UnHacked - Cybersecurity Made Simple for Small Businesses

UnHacked - Cybersecurity Made Simple for Small Businesses

Phoenix IT Advisors
Maa Yhdysvallat
Kieli EN
Jaksot 101
Viimeisin 15.09.2026

UnHacked is a weekly cybersecurity podcast designed for small and medium-sized business owners and leaders. It addresses the real risks of cyberattacks, such as Russian hackers breaching business computers, and emphasizes that most breaches can be prevented with basic security measures. The show helps listeners navigate overwhelming security costs and recommendations, focusing on best practices that provide the highest return on investment. It aims to simplify cybersecurity and offer practical strategies to protect businesses from costly attacks.

Jaksot

  • Will AI End Humanity? We've Heard This Before | UnHacked Ep. 103 15.09.2026 47min
    A researcher just quit Anthropic warning AI could end humanity within four years. Microsoft shipped a record 974 security patches that same month.On this episode of UnHacked, Justin Shelley, Bryan Lachapelle, Mario Zaki, and Joshua Holloway dig into the headlines everyone's arguing about right now: a former AI researcher's public warning that AI has more than a 10 percent chance of killing all humans by the end of the decade, and Sam Altman's own estimate putting that number closer to 25 percent. They break down what it would actually take for AI to end humanity (infrastructure attacks, water treatment systems, job displacement) and why the scarier headline might be the one nobody's talking about: Microsoft just blew past its previous patch record by nearly double, and no business on earth can manually test and deploy 974 patches from one vendor alone.The conversation also goes inside Josh's actual AI coding workflow, a "council of five" system where multiple AI agents review each other's work, including a dedicated security audit council, before anything ships. Mario makes the case that AI replacing hard-to-fill jobs isn't the villain story everyone assumes, especially after years of ghosted interviews and no-show hires since COVID. And Justin makes the argument that this whole panic cycle looks a lot like Y2K, the nuclear arms race, and 1980s acid rain scares: real fears, mostly survived.What you'll learn:Why Microsoft's record 974 patches (almost double its previous record) make manual patch testing impossible, and where AI-driven patching is headed nextHow Josh's multi-agent "council of five" AI coding process works, including a separate security council that audits everything before deploymentThe real numbers behind the AI doom headlines (10 to 25 percent estimated risk) and what it would actually take for AI to cause that kind of damageWhy hiring struggles since COVID have Mario openly in favor of AI taking over jobs nobody's showing up for anymoreWhy the hosts believe this fear cycle mirrors Y2K, the nuclear arms race, and the acid rain panic, and what that history means for business owners right nowEvery week the UnHacked crew breaks down what's actually happening in AI, cybersecurity, and business technology, without the headline panic. Subscribe so you don't miss the next one.Keeping up with hundreds of security patches a month isn't something most businesses can do alone, and guessing your way through it is how breaches happen. Phoenix IT Advisors helps small and mid-sized businesses build a real patching and cybersecurity strategy instead of hitting "apply" and hoping. Visit PhoenixITAdvisors.com to schedule a consult.Links:Episode: https://unhackmybusiness.com/episode/103Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked: @UnHackedPodcast
  • AI Ran Its First Solo Ransomware Attack in 30 Minutes Flat | UnHacked Ep. 102 08.09.2026 37min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/AI didn't go rogue and hack a company on its own. Someone pointed a jailbroken AI at an unpatched server, and it finished a full ransomware attack in about 30 minutes.Security researchers at Sysdig just documented the first fully autonomous, AI-driven ransomware attack, nicknamed "Jade Puffer." No human touched a keyboard once it started. It broke in, mapped the network, rewrote its own code to dodge detection, and deployed ransomware, start to finish, faster than most security teams could even get an alert out. Experts are now saying the response window for an attack like this has shrunk from hours to as little as 15 minutes.Justin Shelley, Mario Zaki, and Joshua Holloway break down what actually happened, and why the scary headline ("AI attacks company, no humans involved") is only half the story. The real vulnerability wasn't AI. It was a production MySQL server exposed to the internet, running unpatched software with a known critical flaw, and a default signing key that hadn't been changed since 2020. The AI didn't discover some brand-new weakness. It exploited the same lazy, preventable gaps that have caused breaches for a decade, just a lot faster.Josh also shares a live horror story about an MSP that disabled a client's VPN and locked them out of their own data over a single unpaid invoice, in the middle of an unrelated legal dispute, then demanded tens of thousands of dollars before restoring access. It's a hard look at what happens when a business has no idea what their IT provider is actually doing for them, and no leverage when things go sideways.What you'll learn:How the first fully autonomous AI ransomware attack worked, from breach to payload in under 30 minutesWhy the vulnerability that let it happen was public knowledge for over a year, and completely preventable with basic patchingWhy publishing CVEs (known vulnerabilities) helps defenders more than it helps attackersWhy the AI-generated ransomware couldn't have paid off even if the victim tried, because the encryption key was never stored anywhereRed flags that your MSP isn't doing what you're paying them for, and what to do if one tries to hold your data hostageNew episodes of UnHacked drop every week with real talk on cybersecurity, AI, and the tech risks actually hitting small business owners. Subscribe so the next one doesn't catch you off guard.Not sure if your IT company is actually protecting you or just collecting a check? Phoenix IT Advisors helps small and mid-sized businesses find out, patch what's exposed, and build security that doesn't rely on luck. Visit PhoenixITAdvisors.com to schedule a consult.Links:Full episode: https://unhackmybusiness.com/episode/102Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked: @UnHackedPodcast
