Leigh Kefford
Don't Be A Sitting Duck Podcast
Cybercriminals are evolving—are you keeping up? Don’t Be A Sitting Duck is the podcast for business leaders and professionals who want to stay one step ahead of the latest cyber threats. In each bite-sized episode, we dive into real-world cyber breaches, phishing scams, and ransomware attacks, sharing actionable advice to help you protect your business. Looking for more insights and resources? Visit sittingduck.com.au to explore educational content designed to help you navigate today’s complex cybersecurity landscape. If you’re ready to embrace proactive protection and outsmart cyber threats,...
Author
Leigh Kefford
Category
Podcast website
Latest episode
May 18, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Ransomware Realities: What You Need to Know 01.07.2025 3:26
Ransomware is more dangerous — and more accessible — than ever before. In this episode of Don’t Be A Sitting Duck , Leigh Kefford breaks down what’s really happening behind the scenes, how local businesses are being impacted, and the 5 non-negotiable actions your business must take to stay protected. In This Episode: Why ransomware is exploding in 2025 The biggest risks for regional businesses How...
CPS 234: What It Means for Your Business in 2025 06.06.2025 6:22
Is your business really ready for a cyberattack? If you’re in banking, insurance, or superannuation — APRA’s CPS 234 isn’t just a suggestion, it’s mandatory. In this extended episode, Leigh Kefford unpacks the what, why, and how of CPS 234 — Australia’s leading information security standard for regulated financial entities. But even if you’re not regulated, there’s a lot to learn here. What CPS 23...
Ransomware Payment Laws Now Mandatory: What You Must Report 05.06.2025 6:30
From 30 May 2025, Australian businesses earning over $3 million per year must report any ransomware or cyber extortion payments to the government within 72 hours. In this episode, Leigh explores: What qualifies as a reportable ransomware or cyber extortion payment Who needs to report and how to calculate turnover thresholds What’s included in the 72-hour reporting requirement Why these reports mat...
Healthcare Breach Fears, Retail Attacks & New Ransomware Laws 05.06.2025 4:28
Fatalities caused by cyberattacks in hospitals? That’s what healthcare leaders are bracing for—and that’s just the beginning. In this episode of the Don't Be A Sitting Duck Podcast , Leigh Kefford unpacks the critical cybersecurity threats facing Australia right now. We explore: The growing belief that it’s only a matter of time before a cyberattack leads to death in healthcare. New legislatio...
Cybersecurity Threats: Unmanaged Assets, AI Misinformation, and Banking Breaches 01.05.2025 3:20
In this episode, we delve into the pressing cybersecurity issues facing Australia today. From the dangers of unmanaged digital assets to the rise of AI-generated election misinformation, and the recent malware attacks on major banks, we uncover the vulnerabilities that businesses and individuals must address. Tune in to learn actionable steps to protect your digital environment. 👉 Full transcrip...
Australia Hit by Infostealer Malware: Banking Credentials Sold Online 29.04.2025 4:08
Thousands of Australians have had their online banking passwords stolen by stealthy infostealer malware like RedLine and Raccoon Stealer. These credentials are now being sold on dark web marketplaces, putting businesses and individuals at risk. In this episode, I break down how infostealer malware works, why it's so dangerous, and the key steps you must take to protect your business. Episode N...
Super Fund Cyberattack: What Went Wrong & How to Stay Safe 04.04.2025 3:50
A coordinated cyberattack hit several Australian super funds—including AustralianSuper, Hostplus, and Rest—leading to major financial and data loss. This episode explores how the breach happened, the method known as credential stuffing, and steps businesses can take to avoid a similar fate. Main Stories Covered: Credential stuffing attacks on super funds $500,000 stolen from compromised Australian...
Ransomware Attacks Hit Record High – Are You at Risk? 18.03.2025 3:33
February 2025 saw ransomware attacks hit an all-time high, with cybercriminals exploiting software vulnerabilities to hold businesses hostage. At the same time, social engineering scams are becoming more deceptive, tricking victims into handing over sensitive information. In this episode, I break down: ✅ Why ransomware attacks skyrocketed and how businesses are being targeted ✅ The growing threa...
