Home
Categories
EXPLORE
True Crime
Comedy
Society & Culture
Business
Sports
Health & Fitness
Technology
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Podjoint Logo
US
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/eb/2b/59/eb2b5984-2060-3202-97c7-d502da36aab8/mza_1917759792163288392.jpg/600x600bb.jpg
Don't Be A Sitting Duck Podcast
Leigh Kefford
41 episodes
1 day ago
Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!
Show more...
Technology
RSS
All content for Don't Be A Sitting Duck Podcast is the property of Leigh Kefford and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!
Show more...
Technology
Episodes (20/41)
Don't Be A Sitting Duck Podcast
NSW AI Data Breach & Telco Hack – What Your Business Can Learn
  • Today’s episode unpacks two alarming cybersecurity incidents in Australia that should act as red alerts for every business. First, we look at how a contractor for a government flood-recovery program uploaded thousands of applicant records into ChatGPT without authorisation—revealing vulnerabilities in AI tool usage. Then we dive into a breach at telco Dodo (and its parent Vocus Group) where email accounts were compromised and SIM swaps executed. What went wrong, why it matters, and—most importantly—what your business needs to do next.

  • This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/nsw-ai-data-breach-dodo-hack-cybersecurity-lessons/

    Show more...
    1 day ago
    6 minutes 24 seconds

    Don't Be A Sitting Duck Podcast
    Australian Ransomware Wave Hits Law, Boats & Aviation

    This week on the Don’t Be A Sitting Duck Podcast, Leigh Kefford explores three major Australian cyber incidents — revealing how ransomware groups and vendor breaches continue to challenge even the most trusted organisations.

    • WA law firm confirms breach following Anubis ransomware claim
    • Malibu Boats Australia targeted by Qilin ransomware gang
    • Air Services Australia vendor data exposure under investigation


    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/australian-ransomware-wave-law-boats-air-services/

    Show more...
    2 days ago
    6 minutes 51 seconds

    Don't Be A Sitting Duck Podcast
    Qantas Data Leak & Australia’s $5.8M Privacy Penalty

    In this episode, we dig into two gripping and high-stakes stories in cybersecurity. First, Qantas is one of nearly 40 global firms being extorted over stolen data from Salesforce, now leaking millions of customer records. Then, in Australia, a health services firm becomes the first to face a major civil penalty—$5.8 million—for a data breach that exposed sensitive personal records. These twin lessons underscore just how fast the regulatory and threat landscape is evolving.

    You’ll hear clear, actionable advice for your business: how to defend against vishing attacks, contain data exposure, plan incident responses, and stay on the right side of privacy regulators.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/qantas-data-breach-australia-privacy-penalty/

    Show more...
    3 weeks ago
    5 minutes 15 seconds

    Don't Be A Sitting Duck Podcast
    Cyberattacks on Pharmacy, Brewer & UK Nursery

    In this episode of the Don’t Be A Sitting Duck Podcast, Leigh Kefford unpacks three alarming cyber incidents that reveal just how far attackers are willing to go:

    • Toowoomba Pharmacy Ransomware Attack – The Friendly Society Dispensary hit by the DragonForce group, with nearly 36GB of sensitive staff and patient data stolen.
    • Asahi Group Cyberattack in Japan – A global beverage giant forced to halt factory operations when IT systems collapsed, disrupting orders, shipping, and production.
    • UK Nursery Chain Hack – Kido nurseries breached by hackers claiming to hold data on more than 8,000 children, including names, photos, and safeguarding reports.


    These cases show a disturbing reality: no industry is off-limits, and cybercriminals are increasingly targeting healthcare, manufacturing, and even childcare. Leigh explains how the attacks unfolded, why they matter, and—most importantly—what actions your business can take to avoid becoming the next headline.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/cyberattacks-pharmacy-brewer-uk-nursery/

    Show more...
    1 month ago
    5 minutes 26 seconds

    Don't Be A Sitting Duck Podcast
    Chinese APT Threats Targeting Australian Critical Infrastructure

    In this episode, we unpack the alarming rise of state‑sponsored Chinese cyber actors compromising critical infrastructure—from backbone routers to military and government networks. You'll learn how these Advanced Persistent Threat groups maintain stealthy, long‑term access, and why this matters for national and business security.