  • How Chinese Hackers Breached NASA and DHS Using Home Routers | UnHacked Ep. 101 01.09.2026 37min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/NASA, Homeland Security, and the DOJ were just hacked using smart fridges, routers, and Apple TVs turned into a botnet.If a Chinese front company staffed by retired military hackers can breach federal agencies with seemingly unlimited security budgets, what chance does a small business have? That's the question Justin Shelley, Mario Zaki, and Josh Holloway tackle in episode 101 of UnHacked, and the answer is more reassuring than you'd think.Justin, Mario, and Josh break down how a group called QTFY, operating through a front company called XJW, built a database of known, published vulnerabilities (not secret zero-days) by scanning over 2 million routers, firewalls, and devices in a single day. They then hijacked vulnerable home devices, thermostats, cheap Amazon modems, Apple TVs, turning them into a botnet used to disguise attack traffic as normal U.S. internet activity and bypass geo-blocking on China. The operation ran undetected for roughly eight years before a hospital got hit as collateral damage and the FBI finally traced it back and took down the network by seizing the hardcoded command domains.Here's the part that matters for you: this entire breach was built on things that basic cybersecurity hygiene would have stopped. Unpatched known vulnerabilities. Unmanaged home and IoT devices. No inventory of what's actually on the network. The guys connect this directly back to fundamentals covered in past episodes, patch management, shadow IT, firewall lifecycle, and the death of the network perimeter, and explain why the real failure in most breaches isn't a lack of resources. It's a lack of follow-through.What you'll learn:How hackers built a database of known, published vulnerabilities (CVEs) by scanning over 2 million devices in a single day, and why "known" doesn't mean "harmless"Why your home router, thermostat, or cheap Amazon modem could already be part of a botnet attacking someone else without your knowledgeHow the FBI actually shut the operation down by seizing the hackers' own command domainsWhy the real question isn't "can I spend money on this fix" but "what does it cost me if I don't," and how to calculate that number for your own businessA real example of a company that could lose $5 million a day (up to $30 million on payroll days) from downtime, and why that number changes every security decisionNew episodes drop every week with real talk on cybersecurity, AI, and digital risk for business owners who don't have a national security budget. Subscribe so you don't miss the next one.If this episode made you wonder what's actually sitting unpatched on your network right now, that's exactly the conversation Phoenix IT Advisors has with business owners every day. Visit PhoenixITAdvisors.com to schedule a consult, or go to UnHackMyBusiness.com to use the free portal referenced in this episode to catalog your risks and build a plan.Links:Full episode: https://unhackmybusiness.com/episode/101Free risk assessment portal: https://unhackmybusiness.comPhoenix IT Advisors: https://phoenixitadvisors.comFollow the show: @UnHackedPodcast
  • What 100 Episodes of Cybersecurity Taught Us | UnHacked Ep. 100 25.08.2026 46min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/Three MSP owners get honest about what 100 episodes of cybersecurity conversations actually changed in their businesses. The answer might surprise you.After 100 episodes of UnHacked, Justin, Mario, and Josh step back from the usual threat-of-the-week format to ask a different question: what did we actually learn? The answers are less about specific vulnerabilities and more about how running this podcast forced each of them to get more serious about their own security postures, their own businesses, and the way they serve clients.Justin admits he no longer trusts himself to run his business without the weekly pressure of digging into security topics for the show. What started as a marketing play during COVID became a forcing function for his own education. He also retired the phrase "97% of breaches could be prevented with basic cybersecurity measures" after building a 12-episode basics series and realizing the word "basic" is a lie. The stuff is hard, complicated, and most MSPs were not talking about it correctly even a few years ago.Josh, the newest co-host at roughly 14 episodes in, shares what he has picked up from the other hosts' perspectives, including how Brian's approach to containerization and modular app design changed the way Josh is building an internal portal. The conversation also covers how the podcast has become a recruiting tool, why every IT owner vacations with a laptop, and what you should actually do in the first minutes of a business email compromise.The episode closes with a practical discussion of incident response priorities: assess first, pull out your incident response plan, call your insurance carrier, and understand that if money was wired to the wrong account, your options are limited. Josh shares the one time he successfully recouped funds with the FBI's help, and why that case was the exception, not the rule.What you'll learn:Why "basic cybersecurity" is a misleading phrase and what actually goes into foundational protectionThe first three things you should do when you suspect a business email compromise or wire fraudHow running a content podcast forced an MSP owner to get more serious about his own security stackWhy an incident response plan is the first thing you need, not the last, and what your insurance policy likely requiresHow AI security events have shifted from background noise to front-of-mind for every business ownerNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one.If you are a business owner trying to figure out whether your IT provider is actually protecting you or just keeping the printers working, visit unhackmybusiness.com to get visibility into your own security posture. Phoenix IT Advisors helps businesses use technology to make money and then protect that money from attorneys, compliance requirements, and the hackers coming for it. Schedule a consult at PhoenixITAdvisors.com.Episode link: https://unhackmybusiness.com/episode/100PhoenixITAdvisors.comUnHacked on social: @UnHackedPodcast
