UnHacked the podcast with hosts Justin Shelley, Bryan Lachapelle, and Mario Zaki.

There's no license, no exam, and no third-party check required to call yourself a cybersecurity expert. On episode 100, we admit what that really means for your business.

For their 100th episode, Justin Shelley, Mario Zaki, and co-host Joshua Holloway skip the guest interview and get honest about what a hundred episodes of talking cybersecurity has actually taught them. The takeaway isn't a highlight reel, it's a confession: cybersecurity has no licensing board, no universal certification, and no guaranteed way to know if the person protecting your business actually knows what they're doing.

They walk through the moments that changed how they think about security, including the 2017 CCleaner supply chain attack, where hackers hid malicious code inside a trusted software update used by millions of people, and a wire fraud case where the FBI actually recovered stolen funds because the money landed in a U.S. bank account before it could be moved offshore. Mario also tells the story of a former podcast guest who claimed years of cybersecurity consulting experience but went silent every time the conversation turned technical, using the interview as a sales pitch instead of answering real questions.

Justin explains why he stopped repeating the stat that "97% of breaches could have been prevented with basic security measures." After building a 12-episode series breaking down the fundamentals from scratch, he realized there's nothing basic about it. It's complicated, it changes constantly, and a lot of business owners, and a lot of IT providers, are guessing more than they'd like to admit.

What you'll learn:

  • Why there's no credentialing system for cybersecurity experts, and what that means when you're hiring an MSP or consultant
  • How the 2017 CCleaner hack let attackers hide malware inside a legitimate software update trusted by millions of users
  • How one wire fraud victim actually got their money back through the FBI, and why most victims never do
  • What to do first when a security incident happens: assess, call your insurance carrier, then pull your incident response plan
  • Why "basic" cybersecurity advice is a myth, and what changed after the hosts dug into the fundamentals themselves