The Technology Translator
Technology is now part of every business, but most business owners, managers and leaders were never taught how to make technology decisions.
The Technology Translator is a practical podcast that breaks down technology, cybersecurity, AI and digital business topics into plain English.
Hosted by Vic, a technology professional with more than a decade of experience working with Australian organisations, each episode explores the questions business leaders are asking every day:
What technology do we actually need?
How do we reduce risk?
What should we know about AI?
How do we get value from technology without getting lost in the jargon?
No buzzwords. No vendor sales pitches. No unnecessary complexity.
Just practical conversations designed to help Australian businesses make technology make sense.
The Technology Translator
Passwords, MFA and Why Most Businesses Are Easier to Hack Than They Think
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Most cyberattacks don't start with someone breaking into your systems.
They start with someone logging in.
In this episode of The Technology Translator, Vic shares one of the most embarrassing moments of her cybersecurity career – falling for a phishing simulation while working for a company that specialised in phishing awareness training.
From phishing emails and password reuse to multi-factor authentication (MFA) and password managers, this episode breaks down how cybercriminals really gain access to businesses and why good people make security mistakes every day.
You'll learn:
- Why phishing attacks still work
- The difference between opportunistic and targeted attacks
- How much information strangers can find about you online
- Why passwords alone are no longer enough
- How MFA can prevent a simple mistake becoming a major incident
- Why password managers are one of the easiest security wins available
Cybersecurity isn't about being perfect. It's about making sure one human mistake doesn't become a business-ending event.
Thanks for listening to The Technology Translator.
If you found this episode useful, please follow the podcast and share it with someone who has ever been responsible for making a technology decision.
You can connect with me on LinkedIn - https://www.linkedin.com/in/victoriaccole/
Instagram - @thetechnologytranslator
Email - vic@thetechnologytranslator.au
Remember:
You don't need to become technical.
You do need to become informed.
Welcome to the Technology Translator. I'm Vic. Every episode we break down technology, cybersecurity, and AI into plain English for Australian business leaders. Welcome to the podcast. Hey everyone, and welcome back to the Technology Translator for episode four. I'm Vic, based here in Brisbane, Australia, and if this is your first time listening, this podcast exists for one simple reason. Technology is now part of running a business, whether we like it or not. Yet most business owners, managers, and leaders have actually never been taught how to make technology decisions. And cybersecurity is probably one of the biggest examples of this. Because when most people hear the word hacker, they picture someone sitting in a dark room, wearing a hoodie, typing furiously while trying to break into systems. The reality is far less exciting. Most cyber incidents don't start with someone breaking in. They start with someone logging in. Today we're going to talk about passwords, multi-factor authentication, phishing emails, password managers, and why most businesses are far easier to compromise than they realize. But before we get into this, I want to tell you one of the most embarrassing stories of my entire career so far. The day I failed a phishing simulation. So a number of years ago, I worked for a company that specialized in phishing simulation and cyber awareness training. In other words, we literally taught people how not to fall for phishing emails. I saw thousands of examples. I knew exactly what they looked like. I knew what to look for. Hey, I even designed some of them. I knew all the tricks. And then one day, I clicked one. The day before, a colleague had mentioned they were looking for a new role and asked whether I'd be willing to provide a reference if a recruiter reached out. Of course, no problems. The next day, an email landed in my inbox. Please click here to provide a reference. Makes sense, right? I was expecting it. I wasn't looking for the spelling mistakes. I wasn't checking the sender. I wasn't taking into consideration that they even had the wrong name in the email. I wasn't analyzing links. My brain simply connected two events together and said, Yep, that's what I was expecting. Click. And you know the worst part? Nothing happened. I thought to myself, oh, that was odd. I'll click it again. No. Anyway, about a week later, someone goes, You failed the phishing simulation. And I remember sitting there thinking, oh, it was that email. You've got to be kidding me. I work in the industry. I know what these look like. And I still clicked. And look, the lesson wasn't that I needed more cybersecurity training. The lesson was actually something a lot more important. Attackers don't need to catch you when