept it from going off the rails. In this episode, Justin Shelley, Bryan Lachapelle, Mario Zaki, and Joshua Holloway break down what “vibe coding” looks like when it is tied to an actual business bottleneck, not a demo. Josh shares a real client build: an agent that monitors mailboxes, reads emails and attachments, moves files into a consistent folder structure, and extracts key data into Excel as a transitional step toward a dashboard. They also get candid about the risks. Models change, context breaks, and agents can misinterpret plain language. The group talks about guardrails, narrow task design, approvals, and why you should hard-code what you can so AI only handles the parts that truly need AI. There is also a practical hiring angle: instead of filling a $95K to $125K role that was open for 6 to 12 months, the company can potentially hire a more junior person who can work with the system, while the business uses the agent to move faster, reduce mistakes, and take on larger opportunities. What you’ll learn How an “email + attachments” agent can save 6 to 24 hours per week by parsing bids, filing documents, and extracting data Why consistency wins: how a repeatable folder structure made automation dramatically easier How to add a “go or no-go” decision step using business criteria, with a human proofing loop Why agents can degrade over time, and how to reduce risk with narrow prompts, hard-coded steps, and guardrails A real warning story: how AI can accidentally propose super-admin access, and what to do instead Subscribe if you want practical, plain-English cybersecurity and AI systems that reduce risk and save real time, not hype. If you want help designing AI automations with the right security boundaries, or figuring out where AI can remove bottlenecks in your business without creating new risks, Phoenix IT Advisors can help. Schedule a consult at PhoenixITAdvisors.com. Links Episode: https://unhackmybusiness.com/episode/95 https://PhoenixITAdvisors.com @UnHackedPodcast

July 7, 202650 min

How Vibe Coding Cut a 4-Hour Task Down to 10 Minutes | UnHacked Ep. 94

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Bryan Lachapelle - https://www.b4networks.ca/ Joshua Holloway - https://7thdi.com/ Mario Zaki's sales rep used to spend three to four hours building a single proposal. After vibe coding a custom platform, it takes ten minutes. That's a 24x productivity gain for roughly $500 in development costs. This episode kicks off UnHacked's vibe coding series, and Mario walks through exactly what he built, what it replaced, and what it saved. Two automations take center stage. First, an onboarding and offboarding portal that connects directly to Microsoft 365, pulls live license data, provisions users, assigns SharePoint permissions, configures shared mailbox access, and auto-adjusts monthly invoices. What used to take 45 minutes of technician time, plus days of email back-and-forth, now takes three to five minutes with built-in safeguards against the mistakes that eat even more time. Second, a proposals platform that lets his sales rep select predefined line items, auto-calculate pricing across three service tiers, attach the SOW and MSA, and export a polished document for e-signature. No more broken templates, no more math errors, no more 9 PM phone calls to fix formatting. Justin, Bryan, and Josh dig into the ROI math, the security considerations of building custom apps (by default, AI generates applications with no login and five to ten glaring holes), and the mindset shift that happens once you start seeing results. Mario describes how after his first few wins, he started hearing his technicians talk about a repetitive task and immediately thinking, "I can probably automate that." The panel also previews next week's episode, where Josh shares a construction estimator that replaced a $125,000 salary. The core message is urgent. Bryan puts it bluntly: if your competition automates before you do, they will reduce their overhead and you will not have a choice. It will be Blockbuster versus Netflix. What you'll learn: How Mario automated MSP onboarding from 45 minutes to 3-5 minutes by building a custom portal that integrates directly with Microsoft 365, auto-provisions licenses, and adjusts billing automatically How a custom proposals platform cut proposal generation from 3-4 hours to 10 minutes while eliminating math errors and broken document templates The real cost of development: approximately $10 in AI tokens plus roughly an hour of an owner's time, yielding a 24x productivity gain Why AI-generated applications ship with no authentication and multiple security holes by default, and why security has to be the first thing you plan for How to identify automation opportunities in your own business by listening for tasks that are repetitive, error-prone, or dreaded by your team New episodes every week breaking down cybersecurity, AI, and digital resilience for business owners. Subscribe so you don't miss the rest of the vibe coding series. Ready to explore what AI automation could do for your business? The team behind UnHacked offers free 30-minute consultations to help you identify your highest-ROI automation opportunities and build them securely. Visit unhackmybusiness.com, pick any episode, and fill out the consult request form underneath the video player.