    We break down how the attacks happen, explain the global coordination behind recent advisories, and offer smart, actionable steps you can take now to protect your organisation.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/chinese-state%e2%80%91sponsored-cyber-threat/

    Show more...
    2 months ago
    6 minutes 22 seconds

    Don't Be A Sitting Duck Podcast
    Microsoft 365 Calendar Phishing: Don’t Let Invites Fool You

    This episode uncovers a stealthy cyber‑attack slipping through inbox filters: Microsoft 365 calendar phishing. Scammers send fake billing alerts—like “Payment Failed” or “Account Suspended”—directly to your calendar. Without clicking anything, the threat arrives. We explain how they exploit default invite settings, why deleting or responding can put you on their radar, and most importantly, how you and your team can defend against it.

    You’ll learn actionable steps: ignore suspicious invites, use inbox tools wisely, verify via official channels, and empower your business with layered protection.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    2 months ago
    4 minutes 34 seconds

    Don't Be A Sitting Duck Podcast
    FileFix Attack: Clipboard‑Based Threat Every Business Must Know

    In this episode, we dig into the newly discovered FileFix attack—a clever and stealthy cyber trick that exploits how people use their clipboard. No malware. No download. Just voice‑less manipulation of Windows Explorer and the clipboard to execute hidden PowerShell commands. We’ll break down how it works, why it’s so dangerous, and what businesses should do today to stay protected.Click here for full Transcript, shownotes and resources

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    3 months ago
    2 minutes 59 seconds

    Don't Be A Sitting Duck Podcast
    Qantas Data Breach: Customer Info Leaked via Vendor

    Qantas has joined the long list of major companies hit by cybercrime — this time, through a third-party contact centre platform. In this special Don’t Be A Sitting Duck episode, Leigh Kefford unpacks how customer data was leaked, what it means for businesses, and why vendor risk can no longer be ignored.


    What You’ll Learn:

    • Which customer details were compromised
    • Why third-party platforms are your biggest hidden risk
    • Steps to audit your vendors and protect your business
    • What cyber insurers now expect as minimum standards
    Show more...
    4 months ago
    4 minutes 1 second

    Don't Be A Sitting Duck Podcast
    Ransomware Realities: What You Need to Know

    Ransomware is more dangerous — and more accessible — than ever before. In this episode of Don’t Be A Sitting Duck, Leigh Kefford breaks down what’s really happening behind the scenes, how local businesses are being impacted, and the 5 non-negotiable actions your business must take to stay protected.

    In This Episode:

      • Why ransomware is exploding in 2025
      • The biggest risks for regional businesses
      • How phishing, patching, and backups can make or break your response
      • What every business needs to qualify for cyber insurance
      • The #1 tool to assess your risk — for free


    Key Takeaways:

      • Most ransomware attacks are preventable with the right systems.
      • Employee awareness is as important as firewalls.
    • Recovery depends on preparation — not luck.

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.


    View Shownotes and full transcript here: https://sittingduck.com.au/podcast/ransomware-realities-what-every-business-must-know/

    Show more...
    4 months ago
    3 minutes 26 seconds

    Don't Be A Sitting Duck Podcast
    CPS 234: What It Means for Your Business in 2025

    Is your business really ready for a cyberattack? If you’re in banking, insurance, or superannuation — APRA’s CPS 234 isn’t just a suggestion, it’s mandatory.

    In this extended episode, Leigh Kefford unpacks the what, why, and how of CPS 234 — Australia’s leading information security standard for regulated financial entities. But even if you’re not regulated, there’s a lot to learn here.

    • What CPS 234 requires from boards, management, and IT
    • Why third-party accountability still lands on your shoulders
    • What actions your business can take today — even as an SME
    • Why this isn’t just about compliance — it’s about survival

    Get the full show notes and resources at ⁠sittingduck.com.auThis podcast was produced by ⁠National PC⁠, delivering expert cyber security services in ⁠Townsville ⁠and ⁠Cairns ⁠through our ⁠Empower Managed IT⁠ solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    4 months ago
    6 minutes 22 seconds

    Don't Be A Sitting Duck Podcast
    Ransomware Payment Laws Now Mandatory: What You Must Report

    From 30 May 2025, Australian businesses earning over $3 million per year must report any ransomware or cyber extortion payments to the government within 72 hours. In this episode, Leigh explores:

    • What qualifies as a reportable ransomware or cyber extortion payment

    • Who needs to report and how to calculate turnover thresholds

    • What’s included in the 72-hour reporting requirement

    • Why these reports matter for Australia’s national cyber defence

    • How to prepare your business now before penalties kick in

    🎯 Book your free Empower Systems Assessment at ⁠nationalpc.com.au/empower⁠

    🎧 Get the audiobook ⁠Sitting Duck - The Phone Call You Don’t Want to Receive now⁠ on Spotify.

