Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
History
TV & Film
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/c4/8c/82/c48c82ac-996a-5393-2e52-d02bd6004fa5/mza_10583684370011003460.jpg/600x600bb.jpg
Don't Be A Sitting Duck Podcast
Leigh Kefford
54 episodes
3 days ago
Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!
Show more...
Technology
RSS
All content for Don't Be A Sitting Duck Podcast is the property of Leigh Kefford and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!
Show more...
Technology
Episodes (20/54)
Don't Be A Sitting Duck Podcast
Sydney University & iiNet Cyber Breaches: What Businesses Must Learn

In this episode of the Don’t Be A Sitting Duck Podcast, we explore two recent and impactful Australian cyber incidents — the University of Sydney data breach and the iiNet customer data exposure. We explain how attackers gained access, what kinds of data were compromised, and most importantly, share actionable advice for businesses to reduce their risk of similar breaches.

Main Stories Covered:

  • University of Sydney cyberattack: Personal data of current and former staff, students and alumni accessed via a code library.
  • iiNet cyber breach: Contact details and account information from ~280,000 customers exposed through stolen employee credentials.

Key Takeaways:

  • Legacy systems and forgotten data repositories can be prime targets — don’t ignore them.
  • Stolen credentials are often all a cybercriminal needs to begin a breach.
  • Multi-factor authentication and strong access controls are essential.
  • Staff training on credential security and phishing awareness is critical.

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

View Show Notes and full transcript here: https://sittingduck.com.au/podcast/sydney-university-iinet-cyber-breaches-what-businesses-must-learn/

Show more...
4 days ago
5 minutes 47 seconds

Don't Be A Sitting Duck Podcast
CPS 234 Explained: Why Cyber Security Is a Board Issue

Cyber security is no longer just an IT problem—it’s a board-level responsibility. In this episode, Leigh Kefford breaks down APRA’s CPS 234 Information Security standard in plain English, explaining what it requires, why regulators care, and what happens when controls fail.

We unpack board accountability, third-party risk, security testing, and incident response obligations—and why CPS 234 is fast becoming the benchmark for all Australian businesses, not just banks and insurers.

If your organisation handles sensitive data, relies on cloud providers, or assumes “it won’t happen to us,” this episode is essential listening.

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

View Show Notes and full transcript here: https://sittingduck.com.au/podcast/cps-234-explained-why-cyber-security-is-a-board-issue/

Show more...
2 weeks ago
7 minutes 5 seconds

Don't Be A Sitting Duck Podcast
Day 12: Your Phishing Defence Checklist — The Complete Guide

Day 12 — The Grand Finale of the National PC 12 Days of Phishmas!

 

This episode brings together everything covered throughoutthe series into a complete, actionable Phishing Defence Checklist. You’ll learn:

 

  • The essential controls all businesses need
  • Email, identity, device & cloud protections
  • User behaviour improvements
  • Backup & recovery readiness
  • Tips for suppliers, payments & culture

 Book your free Empower Systems Assessment:

https://nationalpc.com.au/empower

 

🎧 More episodes & resources:

https://sittingduck.com.au

Show more...
3 weeks ago
4 minutes 53 seconds

Don't Be A Sitting Duck Podcast
Day 11: User Behaviour — The #1 Cybersecurity Risk

Day 11 of the National PC 12 Days of Phishmas!

 

Today we explore why user behaviour is the biggestcybersecurity risk for every organisation.

Technology alone can't protect your business — people playthe defining role.

 

In this episode:

  • Why humans are targeted
  • How attackers use trust & urgency
  • The psychology behind phishing
  • What data harvesting reveals
  • How to reduce human error
  • How to build a culture of cybersecurity

🛡 Empower Systems Assessment:

https://nationalpc.com.au/empower


🎧 More episodes:

https://sittingduck.com.au

Show more...
3 weeks ago
4 minutes 47 seconds

Don't Be A Sitting Duck Podcast
Day 10: The Ransomware Attack Chain — How One Click Leads to Disaster

Day 10 of the National PC 12 Days of Phishmas!

 

Ransomware attacks don’t start with encryption — they startwith access, usually through a phishing email.

This episode breaks down each stage of the ransomware attack chain and shows how to stop it early.

