Welcome to This Is Not A Data Podcast!
Aug. 27, 2026

The Post-It Note That Hacked Sony

The Post-It Note That Hacked Sony
The Post-It Note That Hacked Sony
This Is Not A Data Podcast
The Post-It Note That Hacked Sony

This week, Bren & Lenno venture into the world of security, starting with a media company whose entire channel went completely offline. Not because of a sophisticated breach, but because of a simple but stupid human action.

This episode digs into why data sovereignty and geopolitics get all the corporate attention, while the far bigger risk sits closer to home.

And ultimately they address the question that you can spend a billion dollars on security, but what's the point if it only takes one person to undo it?

Bren: Hello and welcome back to This Is Not A Data podcast. Today we're talking about where your data actually lives, the servers, the geopolitics, the hyperscalers, and whether any of us stop to think about it when we tap accept on another app. But the real story today is a post-it note and the implications from a cybersecurity perspective. You can spend a billion dollars on security, but one careless human action can undermine it all. So are we the weak link? Or is it the systems that we trust that let us down? Let's get into it. Hello, hello. We're get straight into it because this is another episode of This Is Not A Data podcast. I think you might be surprised. I've also got my co-host with me, Leno.


Lenno: Hey, good morning. Hey, Brian.


Bren: How about this? I'd like to say it is a gloriously sunny day in South West London. The birds are tweeting, the sun is shining and I'm sat here with my slippers on, watching the world go by, but that would be a total fabrication. But you know what? We can dream. We can dream.


Lenno: In the world nowadays we can generate close to everything, so why not generating the weather?


Bren: Although, actually funny you say that, and I know we've had sort of a period of dry spells. One part that really baffles me, and I think we're messing with Mother Nature. When you go to the Middle East and be fortunate enough to go to Dubai and Abu Dhabi a few times to play golf and see friends, they do something called cloud seeding. They


Lenno: Yes! Yes!


Bren: make it rain when they want to rain. Now, I am both sort of fascinated and terrified this because I don't think we should be effing with Mother Nature, but they can make it rain when they want.


Lenno: Yeah, I've read articles about it and also reading people. Yeah, at the one hand side, of course, it's scientifically exciting. At the other hand side, it's also scientifically really impactful and maybe borderline dangerous.


Bren: Yes


Lenno: You know, I also need to be very, very honest to myself. I like skiing a lot. Though in the winter we


Bren: Okay, thanks to you.


Lenno: go to the Alps. Years ago there was more than enough snow to enjoy a couple of weeks of skiing.


Bren: Yeah.


Lenno: Nowadays I'm reliant upon the resort or the area to create artificial snow. The only thing, quote unquote, that they now need is temperature. The temperature


Bren: Mmm.


Lenno: needs to be low enough, but then, of course, they can generate snow. So the slopes are accessible close to all of us. So I think for our human convenience, we seem to be able to bend the rules to our favor. whenever it is more favorable to us. So make it rain in the desert by cloud seeding, creating snow in the areas where the temperatures are enough to enjoy winter sports.


Bren: I hadn't actually thought, I mean, it'd been a big scare as well. I hadn't actually thought about that because there's certainly some of the snowfall over the last seasons or two has come when you least expect it. think the end of last season there was an absolute dump and some


Lenno: Yeah.


Bren: of the best conditions ever. there's definitely a part that fascinated by how it works, but also should we be doing it because the part... I don't know whether when you were growing up you watched any of the cartoons, but it just feels a bit like if we're not careful, we'll all be wandering around, we'll have an individual rain cloud that just follows us around. If you piss off Mother Nature, she'll be like, I'm just going make it rain.


Lenno: Imagine that in so many years from today, you will have an app on your phone. We need say like on a very hot and sunny day. I now want to activate my personal cloud. Not my personal data cloud, but my personal cloud to just give me that sheer amount of shade. to protect me from. Maybe, well, anyways, that's a sci-fi section that we are now touching upon. Yeah.


Bren: Well, I mean, that's probably the next iteration of this is not a sci-fi podcast that we can spin off. So we'll come back


Lenno: Yes.


Bren: to the viewers and give them what they want. you mentioned, I talking about clouds, I think one of the conversations I'd like us to think about today is the whole security aspect. I've certainly become a little bit more laissez-faire, little bit more flippant with where my data is hosted. Now I don't know whether that's because I don't have anything to hide. I've got other things that I think are more important to worry about, or I'm just being wonderfully naive and going to be sort of, it's going to come back to bite me at some point in the future. In talking to a very good friend of mine who runs quite a big transformation, we're talking about where service need to be hosted. And there's obviously been a big shift with everything that's happened in the states, sort of from a political situation


Lenno: geopolitics.