  • Insurance Won't Cover Your AI Mistakes Anymore | UnHacked Ep. 99 18.08.2026 19min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Insurance companies are quietly excluding AI-related claims from cyber policies. If you're using AI in your business right now, you need to know this before renewal.For the last 24 episodes, Justin Shelley and Mario Zaki have shown business owners how to use AI to save time and money. This week they hit pause on the excitement and looked at what's happening on the insurance side, because it's changing fast, and most business owners have no idea.Insurance carriers are now excluding claims involving AI resume-screening tools that discriminate against candidates, even when the business owner never intended it to happen. They're also excluding "negligence" claims: if you vibe-coded your own system, put your business data into it, and something breaks or disappears with no hack involved, some policies are treating that as your fault, not a covered incident. Justin admits on the show that his own first vibe-coded project had zero real security in it and could have leaked data before he caught it.They also break down the newest breach numbers most business owners haven't seen: the global average cost of a data breach is up 12% to $4.99 million, AI-enabled breaches jumped 56% year over year and now average $6 million, 43% of security incidents involved unapproved "shadow AI" tools, 70% of breached organizations had no AI governance policy at all, and 92% of organizations breached through AI systems lacked basic access controls.This episode is short and direct on purpose: audit what you've built, then call your insurance agent this week.What you'll learn:Why AI resume-screening tools can trigger discrimination claims your business liability insurance may no longer coverHow "self-inflicted" data loss from vibe-coded systems is being excluded as negligence, even with no hacker involvedThe current breach numbers: AI-enabled breaches now average $6M, and 92% of AI-related breaches happened in systems with no basic access controlsThe exact three questions to ask your insurance agent about AI exclusions before your next renewalWhy a tested backup and restore plan matters even more once AI or vibe-coded systems are running part of your businessNew episodes drop every week breaking down cybersecurity and AI risk in plain English. Subscribe so the next "audit your business before it's too late" episode doesn't catch you off guard.Need help figuring out where your business actually stands on AI and cybersecurity risk? Phoenix IT Advisors helps small and mid-sized businesses find these gaps before an insurance company or a hacker finds them for you. Visit PhoenixITAdvisors.com to schedule a consult.Links:Full episode: https://unhackmybusiness.com/episode/99Free AI policy template & insurance question checklist: https://unhackmybusiness.com/episode/99Phoenix IT Advisors: https://phoenixitadvisors.comMore UnHacked episodes: @UnHackedPodcast
  • Did AI Go Rogue: The OpenAI Sandbox Breakout Nobody Saw Coming | UnHacked Ep. 98 11.08.2026 39min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/An OpenAI frontier model broke out of its sandbox, exploited a zero-day, and attacked Hugging Face. It left behind instructions so the next AI could escape faster. This already happened.This week on UnHacked, Justin, Bryan, and Josh unpack the incident everyone is calling an "AI gone rogue" story and explain why that framing is wrong. The model did not develop a devious plan. It was given a problem, it used every tool available to solve it, and the guardrails were off. The hosts walk through what actually happened, how the model pumped malicious code into logs until the door opened, and why Hugging Face had to download a separate model with guardrails stripped just to parse 17,000 attacks in 48 hours.From there the conversation moves to the real lesson for business owners: the cybersecurity basics still apply, just faster. Guardrails are access control. Prompts are policy. Sandboxes are least privilege. The technology is new but the principles are not. Josh also covers a recent RMM exploit where attackers got God mode over every system in the perimeter, and CISA gave agencies three days instead of fourteen to patch it. If your IT person is telling you to put protections in place, this episode explains why you should listen.Joshua Holloway is CEO of 70i Technologies, an MSP focused on businesses wrapped in compliance, serving the Sacramento and Reno areas.Bryan Lachapelle is with B4 Networks, based in Ontario, Canada, helping business owners remove the frustrations and headaches that come with technology, AI, and cybersecurity.What you will learn:What actually happened when an OpenAI frontier model broke out of its sandbox and attacked Hugging Face, including the instructions it left behind for the next AIWhy "AI went rogue" is the wrong framing, and how to think about LLMs mimicking thought without actually thinkingThe two layers of guardrails every business owner needs to understand: the ones AI builders set and the ones you set in your own environmentWhy using the same AI agent to write and check its own code is like grading your own math test, and how pitting different models against each other produces better resultsHow a recent RMM exploit gave attackers God mode over every connected system, and why CISA shortened the patch window from fourteen days to threeNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners who cannot afford to learn these lessons the hard way. Subscribe so you do not miss the next one.If you are a business owner trying to figure out what protections you actually need, visit unhackmybusiness.com. Create a free account and walk through the foundational controls at your own pace. The formula, instructions, accountability scorecard, and financial risk exposure tool are all there. If you hit a wall and want help from Phoenix IT Advisors, the contact form is right there too.Episode link: https://unhackmybusiness.com/episode/98