 

You’ll learn:

  •  How attackers gain initialaccess
  • What lateral movement lookslike
  • How payloads are deployed
  • Why backups get targeted
  • How extortion and data theftwork
  • The key defences that breakthe chain

https://nationalpc.com.au/empower

 🎧 More episodes:

https://sittingduck.com.au

Show more...
3 weeks ago
4 minutes 49 seconds

Don't Be A Sitting Duck Podcast
Day 9: Social Engineering & Data Harvesting — How Attackers Study You Before They Strike

Day 9 of the National PC 12 Days of Phishmas!

 

Cybercriminals don’t always break into systems — sometimesthey break into people.

This episode explores how scammers use publicly availableinformation, emotional manipulation, and behavioural cues to create targetedattacks.

 In this episode:

  •  Where attackers gather information
  • How social engineering manipulates users
  • Why emotions create cyber vulnerabilities
  • How attackers use context to increase success
  • What businesses can do to reduce risk

🛡 Book your free Empower Systems Assessment:

https://nationalpc.com.au/empower


🎧 More episodes:

https://sittingduck.com.au

Show more...
3 weeks ago
3 minutes 46 seconds

Don't Be A Sitting Duck Podcast
Day 8: Account Takeover & Hijacked Email Threads — When Cybercriminals Become You

Day 8 of the National PC 12 Days of Phishmas!

 

Today we’re breaking down Account Takeover (ATO) andHijacked Email Threads — two of the most convincing and damaging forms of phishing.

In this episode:

  •  How attackers gain access to real inboxes
  • Why hijacked threads are so effective
  • What signs to look for
  • How these attacks lead to financial loss
  • The essential steps to protect your organisation

 🛡 Book your free Empower Systems Assessment:

https://nationalpc.com.au/empower

 

🎧 More episodes:

https://sittingduck.com.au

Show more...
4 weeks ago
3 minutes 32 seconds

Don't Be A Sitting Duck Podcast
Day 6: Malicious Attachments & Cloud File Scams — The Hidden Threat in Your Inbox

Why fake documents and shared file links are one of the most dangerous phishing threats for businesses.Day 6 of the 12 Days of Phishmas!

Today’s episode breaks down one of the biggest ways cybercriminals gain access to your systems: malicious attachments and cloud file impersonation.


These scams use fake PDFs, ZIP files, SharePoint links, OneDrive invites, and Google Drive notifications to infect your device or steal your credentials.

In this episode:

  • How malicious attachments deliver malware
  • Why fake cloud links are so convincing
  • Real examples from Australian businesses
  • What happens after you click
  • How to protect your staff and systems

🛡️ Book your free Empower Systems Assessment:

https://nationalpc.com.au/empower


🎧 More episodes & resources:

https://sittingduck.com.au

Show more...
4 weeks ago
5 minutes 8 seconds

Don't Be A Sitting Duck Podcast
Day 1: The Most Common Phishing Red Flags — What to Watch For

🎄 Welcome to Day 1 of the 12 Days of Phishmas!

We’re kicking off the series with the foundation of all cyber awareness:

🔍 The Most Common Phishing Red Flags

These are the warning signs scammers can’t hide — the little clues that tell you something isn’t right.
And understanding them can prevent the vast majority of cyber incidents.

In this episode, I break down:

  • The red flags hidden inside phishing emails
  • Why scammers rely on small details to trick people
  • How formatting, urgency, and sender details give them away
  • Real-world examples I see in Australian businesses
  • What you can do to protect yourself and your team

Most cyberattacks start with a single email.
Learning the early red flags is one of the simplest, most powerful defences you can build.


🛡 Want more tools to protect your business?
Book your free Empower Systems Assessment:
nationalpc.com.au/empower

🎧 Explore more episodes and resources at:
sittingduck.com.au

📘 Check out the audiobook:
Sitting Duck – The Phone Call You Don’t Want To Receive

Have a question? Reach out on LinkedIn — We're always happy to help. Stay safe, stay sceptical…
And don’t be a sitting duck.

Show more...
1 month ago
4 minutes 7 seconds

Don't Be A Sitting Duck Podcast
Australia’s Retailers Are Quietly Bringing Back Facial Recognition

Australian retailers are quietly reintroducing facial recognition technology—even after public backlash. In this episode, Leigh breaks down why stores are turning to AI-driven biometric surveillance, what risks it creates for customers, and why business leaders should think carefully before deploying similar tools.