you're at your best. They only need to catch you when you're busy or distracted or tired or juggling 10 or 20 things at once. And if you've ever clicked on something you shouldn't have, you're not stupid. You're just being human. And one of the things I've noticed over the years is that people think phishing emails only work because people aren't paying attention. And that's only partially true. The reason that phishing works is context. Attackers don't want you thinking logically. They want you reacting emotionally. Maybe you are expecting a parcel. Maybe you were waiting on that invoice. Maybe you're expecting a password reset. Maybe you're waiting at a job reference request. Maybe you're rushing between meetings. The best phishing emails don't feel suspicious. They feel expected. And with AI becoming more accessible, these emails are getting significantly better. Gone are the days where every phishing email looks like it came from a Nigerian prince. The spelling is better, the grammar is better, the formatting is better. Sometimes the only clue is actually tiny. An email address that uses a lowercase R and N instead of an M. A domain name that's almost correct. A logo that's slightly different. Something you'd probably never notice at four o'clock on a Friday afternoon after a very long week. And that is exactly what attackers are counting on. And you are easier to research than you think. One of the most interesting exercises I've ever seen happen during a cybersecurity workshop is one that I did with an organization I worked with. The organization that we were training had suffered a breach previously, and part of the education process involved showing people how much information was publicly available about them. And what we ended up doing is it was a three-part series. We had three different workshops about two weeks apart, and each workshop had a different cohort of people. Before each workshop, a handful of attendees were actually selected, and our team had spent some time researching them. It wasn't anything illegal. It was nothing sophisticated. It was really just Google, LinkedIn, Facebook, Instagram, publicly available information. And during this workshop, our team began presenting what they'd found. They were saying, All right, well, John, look, we know where you work, we know your job title. Oh, and this is your partner's name, and these are your children's names, and these are the sporting clubs that you're associated with. This is when you last went on holidays, these are your interests, this is your professional history. And the room got very quiet. And the reason is that people started realizing how much information they'd voluntarily shared over the years. And then came the uncomfortable part. The facilitator asked, How many of you use your children's names and passwords? And a few hands went up. How many of you use pets' names? More hands. Birthdays? More hands again. Now, all of a sudden, the information that seemed fairly harmless wasn't so harmless anymore. Because if someone decides to target you specifically, they're not guessing randomly. They're using information you've really already given away. And then we jump into opportunistic attacks versus targeted attacks. This one's an important distinction. Most cyber attacks are not someone looking at you going, I am going to target you. No one has chosen you specifically. Most cyber attacks are quite opportunistic. All they're looking for is an unlocked door. It's the digital equivalent of someone walking down the street, checking door handles. They're not interested in who owns the house. They're interested in which house is easiest to enter. And that's the vast majority of cybercrime. And the second type is actually targeted. It's where someone decides that your organization has something they want. Maybe it's money. Maybe it's intellectual property. Maybe it is customer information. And maybe it's also access to another organization through yours. And that's where the research starts happening. And that's where social engineering, so looking you up online and trying to actually engineer their way into the business by using information they can find, becomes far more sophisticated. And unfortunately, technology has actually made that easier than before. The barriers to entry are lower, the tools are a lot more accessible, and research that once took hours can often be done in minutes, which means businesses of all sizes are now potential targets, and that's not just large enterprises. And one of the things I hear quite often is, look, my password is pretty secure. Good luck for someone trying to get in. And look, maybe it is. But passwords have a fundamental problem. Humans created them. Humans are predictable. We use names, birthdays, sporting teams, pets, favorite places. And even when we think we're being clever, we're usually creating a variation of information that's already publicly available. I thought I was being hilarious as a teenager using the password password zero and setting my uh password hint as the password is nothing. But ultimately, one of our biggest issues is that there is a lot of password reuse out there. And let's be honest, most