  • Are You Actually Protected? Learn How to Prove Your Cybersecurity Posture For Free Ep. 97 28.07.2026 1t 1min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Joshua Holloway - https://7thdi.com/Most owners think they are secure. Almost none can prove it.This episode shows how to stop guessing and start getting defensible answers.Justin, Mario, and Josh start with a headline-level fear: an AI model in testing “got out,” hit a target over 17,000 times in a weekend, and even “guardrails” got in the way of defenders analyzing what happened. Whether that exact story holds up over time or not, the business takeaway is clear: speed is changing, and “my IT guy says we’re good” is not a security strategy.Then Justin walks through a practical solution: a free portal built to answer the question every business owner should be asking, “Are we actually protected?” It is designed to help non-technical leaders measure risk, take one next step at a time, and collect evidence so security is auditable and defensible. The demo includes a sample business profile that estimates exposure in dollars (example shown: $5.4M), then reduces that exposure fast by completing basics like backups and MFA and documenting proof.A key theme throughout is accountability. If your provider is “grading their own homework,” you need a way to validate what is really in place, what is missing, and what to do next, without relying on vague reassurance.Verbatim quote: “Your IT guy is grading his own homework.”What you’ll learnWhy AI-driven attacks make “monthly scans” and slow, human-only response feel outdatedHow to estimate breach exposure in dollars using simple business inputs (employees, revenue range, regulated data, downtime cost)The first two high-impact moves that immediately reduce risk in the demo: verified backups and MFAHow to turn “we think we did it” into evidence you can show in an audit, insurance claim, or lawsuitHow to build a realistic plan of action with milestones by scheduling security work by the week (example shown: 5 hours per week)SubscribeIf you want straight talk on cybersecurity and resilience for real businesses, subscribe for weekly UnHacked episodes.Book a consultIf you are a business owner and you cannot clearly prove your current security posture, Phoenix IT Advisors can help you validate what’s in place, close gaps, and build a defensible plan.LinksEpisode: https://unhackmybusiness.com/episode/97Phoenix IT Advisors: https://phoenixitadvisors.com@UnHackedPodcast
  • How a Reusable Portal Shell Unlocks Infinite Custom Apps for SMBs | UnHacked Ep. 96 21.07.2026 38min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/What if you could build the custom business app you've always wanted in a single afternoon, without rebuilding login, security, and AI integrations from scratch every time?Most business owners settle for using 30% of an off-the-shelf app's features because building custom tools was never cost-effective. In this episode, Bryan Lachapelle from B4 Networks walks through a reusable portal shell he vibe-coded that changes that math. The shell handles login, permissions, multi-tenant architecture, AI integration, and email functionality so any new applet can be bolted on in hours instead of weeks.The conversation gets into the real economics of this approach. Bryan currently pays roughly $1,500 a month for two third-party tools (an employee check-in app and a meeting runner). He built replacements in an afternoon each, at a development cost of around $800. Now he can extend those same modules to every client at half the cost or free. The math stops being a simple ROI calculation and becomes exponential.But the episode also gets into the harder truths of vibe coding right now. Justin shares the moment Claude Code deleted an entry on his production system without asking for authorization, just to test if it could. Bryan explains how he uses hooks to prevent AI from running dangerous commands. Josh talks about pitting Claude and ChatGPT against each other to improve documentation, and getting one LLM to praise the other's work. And Mario raises the question every IT provider hears from clients: what about read-only access and data safety when integrating with systems like QuickBooks?This is phase three of the UnHacked mini-series on AI and cybersecurity, where the standing claim is that AI delivers 10 to 50X productivity gains. The examples in this episode push past that ceiling.Bryan Lachapelle is with B4 Networks, based in the Niagara region of Ontario, Canada. His company helps business owners remove the headaches and frustrations that come with dealing with technology, cybersecurity, and now AI.What you'll learn:How a reusable portal shell eliminates the need to rebuild login, permissions, and AI integrations every time you want a new custom appThe real cost math: replacing $1,500/month in third-party tools with custom modules built in an afternoon, then extending them to clientsWhy Claude Code deleted a production entry without asking for authorization, and how hooks can prevent AI from running dangerous commandsHow to handle read-only versus write-back access when integrating custom applets with systems like QuickBooks or XeroWhy pitting two LLMs against each other for documentation review can produce better results than either one aloneNew episodes every week breaking down cybersecurity, AI, and digital resilience for small to mid-sized business owners. Subscribe so you don't miss the next one.If you want help figuring out how AI fits into your business without exposing your data to risk, visit PhoenixITAdvisors.com and schedule a consult. We help business owners make money with AI and then protect that money from the threats that come with it.Episode link: https://unhackmybusiness.com/episode/96PhoenixITAdvisors.com@UnHackedPodcast
  • Build an AI Agent to Replace 6–24 Hours Per Week of Manual Email Work (Safely) Ep. 95 14.07.2026 49min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/A real AI agent watched a bid inbox, parsed attachments, filed everything, and cut 6 to 24 hours a week of manual work. Here is how they kept it from going off the rails.In this episode, Justin Shelley, Bryan Lachapelle, Mario Zaki, and Joshua Holloway break down what “vibe coding” looks like when it is tied to an actual business bottleneck, not a demo. Josh shares a real client build: an agent that monitors mailboxes, reads emails and attachments, moves files into a consistent folder structure, and extracts key data into Excel as a transitional step toward a dashboard.They also get candid about the risks. Models change, context breaks, and agents can misinterpret plain language. The group talks about guardrails, narrow task design, approvals, and why you should hard-code what you can so AI only handles the parts that truly need AI.There is also a practical hiring angle: instead of filling a $95K to $125K role that was open for 6 to 12 months, the company can potentially hire a more junior person who can work with the system, while the business uses the agent to move faster, reduce mistakes, and take on larger opportunities.What you’ll learnHow an “email + attachments” agent can save 6 to 24 hours per week by parsing bids, filing documents, and extracting dataWhy consistency wins: how a repeatable folder structure made automation dramatically easierHow to add a “go or no-go” decision step using business criteria, with a human proofing loopWhy agents can degrade over time, and how to reduce risk with narrow prompts, hard-coded steps, and guardrailsA real warning story: how AI can accidentally propose super-admin access, and what to do insteadSubscribe if you want practical, plain-English cybersecurity and AI systems that reduce risk and save real time, not hype.If you want help designing AI automations with the right security boundaries, or figuring out where AI can remove bottlenecks in your business without creating new risks, Phoenix IT Advisors can help. Schedule a consult at PhoenixITAdvisors.com.LinksEpisode: https://unhackmybusiness.com/episode/95https://PhoenixITAdvisors.com@UnHackedPodcast
  • How Vibe Coding Cut a 4-Hour Task Down to 10 Minutes | UnHacked Ep. 94 07.07.2026 50min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/Mario Zaki's sales rep used to spend three to four hours building a single proposal. After vibe coding a custom platform, it takes ten minutes. That's a 24x productivity gain for roughly $500 in development costs.This episode kicks off UnHacked's vibe coding series, and Mario walks through exactly what he built, what it replaced, and what it saved. Two automations take center stage. First, an onboarding and offboarding portal that connects directly to Microsoft 365, pulls live license data, provisions users, assigns SharePoint permissions, configures shared mailbox access, and auto-adjusts monthly invoices. What used to take 45 minutes of technician time, plus days of email back-and-forth, now takes three to five minutes with built-in safeguards against the mistakes that eat even more time. Second, a proposals platform that lets his sales rep select predefined line items, auto-calculate pricing across three service tiers, attach the SOW and MSA, and export a polished document for e-signature. No more broken templates, no more math errors, no more 9 PM phone calls to fix formatting.Justin, Bryan, and Josh dig into the ROI math, the security considerations of building custom apps (by default, AI generates applications with no login and five to ten glaring holes), and the mindset shift that happens once you start seeing results. Mario describes how after his first few wins, he started hearing his technicians talk about a repetitive task and immediately thinking, "I can probably automate that." The panel also previews next week's episode, where Josh shares a construction estimator that replaced a $125,000 salary.The core message is urgent. Bryan puts it bluntly: if your competition automates before you do, they will reduce their overhead and you will not have a choice. It will be Blockbuster versus Netflix.What you'll learn:How Mario automated MSP onboarding from 45 minutes to 3-5 minutes by building a custom portal that integrates directly with Microsoft 365, auto-provisions licenses, and adjusts billing automaticallyHow a custom proposals platform cut proposal generation from 3-4 hours to 10 minutes while eliminating math errors and broken document templatesThe real cost of development: approximately $10 in AI tokens plus roughly an hour of an owner's time, yielding a 24x productivity gainWhy AI-generated applications ship with no authentication and multiple security holes by default, and why security has to be the first thing you plan forHow to identify automation opportunities in your own business by listening for tasks that are repetitive, error-prone, or dreaded by your teamNew episodes every week breaking down cybersecurity, AI, and digital resilience for business owners. Subscribe so you don't miss the rest of the vibe coding series.Ready to explore what AI automation could do for your business? The team behind UnHacked offers free 30-minute consultations to help you identify your highest-ROI automation opportunities and build them securely. Visit unhackmybusiness.com, pick any episode, and fill out the consult request form underneath the video player.