We explore how the technology works, why it’s making a comeback, and the serious privacy, ethical, and governance implications you need to understand. Plus, practical advice for businesses considering advanced security systems.


This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

View Show Notes and full transcript here: https://sittingduck.com.au/podcast/australias-retailers-are-quietly-bringing-back-facial-recognition/

Show more...
1 month ago
5 minutes 34 seconds

Don't Be A Sitting Duck Podcast
Cyber-Attack Shuts Down London Councils; Aussie Industry Breaches Exposed

In this episode, we look at a major cyber-attack that forced multiple London councils offline, cutting essential services for hundreds of thousands of residents — and a shocking new report showing Australia’s mining and manufacturing sectors often take months (or longer) to detect and report data breaches, exposing personal data of millions. We break down how these incidents unfolded, why they matter even for organisations far away from government or heavy industry, and most importantly — what you can do to protect your business.


This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

View Show Notes and full transcript here: https://sittingduck.com.au/podcast/cyber-attack-shuts-down-london-councils-aussie-industry-breaches-exposed/

Show more...
1 month ago
6 minutes 50 seconds

Don't Be A Sitting Duck Podcast
Vietnam’s Social Media Heists & The Rise of Asia’s Cybercrime Underground
  • Vietnam’s cybercriminals aren’t just hacking servers — they’re hijacking social media business accounts. In this episode, Leigh Kefford breaks down new findings from the CrowdStrike 2025 APJ eCrime Landscape Report — including how Vietnamese malware like Ailurophile Stealer is stealing ad accounts, the rise of Chinese-language cybercrime marketplaces, and why AI-driven ransomware is changing the game.

  • You’ll learn practical steps to protect your organisation, from tightening account controls to understanding how regional threat actors operate.

  • This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Show Notes and full transcript here: https://sittingduck.com.au/podcast/vietnams-social-media-heists-the-rise-of-asias-cybercrime-underground/

    Show more...
    1 month ago
    5 minutes 42 seconds

    Don't Be A Sitting Duck Podcast
    Human Error & Ransomware Risks for Australian Businesses

    In this episode of Don’t Be A Sitting Duck, I break down two critical risks for Australian organisations: the rising role of human error in data breaches, and the ever-present threat of ransomware. Using the latest figures from the OAIC and industry commentary, we explore how staff mistakes and mis-configurations are now major breach drivers, and why ransomware remains such a potent business continuity threat. I also share actionable steps you can take now to minimise risk, tighten your defences and ensure you're ready if the worst happens.

    Key Takeaways

    • Human error now accounts for around 37 % of reported breaches in Australia.
    • Malicious attacks (including ransomware/phishing) remain the primary cause of breaches.
    • Ransomware is not just a data loss event — it’s a business continuity and reputational risk.
    • Practical defence involves training, segmentation, MFA/backups, vendor oversight and incident readiness.
    • Book an assessment, test your recovery, and assume the unexpected.


    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Show Notes and full transcript here: https://sittingduck.com.au/podcast/human-error-and-ransomware-risks-australian-businesses/

    Show more...
    2 months ago
    8 minutes 17 seconds

    Don't Be A Sitting Duck Podcast
    Ransomware Realities: What You Need to Know

    Ransomware has become the most disruptive threat facing Australian businesses today. From small councils to local manufacturers, attacks are happening closer to home — and they’re getting smarter, faster, and more ruthless. In this episode, Leigh Kefford explores how ransomware works, what recent attacks reveal, and what practical steps every business can take to stay protected.

    Key Takeaways:

    • Ransomware spreads quickly through email, unpatched systems, and remote access.

    • Paying the ransom doesn’t guarantee recovery — backups and prevention are key.

    • Multi-factor authentication and staff training remain the most effective defences.

    • Every business, no matter how small, is a potential target.


    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Show Notes and full transcript here: https://sittingduck.com.au/podcast/ransomware-realities-what-you-need-to-know/

    Show more...
    2 months ago
    5 minutes 10 seconds

    Don't Be A Sitting Duck Podcast
    NSW AI Data Breach & Telco Hack – What Your Business Can Learn
  • Today’s episode unpacks two alarming cybersecurity incidents in Australia that should act as red alerts for every business. First, we look at how a contractor for a government flood-recovery program uploaded thousands of applicant records into ChatGPT without authorisation—revealing vulnerabilities in AI tool usage. Then we dive into a breach at telco Dodo (and its parent Vocus Group) where email accounts were compromised and SIM swaps executed. What went wrong, why it matters, and—most importantly—what your business needs to do next.