Bren: and the geopolitics of what's happening. It wasn't really something that I was too cognizant of, but from a people perspective, there's one side, but from a data... I guess what I'm trying to ask is in your experience of being a data exec, has it been much of a consideration around the security aspects or is it becoming more of a consideration do you think?


Lenno: think it's becoming more consideration nowadays and especially given the geopolitics, legislations


Bren: Hmm.


Lenno: of course that have been triggered over so many years. The most eye-catching parts are US, China, Russia, these type of areas. think growing up in Europe, there's quite some legislation and with that, As a consumer, I'm maybe naively thinking that all of my data is going to be protected. Nevertheless, I'm indeed using services, using services from different geographies. So it's probably not being as protected as a consumer believes that it is. As a company, the... data positioning, so residency definitely is a topic. although over the years, we have, I think, grown much more comfort and accustomed to consolidating everything into large data-ware hyperscalers. Most of the hyperscalers that a lot of companies are using nowadays are US oriented. And you've actually done the layup already with the shift in the geopolitics. I think that nowadays is provoking also the rethinking of where my data needs to be hosted. Where do I want to position it? I think it does pose a number of specific questions to our IT organizations but equally also our security officers. What is protected? How do I do that? And where do I want to host services from?


Bren: And kind of thinking out loud, when you use your AI of choice, you ever think, I wonder where the data is hosted for this? Have you ever thought that?


Lenno: I think the honest answer is no, because it's a service. And this is response coming from me as a consumer, as an individual. I'm using


Bren: Yep.


Lenno: an Apple device. It's my iPhone. Now, of course, Apple, US company. There's a lot of data that is being tracked through the phone in itself. using more devices as you can see there's the watch so it's tracking all kind of dynamics of me as an individual. All that information is being stored somewhere which is not the Netherlands. I'm aware of that. Using messaging services of another big company, Meta, you know. also USB. So my data, a lot of the data that I'm using is actually hosted somewhere else or is going somewhere else. Around me, I see young people using TikTok, which is basically positioning data in a different part of the world. You know, so I don't think that we as individuals unless you are telling me that you are very, very cognizant about it, are very aware of where the data actually is hosted or where the data is going to be stored.


Bren: It's I mean, maybe this is a slightly embarrassing admission I've not once thought when using Claude or Your choice. I wonder which server this is gonna be Never the same with with whatsapp I mean, they'll say that obviously messages are encrypted end-to-end and whether you believe that or not is is another story But I'm not I'm not thinking when I'm messaging my wife, you know, have a safe journey back from up north. has that has that hit a US server? I am always this is this going to cause me problems in the future? Not once a consideration. And I


Lenno: No. No.


Bren: wonder whether there's been a bit of a disconnect between public use of consumer use of AI models and the data sovereignty question. I think from a corporate perspective there's much more of an OF this could cause us real problems if we get it wrong but from a consumer perspective it's about convenience. I'm going to use Google Maps because I don't want to get lost, I don't want to get run late but from a business if our server resides in California or Texas or wherever it might be that could be a problem.


Lenno: Yeah, so yeah, data residency and where the servers are hosted from, I think is definitely a topic that is corporate-wise coming up more and more. And specifically also triggered by the geopolitical situation nowadays.


Bren: Hmm.


Lenno: If you were to shift that to AI, AI and the capability of support mechanisms that we can have, whether these are the generation of agents, the generation of software, et cetera. The models have been trained on particular data sets that are available in the public domain. I will not be able to, or at least not to my knowledge that I am able to genuinely assess how pieces of code or entire codes have been generated, what has been used as the basis for it. Are there lines of code that are fetched from the public domain and are being reused, maybe adjusted or reused? Will there be a particular piece of code in there that is being reused that may open a back door into my company, I don't know. To that I'll probably be at the mercy of the model that is generating, the company that I've hired to generate the model for me or the application for me. Maybe there will be an interesting legal case if and where anywhere in the future or in the near future there's a definitive case of exposure. And I don't know if that's going to be reality or not. But there's pieces of history, pieces of reuse that is happening. If I were, which I'm not, if I were a very smart hacker 20 years ago, and I would bury some lines of code somewhere on the internet, publicly available, and that data set, unintended, unconsciously, has been used in training the models that are publicly available today. But the coding was rather smart. Maybe pieces of the code is being reused nowadays in the generation of applications. You can even feed, I don't know, maybe a legacy application now to a model. And then please generate a state of the art application for me that can support all of these processes as well. I don't know what are the lines of codes that and the model is going to provide me with. It's going to look amazing. It's going to look state of the art, but in the background, it may have been formed on an old AS400 type of application, you know.


