Your Security Kit Is their Way In
S02:E25

Your Security Kit Is their Way In

•

Episode description

Your Security Kit Is the Way In

The things you bought to keep attackers out are how they’re getting in. Citrix, Fortinet, forgotten WordPress backups, fake ChatGPT adverts, and the AI in your business that nobody owns.

Some time in early September, somebody found a way through a door that thousands of businesses use to let their staff in from home. The owners didn’t know. Then the emergency fix arrived, patched boxes started rebooting, and that turned out to be another hole attackers were already using.

This week Noel Bradford, Lucy Harper, and Graham Falkner follow one thread through every story: something was trusted, and nobody was in charge of checking that trust. Citrix NetScaler zero-days exploited for weeks before disclosure. A FortiMail flaw with fixes still pending, and Noel’s long-running grievance with Fortinet’s track record. Forgotten WordPress backups handing over email and cloud passwords. Microsoft’s Digital Defense Report showing phishing back as the front door. And fake ChatGPT adverts on Google that walk staff straight into installing a remote access tool.

Then the conversation turns to the AI in your business that nobody owns. Prompted by John Wernfeldt’s LinkedIn post on AI teams and governance teams talking past each other, the hosts translate the problem for Gary Mott’s twelve-person building firm and land on three conditions that take twenty minutes to agree. Noel also announces GRCBolt, his own AI policy pack for UK small businesses, now taking waitlist sign-ups.

What to do this week

  • Email your IT provider and anyone who holds your data. Ask whether they run Citrix NetScaler or Fortinet FortiMail, and whether they’ve patched and checked for signs of compromise. For Citrix, ask whether they’ve applied the second fix released on Sunday 4 October.
  • Find out who looks after your website. Ask them to clear old backup files out of public folders, update WordPress, and change the email password stored in your contact form plugin.
  • Turn on passkeys for the accounts that matter most: whoever runs Microsoft 365 or Google Workspace, and whoever approves payments. Both platforms include passkeys at no extra charge. Forcing everyone to use them needs an extra licence on some Microsoft plans.
  • Tell everyone one rule. No genuine website will ever ask you to press the Windows key and R, then paste something in.
  • Agree three things about AI: which tools are allowed, which data never goes in, and who checks the output before a client sees it. Put a name next to each.

Chapters

  • 00:00 Cold open
  • 00:56 Welcome
  • 01:33 The doors you don’t own: Citrix NetScaler and Fortinet FortiMail
  • 10:15 The back door you forgot: WordPress backups leaking passwords
  • 13:36 Borrowed trust: Microsoft’s report and fake ChatGPT adverts
  • 19:13 The AI nobody owns
  • 23:00 Introducing GRCBolt
  • 25:03 Your Monday morning actions
  • 26:57 Close

Sources

Citrix NetScaler

Fortinet FortiMail

WordPress backups

Microsoft Digital Defense Report 2026

Microsoft’s figures come from its own customer and incident response data, so treat them as vendor telemetry.

Fake ChatGPT adverts and ClickFix

Passkeys

AI and governance

GRCBolt

GRCBolt is Noel’s own product, and this episode has no sponsor. It’s an AI policy pack for UK small businesses: four documents written around your business, a one-off price under £100, no subscription, and editable Word files. It’s guidance only, and it doesn’t replace legal advice or certify you against any standard. Join the waitlist and see the partial sample pack at grcbolt.co.uk.

Related episodes

Mentioned in this episode:

Further listening:

Listen, subscribe, and join in

If this episode was useful, share it with someone who needs to hear it. Especially whoever looks after your website.

No chapters are available for this episode.