    This podcast was produced by ⁠⁠National PC⁠⁠, delivering expert ⁠⁠cyber security services⁠⁠ in ⁠⁠Townsville ⁠⁠and ⁠⁠Cairns⁠ ⁠through our ⁠⁠Empower Managed IT⁠⁠ solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    5 months ago
    6 minutes 30 seconds

    Don't Be A Sitting Duck Podcast
    Healthcare Breach Fears, Retail Attacks & New Ransomware Laws

    Fatalities caused by cyberattacks in hospitals? That’s what healthcare leaders are bracing for—and that’s just the beginning. In this episode of the Don't Be A Sitting Duck Podcast, Leigh Kefford unpacks the critical cybersecurity threats facing Australia right now.

    We explore:

    • The growing belief that it’s only a matter of time before a cyberattack leads to death in healthcare.

    • New legislation requiring ransomware payment disclosures in Australia.

    • A global surge in retail breaches hitting brands like Victoria’s Secret and The North Face.


    Full shownotes available at sittingduck.com.au

  • Each story includes practical actions your business can take to stay one step ahead of cybercriminals.

    🎯 Book your free Empower Systems Assessment at nationalpc.com.au/empower
    🎧 Get the audiobook Sitting Duck - The Phone Call You Don’t Want to Receive now on Spotify.

    This podcast was produced by ⁠National PC⁠, delivering expert ⁠cyber security services⁠ in ⁠Townsville ⁠and ⁠Cairns⁠ through our ⁠Empower Managed IT⁠ solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    5 months ago
    4 minutes 28 seconds

    Don't Be A Sitting Duck Podcast
    Cybersecurity Threats: Unmanaged Assets, AI Misinformation, and Banking Breaches

    In this episode, we delve into the pressing cybersecurity issues facing Australia today. From the dangers of unmanaged digital assets to the rise of AI-generated election misinformation, and the recent malware attacks on major banks, we uncover the vulnerabilities that businesses and individuals must address. Tune in to learn actionable steps to protect your digital environment.​

    👉 Full transcript and show notes available at ⁠sittingduck.com.aucybersecurity threats Australia, unmanaged IT assets, AI misinformation risks, election security Australia, Australian banks cyber attack, malware breach 2025, business cybersecurity, small business IT risk, cybercrime prevention, North Queensland cybersecurity, IT security for law firms, endpoint protection, phishing and malware attacks

    This podcast was produced by ⁠National PC⁠, delivering expert ⁠cyber security services⁠ in ⁠Townsville ⁠and ⁠Cairns⁠ through our ⁠Empower Managed IT⁠ solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    6 months ago
    3 minutes 20 seconds

    Don't Be A Sitting Duck Podcast
    Australia Hit by Infostealer Malware: Banking Credentials Sold Online

    Thousands of Australians have had their online banking passwords stolen by stealthy infostealer malware like RedLine and Raccoon Stealer. These credentials are now being sold on dark web marketplaces, putting businesses and individuals at risk. In this episode, I break down how infostealer malware works, why it's so dangerous, and the key steps you must take to protect your business.

    Episode Notes / Show Notes:

    • How infostealer malware silently steals credentials from Australians

    • Real-world breaches involving RedLine and Raccoon Stealer malware

    • Why businesses must act urgently to protect sensitive data

    • Practical cybersecurity steps to defend against info-stealers

    👉 Full transcript and show notes available at sittingduck.com.au
    External Source Links:

    • ACS Cybersecurity News

    • MSN Report on Banking Passwords

    • ABC News Coverage
  • Cybersecurity, Australian Cybersecurity, Infostealer Malware, Banking Passwords, Business Security, Malware Attacks, RedLine Stealer, Raccoon Stealer, Small Business Cybersecurity, Don't Be A Sitting Duck Podcast
  • This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.
  • Show more...
    6 months ago
    4 minutes 8 seconds

    Don't Be A Sitting Duck Podcast
    Super Fund Cyberattack: What Went Wrong & How to Stay Safe

    A coordinated cyberattack hit several Australian super funds—including AustralianSuper, Hostplus, and Rest—leading to major financial and data loss. This episode explores how the breach happened, the method known as credential stuffing, and steps businesses can take to avoid a similar fate.