Major Cyber Incidents: Brydens Lawyers Breach, ASIC's Action Against FIIG Securities, and Ballista Botnet Threat 18.03.2025 4:30
In this episode, we delve into recent significant cybersecurity incidents: a massive data breach at Brydens Lawyers, ASIC's legal action against FIIG Securities for prolonged cybersecurity failures, and the emergence of the Ballista botnet exploiting vulnerabilities in TP-Link routers. These events highlight the critical need for robust cybersecurity measures across all sectors. For more insig...
Cybersecurity in Papua New Guinea: Are They Ready for the Digital Future? 15.03.2025 5:53
Papua New Guinea is going digital—but is it secure? In this episode of Don't Be a Sitting Duck , we dive into the cybersecurity challenges facing PNG’s government, businesses, and critical infrastructure. We discuss real-life cyberattacks—including ransomware incidents affecting PNG’s Department of Finance and the Internal Revenue Commission—and explore what needs to change to protect the nati...
Genea IVF Data Breach Exposes Sensitive Health Records 08.03.2025 2:52
A major cybersecurity breach has rocked Australia’s healthcare sector. Genea , a leading IVF provider, was hit by a cyberattack that compromised sensitive patient data, exposing medical histories, test results, and personal information on the dark web. In this episode, we break down how the attack happened, why it matters, and—most importantly—what businesses can do to prevent similar breaches. 🔗...
APRA’s CPS 230 & CPS 234: Strengthening Operational & Cyber Resilience 25.02.2025 4:55
In this episode of Don't Be A Sitting Duck, we unpack APRA’s latest regulatory updates: CPS 230 on Operational Risk Management and CPS 234 on Information Security. With CPS 230 set to take effect in July 2025, organizations must prepare for stronger risk management, business continuity, and third-party oversight—especially in cloud outsourcing. Plus, we break down CPS 234, which mandates strict cy...
Lazarus Group’s $21M Crypto Heist & Australian IVF Data Breach 24.02.2025 3:46
Cybercriminals are relentless, and this week’s stories prove just how high the stakes are. North Korea’s Lazarus Group Strikes Again: The notorious state-backed hacking group has pulled off another major crypto heist, stealing $21 million in Ethereum from the Bybit exchange. But how did they do it, and what does this mean for the future of cryptocurrency security? Australian IVF Data Breach: A maj...
PNG Tax Office Cyberattack – What It Means for Businesses & Government 16.02.2025 6:01
Papua New Guinea’s Tax Office Hacked – What You Need to Know! The Internal Revenue Commission (IRC) of Papua New Guinea has suffered a devastating ransomware attack, shutting down critical systems and exposing major cybersecurity weaknesses. With government agencies and businesses now on high alert, this breach raises urgent questions about cybersecurity in PNG and beyond. In this episode of the D...
Game Over: Steam Malware, Romance Scam Script, and Cybersecurity Awareness 15.02.2025 4:31
Is your favorite game a cybersecurity threat? In today’s episode of Don't Be A Sitting Duck, we dive into a shocking Steam malware case where a popular game turned into a digital trap. Plus, the Australian Federal Police have released a romance scam playbook used by criminals—learn how scammers manipulate victims with scripted deception. Lastly, we discuss four practical ways to bring cybersecurit...
CommBank & Telstra’s Fraud Tech, Valentine’s Phishing Scams, and Cybercrime as a National Security Threat 12.02.2025 4:18
In this episode of Don't Be A Sitting Duck, we’re breaking down three major cybersecurity threats that businesses need to be aware of: CommBank & Telstra’s Fraud Detection Partnership – A new fraud indicator system is set to improve identity theft detection by 25%. Learn how this technology works and what businesses can do to protect themselves from financial fraud. Valentine’s Day Phishing Scams...
