2443 - What Every Accountant Needs to Know About Cybersecurity Compliance in the Age of AI with CardinalsByte's Michele Novack

17 Jun 2026 · 19 min · 8 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Cybersecurity compliance for small businesses and CPAs in the AI era, focusing on FTC/IRS-related requirements, risk/compliance management, and practical defenses against AI-enabled attacks.

Guest

Michele Novak, founder of Cardinals Byte; cyber engineer and former financial-sector professional with 30+ years at Bank of America and Capital One; teaches CEU content via CPA Academy and runs free web classes.

Key claims

AI increases threats via deepfakes and “human-in-the-loop” failures; hackers are ahead of AI adoption; compliance requires audit-ready documentation and governance, not just tools or MSP promises.

Notable examples

Deepfake Zoom meeting where AI personas approved a CEO transfer of $25M; a compromised email led to a $40,000 invoice payment to a hacker; voice/video cloning used to impersonate executives.

Notable advice

Enable free email phishing protections; use “three, two, one” resiliency with phone verification for money transfers; geographic deactivation and endpoint vulnerability monitoring; test MFA and train staff; build NIST-based compliance, WISP, and incident response plans.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction of Michele Novak

0:51 to 1:26

Josh introduces Michele Novak, founder of Cardinals Byte.

“Michelle, you are the founder of Cardinals Byte.”

Michele's Background and Passion

1:26 to 2:14

Michele shares her journey and dedication to help small businesses.

“I'm so looking forward to having our conversation today and sharing.”

Current Cybersecurity Concerns

2:14 to 4:00

Discussion on the biggest cybersecurity threats for businesses today.

“So Cardinals Byte is an AI-genic risk and compliance management company for small businesses.”

Best Practices for Cybersecurity

4:00 to 6:30

Michele shares actionable best practices for businesses to protect themselves.

“who don't want to find themselves in cyber trouble?”

Understanding Human in the Loop

6:30 to 8:24

Michele explains the importance of human oversight in AI.

“Even developers with 20 years experience are still struggling to understand how to manage it.”

Engaging with Cardinals Byte

8:24 to 11:50

Michele describes her services and the process of working with clients.

“So, again, understand what it is that you're up against.”

Understanding Cybersecurity Risk Assessments

14:00 to 17:45

Learn about the critical components of cybersecurity risk assessments for businesses.

“contractors and so forth, you might be wildly attentive to best practice for security.”

Closing Thoughts on Cybersecurity

17:45 to 17:56

Discover the importance of proactive cybersecurity measures in business continuity.

“Thank you, Michelle, for this great conversation.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:03Welcome to the Thoughtful Entrepreneur. If you're committed to growing your business by serving audiences with generosity and real expertise, you're in the right place. This is a daily 15-minute show featuring leaders who believe real impact comes from generosity, not hype, which means as a listener, you're going to get the good stuff. In fact, we created podverified.com to give thoughtful leaders like you free tools to show up better on podcast stages like this one. That includes your free podverified score, free podverified guest training, a free media kit builder, and so much more. It's the first ecosystem of its kind built by podcasters who genuinely want to help guests thrive and grow in podcasting.

0:46Visit podverified.com if you'd like to be featured as a future guest. I'm Josh Elledge. Let's get into it. With us right now, Michelle Novak. Michelle, you are the founder of Cardinals Byte. You are a cyber engineer. You are the kind of people, it's good to have someone like you in their corner. Because you help very, very bad things, prevent bad things from happening. but your website is cardinalsbites.com, which we have all linked up to our friend that's listening to the show right now. Michelle, thank you so much for joining us. Thank you. I appreciate it. I'm so looking forward to having our conversation today and sharing.

1:33Well, you sound like you're in a great mood and I think that that's because you're kind of on vacation right now as we're recording this. Tell us a little bit about what you've been doing for fun lately. Oh, listen, so I'm down in North Carolina hanging out with my grandson who's three years old, jumping on trampolines, going swimming, doing all the fun stuff, you know, that a grandma does. It's amazing when you live vicariously through them. That's what I do for fun. Yeah, it sounds divine. And so, again, you're surrounded by trees, mountains, hills. It's absolutely gorgeous there. You know, those of us who down in Florida love to get out and get up into some of those elevations.

2:10So, well, very cool. Well, Michelle, share with us a little bit about your work? What is Cardinals Byte? So Cardinals Byte is an AI-genic risk and compliance management company for small businesses. We predominantly focus on one to 50 employees. It's for CPAs, accountants, tax professionals, and anybody who really has to get compliant with the FTC and the IRS around cybersecurity. But the business itself is my love of my life. I've had, You know, Josh, listen, I've worked over 30 years in the financial sector for large corporations like Bank of America and Capital One. And, you know, auditing is in my blood.

2:52So we basically go in and we audit and we get you complied, right, with those regulations. You know, but my biggest mission has always been teaching, right? Believe it or not, I do a lot of teaching, a lot of mentoring. I teach on CPA Academy for those that need to get their CEU credits. But I also teach my clients, right? I give them a lot of free resources because some of my clients and most of my clients, Josh, let's face it. A lot of small businesses don't have the resources. They don't have the IT departments. They don't have the infrastructure to get mandated and meet those mandates. It's very hard today in my world anyway and what I see out there.