    Main Stories Covered:

    • Credential stuffing attacks on super funds

    • $500,000 stolen from compromised AustralianSuper accounts

    • The role of weak passwords and reused credentials

    • Why MFA and security audits are now essential

    External Links:

    • ABC News coverage

    • Hostplus official statement

    • CyberDaily article

    This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.

    Show more...
    7 months ago
    3 minutes 50 seconds

    Don't Be A Sitting Duck Podcast
    Ransomware Attacks Hit Record High – Are You at Risk?

    February 2025 saw ransomware attacks hit an all-time high, with cybercriminals exploiting software vulnerabilities to hold businesses hostage. At the same time, social engineering scams are becoming more deceptive, tricking victims into handing over sensitive information.

    In this episode, I break down:
    ✅ Why ransomware attacks skyrocketed and how businesses are being targeted
    ✅ The growing threat of social engineering scams and how to spot them
    ✅ Practical steps to protect your data, employees, and financial assets

    Don’t wait for a cyberattack to strike—take action now!

    Get the full show notes and resources at sittingduck.com.au

    Show more...
    7 months ago
    3 minutes 33 seconds

    Don't Be A Sitting Duck Podcast
    Major Cyber Incidents: Brydens Lawyers Breach, ASIC's Action Against FIIG Securities, and Ballista Botnet Threat

    In this episode, we delve into recent significant cybersecurity incidents: a massive data breach at Brydens Lawyers, ASIC's legal action against FIIG Securities for prolonged cybersecurity failures, and the emergence of the Ballista botnet exploiting vulnerabilities in TP-Link routers. These events highlight the critical need for robust cybersecurity measures across all sectors. For more insights and resources, visit sittingduck.com.au.

    Show more...
    7 months ago
    4 minutes 30 seconds

    Don't Be A Sitting Duck Podcast
    Cybersecurity in Papua New Guinea: Are They Ready for the Digital Future?

    Papua New Guinea is going digital—but is it secure?

    In this episode of Don't Be a Sitting Duck, we dive into the cybersecurity challenges facing PNG’s government, businesses, and critical infrastructure. We discuss real-life cyberattacks—including ransomware incidents affecting PNG’s Department of Finance and the Internal Revenue Commission—and explore what needs to change to protect the nation’s digital future.

    Key topics covered:

    • The biggest cybersecurity risks facing PNG today
    • Real-world breaches—what happened & what we can learn
    • Government & business accountability in cybersecurity
    • Practical steps for strengthening PNG’s cyber defences


    Who should listen? If you're in government, IT, banking, or business in PNG, this episode is a wake-up call for action.

    Tune in now and start asking the tough questions.

    Got insights? Want to be part of the conversation? Reach out at sittingduck.com.au/podcast.

    Subscribe & listen on Spotify, Apple Podcasts & more!

    Shownotes and links

    Show more...
    7 months ago
    5 minutes 53 seconds

    Don't Be A Sitting Duck Podcast
    Genea IVF Data Breach Exposes Sensitive Health Records

    A major cybersecurity breach has rocked Australia’s healthcare sector. Genea, a leading IVF provider, was hit by a cyberattack that compromised sensitive patient data, exposing medical histories, test results, and personal information on the dark web. In this episode, we break down how the attack happened, why it matters, and—most importantly—what businesses can do to prevent similar breaches.

    🔗 Show notes & resources: sittingduck.com.au

    Show more...
    7 months ago
    2 minutes 52 seconds

    Don't Be A Sitting Duck Podcast
    APRA’s CPS 230 & CPS 234: Strengthening Operational & Cyber Resilience
    In this episode of Don't Be A Sitting Duck, we unpack APRA’s latest regulatory updates: CPS 230 on Operational Risk Management and CPS 234 on Information Security. With CPS 230 set to take effect in July 2025, organizations must prepare for stronger risk management, business continuity, and third-party oversight—especially in cloud outsourcing. Plus, we break down CPS 234, which mandates strict cybersecurity controls, risk assessments, and incident response requirements for financial institutions. Get ahead of compliance and fortify your organisation’s resilience—this is one episode you can’t afford to miss! Resources & Next Steps: Check out the show notes and other cybersecurity insights at sittingduck.com.au/podcast Book your free Empower Systems Assessment at nationalpc.com.au/empower Until next time—stay safe, stay informed, and don’t be a sitting duck!
    Show more...
    8 months ago
    4 minutes 55 seconds

    Don't Be A Sitting Duck Podcast
    Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!