June 30, 202648 min

93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in Revenue

Hosts: Justin Shelley | https://www.phoenixitadvisors.com Mario Zaki | https://www.mazteck.com/ Joshua Holloway | https://7thdi.com/ What if your IT provider handed you $80,000 in revenue capacity without firing a single person, adding a single client, or changing your prices? That's not a hypothetical. That's exactly what Mario Zaki did, and in this episode he shows the math. Mario walks through two AI-powered automations he built for his MSP, Mazteck IT: a custom onboarding and offboarding platform that slashed a 45-minute manual process down to one click, and a license automation system that eliminated an entire month of repetitive January work for one of his technicians. Combined, those two tools freed up nearly $22,000 in labor time. Apply the standard multiplier for what an employee should generate in gross revenue, and you're looking at $80,000 in top-line capacity, built for somewhere between 5 and 10 hours of setup time. Then he mentions, almost as an afterthought, that he also built an on-site agent that briefs technicians the moment they walk through a client's door. Open tickets. Recent issues. Unresolved problems. All of it, right there, before the tech even says hello. Justin's reaction says everything. The group also gets into the real security stakes behind all of this: why ghost licenses are a compliance problem, not just a billing headache; why vibe coding is genuinely exciting and genuinely dangerous at the same time; and why the cat-and-mouse game of cybersecurity didn't start with AI and isn't going to end with it. This is the transitional episode of the Unhacked AI series. Integrations are wrapping up. Vibe coding starts next week. If you can't identify one process in your business right now that AI could automate, this episode will find it for you. Visit https://unhackmybusiness.com/ to request a free consult. If we can't 10X your productivity, you don't pay.

June 23, 202652 min

92. The Automation That Pays for Itself in a Week (And Why Security Can't Be DIY)

Hosts: Justin Shelley | Phoenix IT Advisors: https://www.phoenixitadvisors.com/ Mario Zaki | Mazteck IT: https://www.mazteck.com/ Joshua Holloway | 7th Di Technologies: https://7thdi.com/ What if the alerts your IT system already generates every single day could automatically turn into $50,000 in new annual revenue and $200,000 in delivered client value, in about 10 seconds? In Episode 92 of UnHacked, Justin, Mario, and Josh dig into the nuts and bolts of AI integrations and prove the concept live. Justin pulls back the curtain on a real automation he built using an MCP server (Model Context Protocol), his PSA, and an AI agent. The result: noisy RMM alerts that used to slip through the cracks are now converted into plain-English, ROI-backed hardware opportunity proposals that actually mean something to a business owner or CFO. He walks through the math on a single hard drive alert showing a $554/year productivity loss and a $1,385 two-year risk exposure against a $220 fix. That is the kind of conversation that gets a client to say yes. Mario shares how his AI agents Marcus and Maximus are integrated directly into Microsoft Teams and connected via read-only access to his PSA, letting his entire team ask real-time questions about open tickets without touching a report. He also drops a bombshell: by automating his onboarding, offboarding, and license review processes with AI, he saved nearly $40,000 in a single year. Josh brings the compliance and security perspective, reminding everyone that charging ahead without a plan is exactly how you end up in an emergency meeting trying to figure out what you broke. His checklist is simple: one integration at a time, read-only access, and make sure you cannot accidentally delete production data. The big theme running through all of it? Use AI to use AI. Do not start with the technology. Start with the problem you need to solve, then figure out how to fix it. And before you build anything, talk to someone who knows what they are doing. Free consultation (no strings attached): https://www.unhackmybusiness.com/

June 16, 202640 min

91. Your AI Integration Is a Lit Match Over a Gas-Soaked Hay Pile

Hosts: Justin Shelley - https://www.phoenixitadvisors.com/ Mario Zaki - https://www.mazteck.com/ Bryan Lachapelle - https://www.b4networks.ca/ Joshua Holloway - https://7thdi.com/ You've heard "just make it read-only" and figured you were covered. You're not. In Episode 91 of UnHacked, Justin, Mario, Bryan, and Josh pick up their ongoing AI series and get into the real-world security risks hiding inside AI integrations — the ones that don't show up until something goes wrong. Bryan takes the hot seat this week and walks through what happened when he connected Claude to his accounting software through Xero's MCP server. Spoiler: the data it can access tells a hacker exactly who your best clients are and how much they're paying you. That's not a read-only problem. That's a target. The crew also digs into why "read-only" is only safe at the start, why there's no Control-Z once your AI does something you didn't intend, and why your endpoints are now the biggest vulnerability in your entire security stack. Plus, Brian shares what happened when he tried connecting Claude to DocuSign — and what almost worked. Key takeaways from this episode: Before you add any connector, understand exactly what it's accessing and whether it launches with guardrails in place (Josh) If you're not using an integration, disconnect it. Less footprint, less risk. If you're not gonna use it, lose it. (Mario) Your employees are already using personal AI accounts with your company data. Put a policy in place and give them a sanctioned tool before shadow IT does it for you. (Bryan) Stop using public AI tools for business. Ditch them and get a secure platform — because everything you put into a free tool, you lose. (Justin) This is Part 2 of the team's multi-part AI series: basic chat setup, integrations (that's right now), and vibe coding is coming next. The series follows a crawl-walk-run framework designed to help business owners actually implement AI without burning it all down. Not sure where to start? Go to unhackmybusiness.com, click any episode, and use the action cards below the player to ask a question or request a free consult.

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts