Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats, this podcast is for you. New episodes every day —subscribe now!
Cyber criminals are now targeting Papua New Guinea and the Pacific region with increasing frequency — and many businesses still think they’re too small, too remote, or too unknown to become a target.
In this special edition of the Don't Be A Sitting Duck Podcast, Leigh Kefford breaks down two recent ransomware incidents linked to Papua New Guinea and Fiji, including the alleged targeting of PNG’s Magisterial Servic...
One phishing email. That’s all it took to expose over 5.5 million customer records.
In this episode, we break down how hackers gained access to ADT’s systems—not through advanced hacking, but by targeting a person. We also dive into the growing wave of ransomware attacks hitting major brands like Zara, Carnival, and 7-Eleven, where attackers don’t just lock your data—they threaten to leak it.
Here’...
A Queensland pharmacy chain has allegedly been targeted by the Kairos ransomware group—highlighting a growing trend of cybercriminals targeting essential service providers, not just large enterprises.
In this episode, we break down what happened, how ransomware attacks like this actually work, and why healthcare businesses are increasingly in the firing line. More importantly, we walk through practical steps you can take right...
In this episode of the Don’t Be A Sitting Duck Podcast, we explore two recent and impactful Australian cyber incidents — the University of Sydney data breach and the iiNet customer data exposure. We explain how attackers gained access, what kinds of data were compromised, and most importantly, share actionable advice for businesses to reduce their risk of similar breaches.
Main Stories Covered:
Cyber security is no longer just an IT problem—it’s a board-level responsibility. In this episode, Leigh Kefford breaks down APRA’s CPS 234 Information Security standard in plain English, explaining what it requires, why regulators care, and what happens when controls fail.
We unpack board accountability, third-party risk, security testing, and incident response obligations—and why CPS 234 is fast becoming th...
Day 12 — The Grand Finale of the National PC 12 Days of Phishmas!
This episode brings together everything covered throughoutthe series into a complete, actionable Phishing Defence Checklist. You’ll learn:
Book your ...
Day 11 of the National PC 12 Days of Phishmas!
Today we explore why user behaviour is the biggestcybersecurity risk for every organisation.
Technology alone can't protect your business — people playthe defining role.
In this episode:
🛡 Empow...
Day 10 of the National PC 12 Days of Phishmas!
Ransomware attacks don’t start with encryption — they startwith access, usually through a phishing email.
This episode breaks down each stage of the ransomware attack chain and shows how to stop it early.
You’ll learn:
Day 9 of the National PC 12 Days of Phishmas!
Cybercriminals don’t always break into systems — sometimesthey break into people.
This episode explores how scammers use publicly availableinformation, emotional manipulation, and behavioural cues to create targetedattacks.
In this episode:
Day 8 of the National PC 12 Days of Phishmas!
Today we’re breaking down Account Takeover (ATO) andHijacked Email Threads — two of the most convincing and damaging forms of phishing.
In this episode:
🛡 Book your free ...
Why fake documents and shared file links are one of the most dangerous phishing threats for businesses.Day 6 of the 12 Days of Phishmas!
Today’s episode breaks down one of the biggest ways cybercriminals gain access to your systems: malicious attachments and cloud file impersonation.
These scams use fake PDFs, ZIP files, SharePoint links, OneDrive invites, and Google Drive notifications to infect your device or steal your crede...
🎄 Welcome to Day 1 of the 12 Days of Phishmas!
We’re kicking off the series with the foundation of all cyber awareness:
🔍 The Most Common Phishing Red Flags
These are the warning signs scammers can’t hide — the little clues that tell you something isn’t right.
And understanding them can prevent the vast majority of cyber incidents.
In this episode, I break down:
Australian retailers are quietly reintroducing facial recognition technology—even after public backlash. In this episode, Leigh breaks down why stores are turning to AI-driven biometric surveillance, what risks it creates for customers, and why business leaders should think carefully before deploying similar tools.
We explore how the technology works, why it’s making a comeback, and the serious privacy, ethical, and gove...
In this episode, we look at a major cyber-attack that forced multiple London councils offline, cutting essential services for hundreds of thousands of residents — and a shocking new report showing Australia’s mining and manufacturing sectors often take months (or longer) to detect and report data breaches, exposing personal data of millions. We break down how these incidents unfolded, why they matter even for organisati...
In this episode of Don’t Be A Sitting Duck, I break down two critical risks for Australian organisations: the rising role of human error in data breaches, and the ever-present threat of ransomware. Using the latest figures from the OAIC and industry commentary, we explore how staff mistakes and mis-configurations are now major breach drivers, and why ransomware remains such a potent business continuity threat. I also share ac...
Ransomware has become the most disruptive threat facing Australian businesses today. From small councils to local manufacturers, attacks are happening closer to home — and they’re getting smarter, faster, and more ruthless. In this episode, Leigh Kefford explores how ransomware works, what recent attacks reveal, and what practical steps every business can take to stay protected.
Key Takeaways:
Ransomware spreads quick...
This week on the Don’t Be A Sitting Duck Podcast, Leigh Kefford explores three major Australian cyber incidents — revealing how ransomware groups and vendor breaches continue to challenge even the most trusted organisations.
In this episode, we dig into two gripping and high-stakes stories in cybersecurity. First, Qantas is one of nearly 40 global firms being extorted over stolen data from Salesforce, now leaking millions of customer records. Then, in Australia, a health services firm becomes the first to face a major civil penalty—$5.8 million—for a data breach that exposed sensitive personal records. These twin lessons underscore just how...
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Does hearing about a true crime case always leave you scouring the internet for the truth behind the story? Dive into your next mystery with Crime Junkie. Every Monday, join your host Ashley Flowers as she unravels all the details of infamous and underreported true crime cases with her best friend Brit Prawat. From cold cases to missing persons and heroes in our community who seek justice, Crime Junkie is your destination for theories and stories you won’t hear anywhere else. Whether you're a seasoned true crime enthusiast or new to the genre, you'll find yourself on the edge of your seat awaiting a new episode every Monday. If you can never get enough true crime... Congratulations, you’ve found your people. Follow to join a community of Crime Junkies! Crime Junkie is presented by Audiochuck Media Company.
Gregg Rosenthal and a rotating crew of NFL Media hosts including Jourdan Rodrigue, Colleen Wolfe, and Nick Shook provide all the NFL news, previews, recaps and analysis you need to be smarter and funnier than your friends.
The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy, Jess Hilarious, And Charlamagne Tha God!
The Clay Travis and Buck Sexton Show. Clay Travis and Buck Sexton tackle the biggest stories in news, politics and current events with intelligence and humor. From the border crisis, to the madness of cancel culture and far-left missteps, Clay and Buck guide listeners through the latest headlines and hot topics with fun and entertaining conversations and opinions.