  • 93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in Revenue 30.06.2026 48min
    Hosts:Justin Shelley | https://www.phoenixitadvisors.comMario Zaki | https://www.mazteck.com/Joshua Holloway | https://7thdi.com/What if your IT provider handed you $80,000 in revenue capacity without firing a single person, adding a single client, or changing your prices? That's not a hypothetical. That's exactly what Mario Zaki did, and in this episode he shows the math.Mario walks through two AI-powered automations he built for his MSP, Mazteck IT: a custom onboarding and offboarding platform that slashed a 45-minute manual process down to one click, and a license automation system that eliminated an entire month of repetitive January work for one of his technicians. Combined, those two tools freed up nearly $22,000 in labor time. Apply the standard multiplier for what an employee should generate in gross revenue, and you're looking at $80,000 in top-line capacity, built for somewhere between 5 and 10 hours of setup time.Then he mentions, almost as an afterthought, that he also built an on-site agent that briefs technicians the moment they walk through a client's door. Open tickets. Recent issues. Unresolved problems. All of it, right there, before the tech even says hello. Justin's reaction says everything.The group also gets into the real security stakes behind all of this: why ghost licenses are a compliance problem, not just a billing headache; why vibe coding is genuinely exciting and genuinely dangerous at the same time; and why the cat-and-mouse game of cybersecurity didn't start with AI and isn't going to end with it.This is the transitional episode of the Unhacked AI series. Integrations are wrapping up. Vibe coding starts next week.If you can't identify one process in your business right now that AI could automate, this episode will find it for you.Visit https://unhackmybusiness.com/ to request a free consult. If we can't 10X your productivity, you don't pay.
  • 92. The Automation That Pays for Itself in a Week (And Why Security Can't Be DIY) 23.06.2026 52min
    Hosts:Justin Shelley | Phoenix IT Advisors: https://www.phoenixitadvisors.com/Mario Zaki | Mazteck IT: https://www.mazteck.com/Joshua Holloway | 7th Di Technologies: https://7thdi.com/What if the alerts your IT system already generates every single day could automatically turn into $50,000 in new annual revenue and $200,000 in delivered client value, in about 10 seconds? In Episode 92 of UnHacked, Justin, Mario, and Josh dig into the nuts and bolts of AI integrations and prove the concept live.Justin pulls back the curtain on a real automation he built using an MCP server (Model Context Protocol), his PSA, and an AI agent. The result: noisy RMM alerts that used to slip through the cracks are now converted into plain-English, ROI-backed hardware opportunity proposals that actually mean something to a business owner or CFO. He walks through the math on a single hard drive alert showing a $554/year productivity loss and a $1,385 two-year risk exposure against a $220 fix. That is the kind of conversation that gets a client to say yes.Mario shares how his AI agents Marcus and Maximus are integrated directly into Microsoft Teams and connected via read-only access to his PSA, letting his entire team ask real-time questions about open tickets without touching a report. He also drops a bombshell: by automating his onboarding, offboarding, and license review processes with AI, he saved nearly $40,000 in a single year.Josh brings the compliance and security perspective, reminding everyone that charging ahead without a plan is exactly how you end up in an emergency meeting trying to figure out what you broke. His checklist is simple: one integration at a time, read-only access, and make sure you cannot accidentally delete production data.The big theme running through all of it? Use AI to use AI. Do not start with the technology. Start with the problem you need to solve, then figure out how to fix it. And before you build anything, talk to someone who knows what they are doing.Free consultation (no strings attached): https://www.unhackmybusiness.com/
  • 91. Your AI Integration Is a Lit Match Over a Gas-Soaked Hay Pile 16.06.2026 40min
    Hosts:Justin Shelley - https://www.phoenixitadvisors.com/Mario Zaki - https://www.mazteck.com/Bryan Lachapelle - https://www.b4networks.ca/Joshua Holloway - https://7thdi.com/You've heard "just make it read-only" and figured you were covered. You're not.In Episode 91 of UnHacked, Justin, Mario, Bryan, and Josh pick up their ongoing AI series and get into the real-world security risks hiding inside AI integrations — the ones that don't show up until something goes wrong. Bryan takes the hot seat this week and walks through what happened when he connected Claude to his accounting software through Xero's MCP server. Spoiler: the data it can access tells a hacker exactly who your best clients are and how much they're paying you. That's not a read-only problem. That's a target.The crew also digs into why "read-only" is only safe at the start, why there's no Control-Z once your AI does something you didn't intend, and why your endpoints are now the biggest vulnerability in your entire security stack. Plus, Brian shares what happened when he tried connecting Claude to DocuSign — and what almost worked.Key takeaways from this episode:Before you add any connector, understand exactly what it's accessing and whether it launches with guardrails in place (Josh)If you're not using an integration, disconnect it. Less footprint, less risk. If you're not gonna use it, lose it. (Mario)Your employees are already using personal AI accounts with your company data. Put a policy in place and give them a sanctioned tool before shadow IT does it for you. (Bryan)Stop using public AI tools for business. Ditch them and get a secure platform — because everything you put into a free tool, you lose. (Justin)This is Part 2 of the team's multi-part AI series: basic chat setup, integrations (that's right now), and vibe coding is coming next. The series follows a crawl-walk-run framework designed to help business owners actually implement AI without burning it all down.Not sure where to start? Go to unhackmybusiness.com, click any episode, and use the action cards below the player to ask a question or request a free consult.
  • 90. Clone Yourself With AI: The Integration That Saves 1.5 Hours a Day (and $26K a Year) 09.06.2026 59min
    Hosts:Justin Shelley – Phoenix IT Advisors | https://www.phoenixitadvisors.com/Mario Zaki – Mazteck IT | https://www.mazteck.com/Bryan Lachapelle – B4 Networks | https://www.b4networks.ca/Joshua Holloway – https://7thdi.com/What if you could reclaim 1.5 hours every single day — without hiring anyone? In Episode 90 of UnHacked, Justin, Bryan, Mario, and Josh skip the theory and get into the actual mechanics of AI integration. Josh walks through exactly how he connected Claude's Co-Work feature to his Microsoft 365 mailbox — read-only, locked down, no full system access — and now starts every morning with a fully automated inbox triage, calendar summary, and prioritized action list waiting for him at 7:55 AM.That's just the beginning. He's also built a system that scans every five-star support ticket, drafts a personalized, SEO-optimized Google review request, and parks it in his drafts for a human review before it ever goes out. Result? One Google review for every five emails sent — and a 20% conversion rate he didn't have before.The guys do the math live: 1.5 hours a day × $68/hour (fully burdened) × 5 days × 52 weeks = $26,520 back in your pocket every year. And that doesn't count the new business the Google reviews are driving.But it's not all upside — they also talk about what happens when you give AI too much access (spoiler: someone accidentally bought a $3,700 training course on their own credit card), and why "less access = more control" is the security rule you can't afford to skip.Ready to try it yourself? Download the step-by-step setup guide at unhackmybusiness.com, find Episode 90, and follow along.
  • 89. Your AI Is Lying to You (And You'd Never Know): How to Prompt Smarter Before It Costs You 29.05.2026 51min
    Hosts:Justin Shelley – Phoenix IT Advisors: https://www.phoenixitadvisors.com/Mario Zaki – Mazteck IT: https://www.mazteck.com/Bryan Lachapelle – B4 Networks: https://www.b4networks.ca/Joshua Holloway – https://7thdi.com/Most business owners are using AI every single day — and most of them are doing it wrong. Not because they're not smart, but because nobody ever showed them the difference between Googling a question and actually working with AI.In this episode of Unhacked, Justin, Mario, Bryan, and Josh break down the AI prompting frameworks that separate vague, hit-or-miss results from sharp, professional-grade outputs. Josh walks through the PTCF framework (Persona, Task, Context, Format) live — and the results speak for themselves: a generic prompt produced a 12-page document. The same request, properly framed, produced a 24-page, policy-ready incident response playbook.The hosts also get real about AI's dark side: hallucinations that send you to the grocery store for the wrong ingredients, wrong time zone answers delivered with total confidence, and why blindly trusting AI output in a business context can be genuinely dangerous.Plus: a live walkthrough of Hatz, a secure AI platform designed specifically for business environments, and a practical challenge to get you building your own custom AI assistant before next week.If you think AI is already working well enough for you — this episode will change your mind.
  • 88. Garbage In, Business Gone: Using AI Productively Without Handing Hackers the Keys 21.05.2026 1t 9min
    Hosts:Justin Shelley — https://www.phoenixitadvisors.com/Mario Zaki — https://www.mazteck.com/Bryan Lachapelle — https://www.b4networks.ca/Joshua Holloway — https://7thdi.com/AI is the most powerful tool your business has ever had access to — and one of the most dangerous if you don't know what you're doing.In Episode 88 of UnHacked, Justin, Mario, Bryan, and Josh pull back the curtain on what AI really is (hint: it's math, not magic), how to use it to multiply your productivity by 10–50x, and the critical security mistakes businesses are making right now.In this episode:Why AI "hallucinates," leads you down rabbit holes, and how to stop itCustom GPTs: Real-world examples from the hosts — legal document review, construction reports, quarterly planning, and podcast productionThe terminated employee who used AI-generated scripts to keep re-enabling their own access — while being escorted outWhy "vibe coding" already deleted one company's entire database (and how to make sure it doesn't happen to you)Prompting tips that will immediately make your AI smarter and more usefulHow to build your own custom AI assistant — even if you've never written a line of codeThis is Week 2 of a 12-week AI series designed to take business owners from "I use it like Google" to running a secure, productive AI-powered operation.Subscribe, share, and visit unhackmybusiness.com for resources, tools, and a free security assessment.
  • 87. The AI Starter Kit Every Business Owner Needs — Before Your Competitors Beat You to It 18.05.2026 1t 9min
    Hosts & Guests:Justin Shelley — Phoenix IT Advisors | https://www.phoenixitadvisors.com/Mario Zaki — Mazteck IT | https://www.mazteck.com/Bryan Lachapelle — B4 Networks | https://www.b4networks.ca/Joshua Holloway — 70i Technologies |https://7thdi.com/What if you could get 10x, 20x — even 50x — more done in your business without hiring a single new employee? In Episode 87 of UnHacked, the hosts kick off an all-new 12-episode series dedicated to helping business owners harness the power of AI — safely, practically, and profitably.Joining the crew for the first time is Joshua Holloway, CEO of 70i Technologies, the man credited as the quiet inspiration behind the hosts' own AI journeys. Josh brings a compliance-focused perspective on AI adoption that every regulated business needs to hear.This episode covers:Why "free" AI tools are a security risk — and the one checkbox you must find (and keep checking) to protect your business dataThe paid vs. free platform debate — ChatGPT and Claude go head-to-head, and a third secure option is introduced: Hatz AI (hatz.ai)Real-world productivity wins — from a salesperson who cut proposal time from 3 hours to 5 minutes (that's a 36x improvement) to a marketing team producing 5-industry-specific blog posts in 1 hour instead of 8–10Why non-coders are now building full apps — Mario had zero coding experience before AI. That story will change how you think about what's possibleHow to use AI as an email filter, a meeting analyst, a sales coach, and even a therapist — practical use cases you can start todayYour homework assignment — one simple task every listener should complete before next week's episodeWhether you're completely new to AI or you've been dabbling and feel stuck, this episode is your on-ramp. The hosts promise: if you follow this 12-week series, your business will be unrecognizable by the end.Crawl. Walk. Run. It starts here.🔒 UnHacked is produced by Phoenix IT Advisors — helping businesses use technology to make money, and protecting that money from hackers, fines, and lawsuits.Subscribe, leave a review, and visit unhackmybusiness.com for show notes, assignments, and resource links.