  • This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/nsw-ai-data-breach-dodo-hack-cybersecurity-lessons/

    Show more...
    2 months ago
    6 minutes 24 seconds

    Don't Be A Sitting Duck Podcast
    Australian Ransomware Wave Hits Law, Boats & Aviation

    This week on the Don’t Be A Sitting Duck Podcast, Leigh Kefford explores three major Australian cyber incidents — revealing how ransomware groups and vendor breaches continue to challenge even the most trusted organisations.

    • WA law firm confirms breach following Anubis ransomware claim
    • Malibu Boats Australia targeted by Qilin ransomware gang
    • Air Services Australia vendor data exposure under investigation


    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/australian-ransomware-wave-law-boats-air-services/

    Show more...
    2 months ago
    6 minutes 51 seconds

    Don't Be A Sitting Duck Podcast
    Qantas Data Leak & Australia’s $5.8M Privacy Penalty

    In this episode, we dig into two gripping and high-stakes stories in cybersecurity. First, Qantas is one of nearly 40 global firms being extorted over stolen data from Salesforce, now leaking millions of customer records. Then, in Australia, a health services firm becomes the first to face a major civil penalty—$5.8 million—for a data breach that exposed sensitive personal records. These twin lessons underscore just how fast the regulatory and threat landscape is evolving.

    You’ll hear clear, actionable advice for your business: how to defend against vishing attacks, contain data exposure, plan incident responses, and stay on the right side of privacy regulators.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/qantas-data-breach-australia-privacy-penalty/

    Show more...
    2 months ago
    5 minutes 15 seconds

    Don't Be A Sitting Duck Podcast
    Cyberattacks on Pharmacy, Brewer & UK Nursery

    In this episode of the Don’t Be A Sitting Duck Podcast, Leigh Kefford unpacks three alarming cyber incidents that reveal just how far attackers are willing to go:

    • Toowoomba Pharmacy Ransomware Attack – The Friendly Society Dispensary hit by the DragonForce group, with nearly 36GB of sensitive staff and patient data stolen.
    • Asahi Group Cyberattack in Japan – A global beverage giant forced to halt factory operations when IT systems collapsed, disrupting orders, shipping, and production.
    • UK Nursery Chain Hack – Kido nurseries breached by hackers claiming to hold data on more than 8,000 children, including names, photos, and safeguarding reports.


    These cases show a disturbing reality: no industry is off-limits, and cybercriminals are increasingly targeting healthcare, manufacturing, and even childcare. Leigh explains how the attacks unfolded, why they matter, and—most importantly—what actions your business can take to avoid becoming the next headline.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/cyberattacks-pharmacy-brewer-uk-nursery/

    Show more...
    3 months ago
    5 minutes 26 seconds

    Don't Be A Sitting Duck Podcast
    Chinese APT Threats Targeting Australian Critical Infrastructure

    In this episode, we unpack the alarming rise of state‑sponsored Chinese cyber actors compromising critical infrastructure—from backbone routers to military and government networks. You'll learn how these Advanced Persistent Threat groups maintain stealthy, long‑term access, and why this matters for national and business security.

    We break down how the attacks happen, explain the global coordination behind recent advisories, and offer smart, actionable steps you can take now to protect your organisation.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/chinese-state%e2%80%91sponsored-cyber-threat/

    Show more...
    4 months ago
    6 minutes 22 seconds

    Don't Be A Sitting Duck Podcast
    Microsoft 365 Calendar Phishing: Don’t Let Invites Fool You

    This episode uncovers a stealthy cyber‑attack slipping through inbox filters: Microsoft 365 calendar phishing. Scammers send fake billing alerts—like “Payment Failed” or “Account Suspended”—directly to your calendar. Without clicking anything, the threat arrives. We explain how they exploit default invite settings, why deleting or responding can put you on their radar, and most importantly, how you and your team can defend against it.

    You’ll learn actionable steps: ignore suspicious invites, use inbox tools wisely, verify via official channels, and empower your business with layered protection.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    4 months ago
    4 minutes 34 seconds

    Don't Be A Sitting Duck Podcast
    Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!