Apple’s Zero-Day Patch, Healthcare Cyber Risks & Australia’s Cyber Attack Surge 11.02.2025 4:18
In today’s episode, we dive into three critical cybersecurity threats that businesses can’t afford to ignore. Apple has just released an urgent patch for a zero-day vulnerability affecting iPhones and iPads—find out why it matters and what you should do immediately. Meanwhile, cyber threats in the healthcare sector are escalating, pushing the need for stronger collaboration and proactive defense s...
DeepSeek AI – A Cyber Threat You Can’t Ignore 10.02.2025 5:25
Artificial Intelligence is evolving, but so are cyber threats. In this episode of Don't Be A Sitting Duck, we break down DeepSeek AI and how cybercriminals are leveraging it to supercharge phishing, malware, and business email compromise attacks. Learn how to defend against AI-driven threats and ensure your business isn’t an easy target. What is DeepSeek AI? How cybercriminals are weaponizing AI W...
North Korean Hackers, LinkedIn Scams & ACSC Phishing Warnings 09.02.2025 4:55
Welcome to another episode of Don’t Be A Sitting Duck! This week, we uncover shocking cybersecurity threats that businesses and individuals must be aware of: North Korean hackers, also known as the Lazarus Group, are using LinkedIn job scams to steal credentials and deploy malware. We’ll break down how this attack works and how you can avoid being a victim. Building a culture of cybersecurity with...
Thermomix Recipe Community Data Breach – What You Need to Know 07.02.2025 5:24
Vorwerk, the company behind Thermomix, has confirmed a data breach affecting users of its Recipe Community forum in Australia, New Zealand, and several European countries. While no passwords or financial information were compromised, personal details—including names, addresses, birthdays, and phone numbers—were accessed by cybercriminals. In this episode of Don't Be A Sitting Duck, we break down:...
47 Million Data Breaches in 2024 + AI Bans & Windows 11 Warnings 06.02.2025 4:31
In this episode of Don't Be A Sitting Duck, we break down three major cybersecurity stories affecting businesses today: DeepSeek AI Banned – Why the Australian Government has banned DeepSeek AI from all government devices. 47 Million Data Breaches in 2024 – One breach every second? The latest report reveals shocking cyber attack statistics. Windows 11 – Act Now! – Businesses must prepare for the t...
After the Flood: Protecting Your Business from Hidden Cyber Threats 03.02.2025 5:54
Floods can devastate businesses, causing physical damage and operational chaos—but the risks don’t stop there. In this episode of Don't Be A Sitting Duck, we explore the hidden cybersecurity threats that emerge after a flood. From compromised devices to phishing scams disguised as recovery support, disasters create the perfect storm for cybercriminals to strike. We'll walk you through the essentia...
03/02/2025 - Apple Gift Card Scams: How They Work and How to Avoid Them 02.02.2025 5:16
In this episode of Don’t Be A Sitting Duck Podcast, we’re uncovering the tricks behind Apple gift card scams—one of the most common and deceptive frauds targeting individuals and businesses alike. Learn how scammers convince victims to pay using gift cards, the warning signs to watch for, and what to do if you’ve been targeted. But knowing the scam isn’t enough. If you want to protect your busines...
31/01/2025 - DeepSeek AI Warning, Dover’s Cybersecurity Emergency, and 2025 Cyber Priorities 30.01.2025 5:10
In today’s episode of Don’t Be A Sitting Duck Podcast, we break down three major cybersecurity developments: DeepSeek AI Privacy Concerns – Australian ministers are urging caution over the Chinese-developed AI chatbot DeepSeek, citing potential security risks. Dover’s Cybersecurity Emergency – The City of Dover has declared a state of emergency due to a potential cybersecurity breach, highlighting...
SPECIAL - Take Caution: Cyclone Preparedness for North Queensland Businesses 30.01.2025 3:58
With a potential cyclone approaching North Queensland, now is the time to ensure your business is ready. In this special ‘ Take Caution ’ episode, we share critical IT and cybersecurity steps to protect your data, keep operations running, and stay secure. Don’t wait—prepare now! Key Takeaways: Back up and test critical business data before a cyclone forms. Power down non-essential equipment and pr...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.