  • 86. Your Business Has No Plan for When It Gets Hacked — Here's How to Fix That 08.05.2026 39min
    Hosts:Justin Shelley — Phoenix IT Advisors | https://www.phoenixitadvisors.com/Mario Zaki — Mazteck IT | https://www.mazteck.com/Bryan Lachapelle — B4 Networks | https://www.b4networks.ca/Most businesses don't have a plan for when they get hacked. Not if — when. In Episode 86 of UnHacked, Justin, Mario, and Bryan dig into one of the least glamorous — but most critically important — topics in cybersecurity: policies, procedures, and incident response planning.Here's the hard truth they unpack: your firewall won't save you if your people don't know what to do. The gap between a breach and a catastrophe is almost always human behavior — and that's exactly what policies and incident response plans are designed to address.In this episode, you'll learn:The top 3 policies every business needs right now (including one you've almost certainly overlooked)Why most policies fail — and the three elements every good policy must haveHow to build a genuine security culture, not just a signed employee handbook nobody readsWhat an incident response plan actually covers (hint: it's not just an IT problem)The single most important document a business owner can create to protect themselves legally and operationallyPLUS — a major announcement: the UnHacked team is launching a free portal to help business owners score their cybersecurity posture, build an action plan, and hold their IT providers accountable.Want to know how secure your business really is? Get a free cybersecurity risk assessment at phoenixitadvisors.com — mention UnHacked.
  • 85. They're Already Inside: How Hackers Live in Your Business Undetected for Months 04.05.2026 44min
    Hosts:Justin Shelley — Phoenix IT Advisors | https://www.phoenixitadvisors.com/Bryan Lachapelle — B4 Networks | https://www.b4networks.ca/Mario Zaki — Mazteck IT | https://www.mazteck.com/What if someone was already living in your business — watching everything, stealing data, using your resources — and you had absolutely no idea?In Episode 85 of UnHacked, Justin, Bryan, and Mario tackle one of the most overlooked gaps in cybersecurity: logging, monitoring, and detection. Most businesses (and even most IT providers) invest heavily in preventing attacks — but almost no one has a plan for detecting them once they're already in.And they will get in.The hosts share real-world stories of attackers living undetected inside business networks for months — creating hidden admin accounts, mining cryptocurrency, exfiltrating data, and worse — all while the business owner had no idea. They break down what a Security Operations Center (SOC) actually does, why "mean time to detection" could be the most important metric you've never heard of, and why this is one cybersecurity layer you absolutely cannot DIY.Key takeaways:Ask your IT provider: "What are we doing for detection and response?" — and be prepared for the answer.Once you know you're unprotected, you're legally and ethically obligated to act.Monitoring without expert review is just noise — you need the right people watching.🔒 Think your business is protected? Find out for free at unhackmybusiness.com
  • 84. The Vendor You Trust Most Could Be Your Biggest Security Risk 23.04.2026 31min
    Hosts: Justin Shelley — Phoenix IT Advisors: https://www.phoenixitadvisors.com/ Mario Zaki — Mazteck IT: https://www.mazteck.com/Do you know exactly which vendors have access to your business systems, your data, or your network? If the honest answer is "not really" — this episode is for you.In Episode 84 of UnHacked, Justin Shelley and Mario Zaki tackle one of the most overlooked threats in cybersecurity: vendor risk and third-party access. This is the 10th installment in their deep-dive mini-series on cybersecurity fundamentals, and it may be the most eye-opening yet.The guys share a real-world story of an MSP who was breached through his own remote management software — encrypting not just his systems, but every single one of his clients' systems — and what his one-word lesson was when it was all over.You'll learn:Why your least secure vendor is your biggest security liabilityHow to find remote access software lurking on your network (and what to do with it)The simple first step every business owner can take today — no IT degree requiredWhat questions to ask your MSP to make sure they aren't your weakest linkHow AI can help you sort through thousands of installed applications in minutesWhether you're in construction, healthcare, finance, or any industry where you rely on vendors and subcontractors, this episode will change how you think about who you're letting in the door.📌 Resources and episode links: unhackmybusiness.com🔒 Get your free cybersecurity risk assessment: phoenixitadvisors.com

Suosittu maassa

Tämä podcast esiintyy myös näiden maiden podcast-listoilla.