people aren't remembering 200 unique passwords. They're remembering three or four reusing them everywhere. And here's why that is dangerous. Imagine a website you used five years ago gets breached. Your email and password become publicly available. Now, imagine you're using that same password for your email account. Suddenly, one breach becomes multiple breaches. And not just because your business was hacked directly, because one password got reused. And if there is one thing I wish every business would implement properly, it's multi-factor authentication, MFA. Now, most technical explanations talk about this as something you know and something you have. Something you know being the password that's in your head, and something you have being the code that's just popped up on your phone. I think there's a much simpler explanation. MFA gives you a second chance. It gives you the chance to realize, ooh, have I made a mistake here? Let's say you clicked a phishing email, you enter your username, you enter your password, and then suddenly your phone lights up asking whether you'd like to approve a login. That moment matters because often that's when you stop and think, hang on, should I actually be doing this? Is this something normal? And it gives you that extra moment of clarity. And sometimes that one tiny pause is all that needed to prevent a bad day from becoming a really expensive one as well. Is MFA perfect? No, nothing is. But it's one of the simplest and most effective security controls available, and you can very easily turn it on with just a touch of a button in most scenarios. And now I mentioned this in one of my previous episodes, why I love password managers. And I get asked all the time whether a password manager is actually safe. And my answer is always the same. Compared to what? Because the alternative isn't perfect security. The alternative is usually people reusing passwords or writing them down, having that little black book on their desk, or using variations of the same password everywhere. I mentioned my password zero that I thought was hilarious. Well, I also had password one and password two and password three for a number of different accounts for a solid year or two. Bit scary looking back on it. But when I create a new account using a password manager, it generates a completely random password, letters, numbers, symbols. Things I can tell you right now I'd never remember for myself. And the password manager stores it, my browser fills it in. My phone also fills it in. I don't need to remember it at all. And more importantly, I know that every account has a unique password, and that alone dramatically reduces risk. People often assume password managers are about convenience. They're not. They're actually about reducing human error. So if you're to do a quick cybersecurity health check, here's a simple exercise. Ask yourself these questions. Do all staff use MFA? Do all staff have unique passwords? Do you use a password manager? Are former employee accounts disabled immediately? Do you know who has administrator access? And would you know if someone logged into your Microsoft 365 environment tonight? If you're uncomfortable answering some of those questions, that's okay. A lot of businesses are. But it might also be a sign that there are some opportunities to improve. And look, one thing to do after this episode. When this episode finishes, I want you to do three things. Google yourself, Google your business, and then visit the site Have I Been Pwned. So that's H-A-V-E, I Been Pwned. P W N E D. And search your email address. Spend 10 minutes looking at yourself the way an attacker would, and you might be surprised what you find. Not because someone has done something wrong, but because most of us have never stopped to look. One of the biggest misconceptions about cybersecurity is that it is about stopping every single attack. And it isn't. Every one of us will make mistakes. Every one of us will get distracted. And every single one of us will click on something we shouldn't at some point. Good cybersecurity isn't about being perfect. It's about making sure one mistake doesn't become a disaster. Strong passwords, a password manager, multi-factor authentication, a little bit of awareness, and none of those things are particularly complicated. But together, they make your business significantly harder to compromise. And remember, most cybercriminals aren't looking for the hardest target. They're looking for the easiest one. The goal isn't perfection. The goal is simply not being the easiest door to open. So thanks for joining me for another episode of the Technology Translator. If you've enjoyed today's discussion, feel free to share it with someone who still thinks their dog's name and their birthday is a strong password. I'll catch you next time. Thanks for joining the episode. If you do want to follow me on Instagram at all, you can find me under the Technology Translator. If you would like to email me, Vic at the Technology Translator.au. And I guess I wouldn't be doing this properly if I didn't say, if you like what you hear, hit the follow button. There will be more of these episodes coming up.