Bren: You


Lenno: But then bits and pieces of code in there that are actually opening the back doors into my company. I don't know.


Bren: And I wonder whether, I mean, had a good chat with a friend of mine called Ben last week around some of the cyber security kind of considerations. And certainly that when you think about data sovereignty and where your data resides, one part, how you protect it is another part. I mean, my flippant response is if we're going to adopt a Microsoft stance or Microsoft kind of initial starting point and then you build on the security layers from there, they're going to spend more than a billion dollars a year on security. So, know, I'm going to trust that they get it right. We're certainly not going to do it ourselves because that would be a fool's errand and we'd get nowhere near. But the part that, and he and I had a really good and interesting conversation, still doesn't ignore the social engineering part of the security elements, which is... the part that will always let us down. It's the, you know, the clicking, the clicking of links. Just very quickly, when I worked for a big media firm, Sony, they had a slight issue one year when one of the channels went completely down. They got hacked. Now it transpired that the security was as it should be and everything performed as it should. But one of the employees had stuck a Post-it note to the screen with the username and password and had taken a photo and used it on social media to show the picture of somebody's leaving, do or whatever it was. And they social engineered that to be able to then cause trouble. Which is where the conversation around the cyber elements are. They've got to get it right. Our cyber colleagues have got to get it right every single time. The nefarious people have only got to get it right once. And so the reason for saying that is kind of tying the two pieces together. You've got the sovereignty around the geopolitical stance and making sure that you're comfortable where your servers reside. You can have the greatest protection in the world, but if somebody's going to be a Wally and get something wrong, that just bypasses everything. So do we just sit here and panic or do we focus on one or the other? I'm not sure. And then when you tie it back to your question around sort of AI, the impact of using the different models, I just don't think enough people really care or give an S about that. And it's just like, whatever's what happened. And until it goes wrong, I'm just going to ignore it or pretend it's not an issue.


Lenno: So many references to this one. At the end of the day, indeed, it does come down to humans. To us again, and again, great respect for all of the people working in cybersecurity because they are hampered or challenged with attacks on a daily basis and multiple


Bren: Hmm.


Lenno: times a day. think earlier you and I spoke about the many exposures that are hit a company on a daily basis. So great respect in that area. I think we as individuals, as employees, we definitely need to take security and cybersecurity very, very serious, more serious than we probably are doing.


Bren: Mm.


Lenno: I think a couple of elements to that. Reuse of passwords. is definitely an item. How frequently do you do that? And be very, very honest while listening to yourself. That's one. Second, what is the difficulty of the passwords that you come up with? Do you allow an And of course, there's now services that are available. So you can use all kinds of key vaults, type of


Bren: and


Lenno: things that will generate a password for you. It will store it somewhere. But then, look, it's going to be stored somewhere. So when it's being stored, it's like a bank. You can actually do a heist.


Bren: Hang on, listen, I use one of these services. Don't tell me that. You're going to break


Lenno: No,


Bren: my bubble.


Lenno: So yeah, okay. So you're using Fort Knox, which is pretty well, pretty well protected.


Bren: I'm


Lenno: There's probably someone out there that is considering to break the bank at some point.


Bren: Yeah, yeah.


Lenno: Now, if you transpose that into a company, every company's security protocols will also stay on a frequent basis. You need to change your password. I believe that on the basis of the frequency, people will start to maybe disengage on the security aspect of it. I need to change my password again. Okay. I'll do something. I need 10 digits. Okay. I'll start with one and then end it at zero. Next


Bren: Yeah.


Lenno: month, I will start at zero, do the other way around. You know, it's... People will come up with certain rhythms. So I think with the technology today, and Anthropic probably has models right now that can break codes, can hack almost into every system. So models are not going to be publicly available. The simplicity is probably also to be found by the simplicity or the ignorance of people generating or creating passwords and creating their own layers of protection in them. And that's a password side. Now, what you've also mentioned is people clicking on links, social engineering. So there is an email coming in. There's probably a piece of urgency in that. And therefore you're more likely to overlook the obvious. Who did it? Where is this coming from? Is this genuine? I'll directly click on it. And then you start to supply certain bits and pieces of information. I'd also see and I don't know. And please keep me honest if we are going into into a certain certain rabbit hole. There's also now more, what is it, job seeking type of events happening where there is quote unquote recruiters or people pretending to be recruiters with a


Bren: Yeah.


Lenno: very, very appealing role trying to get in contact with individuals with the sole purpose of extracting company information and with that trying to then find vulnerabilities within the company to move forward.


Bren: That I remember reading I think it was on LinkedIn There was a post that said one of the I guess it's a phishing scheme isn't it ultimately was really really good was really good until the person had sent off the CV and cover letter and then I just got absolutely spammed or whatever the kind of the outcome was that I guess there's always going to be engine ingenious or ingenuity around how nefarious people use technology to do it. I think the part that worries me is exactly that is how do we as consumers, how do we as executives try and keep ourselves safe and moving forward without becoming so paranoid that everything is going to break or be stolen or so forth. And this is where I think a big shout out to the cyber community because the stresses and strains that they run on a recurring basis must just be immense. one that comes to mind, and actually this would be quite an interesting one because Jaguar Land Rover not so long ago got absolutely shut down for two or three months. I think it might've been in long run because they had a cyber attack. Effectively, they took control of the business and held it ransom. Now, not only is that a... absolute devastation for the business. think millions were lost in production lines. But it also transpired from a world that we probably know a bit more about is they couldn't just burn down the warehouse and replace it overnight because it was old and antiquated and held together with sticky tape and and plasters and you know I mean I jest but that side of things then ties back to Where's your data hosted? Which server is it in? How do we do that if know, BCP protocols, disaster recovery. I mean, I'm gonna get way over my skis very quickly in kind of this side of the world, like all of, and I guess it really comes down to like, none of this happens in isolation. And the people side is really what I guess worries me because we're all being pushed to do more and more with AI and don't get me started about sort of just doing


Lenno: Mm-hmm.


Bren: AI. really grinds my gears. But you then say, well, how do we become more efficient? How do we leverage technology? There's a clamor and a desire and a drive to do more quicker without really knowing what we're trying to do, other than we're just doing it quicker. And then people feel the pressure and somebody makes a mistake and then the world ends. I mean, that's a bit hyperbolic, I yeah, I feel like we're just being squeezed from all sides. And that's really where that like the cyber question was. I just feel for them because I don't really know quite what to do in that scenario.


Lenno: Yeah, what to do, I think we as individuals, we need to be very conscious about how we interact and what layers of protection I can actually embrace


Bren: Hmm.


Lenno: in my personal life, but equally also in my working life. Now, in all of the companies that I've worked for, for. We also have these annual trainings around awareness and how you basically work with levels of security. And that, I must say, that does help. And it's almost like training a muscle. Now, if you want to do a sports event, you need to train a muscle. If you want to be good at something, you need to train it. You need to use it frequently. It's like that equally when you are layering fail saves as part of your day-to-day when it comes to cyber security. So when you are not thinking about ways to make your password unique on all of the applications that you're using, The tendency is that you will probably have a password that you're using everywhere. So the ability to hack that setup is much more easy than when there is unique entry points for every application. So I think there's definitely something that we as individuals. can and must embrace, especially in a digital world.


Bren: Yeah, and the other kind of along those lines, I don't know where the thought came from, but what about the older generation? You know, we think about keeping passwords and, you know, if you've got elderly relatives or if one has elderly relatives or it kind of interacts with the older generation who may not have a smartphone, may not be particularly au fait with the technology. I mean, I know a few people who still write down their passwords in a notebook somewhere and so forth.


Lenno: Yeah, I know them also. I must say that for me personally, I'm a little bit scared about what is going to happen to me as an individual in, I don't know, 10, 20, 30 years with dementia growing


Bren: Yeah. Yeah.


Lenno: older. You know, I now can remember phone numbers, addresses, passwords, et cetera. How will that be in a couple of years from today?


Bren: Well, I can also remember that not that my wife listens to this but I can remember my first girlfriend's phone number I'm like, mean this is I mean not that I repeat it regularly and probably should never admit this out loud But it's like, you know, how just some numbers stick I don't


Lenno: Yeah, yes.


Bren: I don't think and maybe you could shed some light on this if you ask the younger generation or you asked your daughters to repeat a phone number would they know Would they know what yours is, for example, or like maybe not yours, because that's probably a bit close, but would they be able to repeat numbers, do you think?


Lenno: Limited, I can't remember


Bren: You


Lenno: when we talked about this earlier. I still, maybe for some people this is recognizable, I still know the phone numbers of lifelong friends and their parents.


Bren: Amazing.


Lenno: Seriously, addresses, phone numbers. you know, back then, Sorry, this is my old age. Back then we needed to dial the numbers continuously.


Bren: Yeah.


Lenno: Now it's just scrolling through your address book and I'll dial my contact. know, the one hand side that's super convenient, at the other hand side, the moment that you lose your index, you lose your phone, you're somewhere in, I don't know, in India, you want to use a public pay phone. somewhere, if and where they still exist, by the way, who you're gonna call?


Bren: It's not gonna be Ghostbusters, is it?


Lenno: No, no, exactly, exactly. It's not going to be Ghostbusters. No, no, but what is the number that you actually remember and therefore can you actually make a phone call? I don't know. But yeah.


Bren: And we're going in a very different segue, this is it's fascinating because when so I've got the same number that I started with when I first got my mobile phone. So I went to university in West London. I spent a year in South Africa teaching before I went to university and I turned up and eat your chuckle but with a very thick South African accent and wearing a South African rugby jersey. So everybody thought ironically I was South African. But That number,


Lenno: You're nuts.


Bren: but no, apparently not. Apparently not. mean, the DNA tests are still being conducted. But so I got the number and it starts 07900 and that was a Vodafone prefix.


Lenno: Mm-hmm.


Bren: The girlfriend at university, she had a 07779 number, which was an orange prefix. Back in the day, networks, couldn't, I mean, this was texting territory, you couldn't text across networks for free and you'd also have to press the button same time a number of times to find the letter which if you ask the younger generations today they think it's hilarious because they'd be like well what do mean I have to press the number three three times to get to whatever it is


Lenno: Yeah, see you.


Bren: but yeah well exactly but but the whole premise of you need to know a number because they're not on the network and if they're not on the network then you know I don't get three minutes or whatever it might be But that whole concept is obviously gone. And you're thinking about remembering numbers. I don't know. I don't interact with too many of the younger generation, but you I don't know whether they could remember a number. I mean, I used to have to remember our home phone number because you'd have to say, mom, dad, can you come and pick me up, please? And they'd be like, no. Okay, fine.


Lenno: Yeah, exactly. Yeah.


Bren: But that side of things, the human side of parts is... Is that being lost? guess is the premise of the podcast. But it's amazing how habits change and all of a sudden, we are the weak link when it comes to security, certainly on the internet world and the data world when technology is really cool and helping protect us. if we click on a link or we send some money to somebody we shouldn't have, we are the weak link. That still blows my little mind, really.


Lenno: If indeed to your example, take a selfie in the office while my username and password is duct taped to my desk.


Bren: Yeah. These days I'd have to put it in size like 42 font cause I can't see anything.


Lenno: Yeah, because otherwise you can't read it without glasses. Fair enough.


Bren: But I do wonder, sort of bringing things to a close, that where data is stored, whether things will, I'm going to say in inverted commas, kind of go back to normality in a couple of years time when geopolitical situations change. I wonder whether the average consumer will ever really care of where their


Lenno: Mm-hmm.


Bren: data is. I mean, you hypothetically speaking, if you grew up in Somerset, you live... in a town, you've got your mobile phone, you do your daily things. Do you care whether your data is residing on a server in Texas? Probably not.


Lenno: I don't think so, unless listeners are phrasing this differently.


Bren: This is where I say, yeah, nobody really cares. Then we get inundated with absolute sort of a plethora of questions. But I do think certainly for individuals like you and I who influence business decisions, they're going to become more prevalent. Even if the answer is we haven't got a clue, we need to keep looking at it. I think just ignoring it is becoming less of a less of a less of an option.


Lenno: Absolutely, absolutely. We need to be very, very conscious about what we're doing and how we're treating our data, and especially what are the layers of security that we're bringing in.


Bren: I this is almost as if we planned it, because that's a lovely way to close out. And this is the part that you enjoy the most. I'm definitely going to get you to do it one day. But to everybody listening, thank you again for getting to the end. If you did, then you are still a fan of This Is Not a Data podcast. But what would really make us happy are the reviews. And I'm not talking like the one or two stars. No, no, we are in the five star category game. This is what we're at. Think about the last time we went to an Uber. Five stars, that's all they ask for. We're looking to do the same because, I mean, Leno and I, when we fly to our big speaking engagements, we don't want to fly business, we want to fly first. So we're


Lenno: you


Bren: going to have to fund this somehow. So for everybody listening, that was a joke. But for, please do leave us a review. It does help us with the algo and all that sort of stuff. But we'd love to hear from you. So if you've got any questions, do let us know. But... How about that? one in the locker?


Lenno: Thank you, thank you very much for hosting and guiding this conversation again.


Bren: and I'm hoping we're gonna do this in person soon. So for everybody listening, keep listening


Lenno: listening.


Bren: and we'll see you next time.


Lenno: Exactly. Have a safe one. Bye bye.