3:34So I make it my mission one client at a time. I tell everybody one client at a time. No jargon. Let's talk. All right. So, Michelle, this is what people love to listen to podcast episodes like this about. We're recording this. We're kind of in the middle of 2026. What are the biggest headlines in your world as it relates to business owners and leaders who don't want to find themselves in cyber trouble? Um, obviously AI, uh, has the opportunity to empower, uh, folks that, um, you know, might not have some great, um, motivations, uh, to, uh, to, to, you know, they're just doing out there doing bad stuff.

4:24And so we have to stay ahead of the, uh, of the bad guys. So Michelle school us, what should we be concerned about? What should we be doing this year? Yeah, so a couple of the biggest focus is AI, right? The human in the loop element, we're seeing a lot of deep fakes. So that's really kind of the run of the mill right now. We're seeing a lot of what we call BDC attacks where they're doing email compromise. Those are kind of the largest. Phishing will always be out there. But the voiceovers, you know, all of that stuff that actually matters, where people can actually clone your voice today, clone your video just like this, and pretend like they're on a Zoom call with you and you don't even know and you're transferring 25 million, right?

5:06And it's happened. We're seeing those things. Breaches will always be an impact. We're seeing a lot of geopolitical stuff going on right now around the world, right, with the hackers and stuff. I know Striker was just hit not too long ago. So there are a lot of things that I see daily. I mean, I'm constantly ingesting that information. We like to teach people how to be resilient, right? Giving them simple three, two, one steps that they can take, things to protect themselves. I think that's very important. Education, education, education, right? I do a lot of web classes that are free to teach you.

5:41You know, once a week I'm on the web, you know, whatever, LinkedIn, YouTube. It's kind of simultaneously broadcasted to teach everybody. But, you know, it's important to understand where we're at in this world today. Right, Josh, it's critical. The news, I was just quoted in one of the cybersecurity journalist magazines, and we were talking about AI and the effects, right? And when you take a look at AI and the effects that it's going to have astronomically around the world, not only from a cybersecurity perspective, but a business perspective, right? I'll tell you that it's great to have, but you need somebody monitoring it.

6:22The pressure is, you know, everybody wants to use it. Everybody wants to enable these tools, but they don't understand exactly how it works. Even developers with 20 years experience are still struggling to understand how to manage it. Right. And especially in our world in cybersecurity, we know that the hackers are ahead of it. Throwing bots and hacking. So that's the reality of the world that we live in today. Michelle, I'm sure you come across some standard best practices that, you know, maybe you could offer to a room of business leaders. What are some things that you'd recommend? Maybe it has to do with just, you know, how we, you know, manage access to sensitive systems, passwords, you know, that sort of thing.

7:09What are maybe like two or three things that you'd say, listen, best practice, listen up. If you get this, don't ever do that. Like what advice would you give us on maybe some tactical things that we could do? Yeah, so let's talk about some best practices, right? Everybody has tools within what they use, like Office 365 or Google. You can turn on simple things to protect your phishing and your emails. I would tell everybody, look it up, go to ChatGPT and say, how do I turn these on? And they're free tools. They'll help you protect and add an added layer to your emails because most hacks come from emails, right?

7:44We know that. Right. And then there's the three, two, one. Anytime you're sending money, I tell everybody, data resiliency, you need to protect your money. If you're transferring money, doing wire transfers because wire fraud is big and fraud alone is big, you need to verify who you're sending that money to. Don't trust the email. Don't trust the instructions. Call them. Speak to them. They're even spoofing, right? So make sure that you're validating money transfers. I don't care how small or how large your organization is. I had a client not too long ago. They were able to compromise her email, and she sent an invoice to another client.

8:24Client paid her$40 ,000 to the hacker. She's out that money. So, again, understand what it is that you're up against. Geographic deactivation protocol. protecting your firms from your own distributed workforce by auditing endpoint vulnerabilities. I'll tell everybody that. Make sure that you have blocks on foreign addresses and that you have a monitoring system in place. Right. Those are critical. You know, and then you talk about the AI agentic, the human and the loop. I teach this human and the loop. Right. Yeah. Before. Yeah. You're talking specifically if you're running experiments with agentic AI.

9:05Yeah. I've I think by now, if you've been, you know, you follow AI news, you've probably heard some horror stories. What can go wrong there, Michelle? Well, you begin with a laugh. Love it. Oh, boy. Listen, I've seen a lot of creative things with, you know, without the human in the loop, right? And I think we just hit one of them. One of the biggest things that we just saw that came out last year, right? It was payroll. Someone pretended to join a Zoom meeting. It was all deep faked people, right? There were nobody real. It was all AI personas that looked like the real people because again, they can clone your image.

9:47They were all on this call and this guy got the approval supposedly from the CEO that was on this call to transfer 25 million in payroll and he did it. He did it willingly. Okay. So, you know, there are different things when you're looking at human and the element and And I teach this AI. If you want to watch the mouth, you want to watch the eyes. You want to listen to the tone because it's flat. Right. The eyes. If you tell it, tell somebody turn to the left. Can you look over there? Or like, you know, pretend like it threw something because it'll glitch. You want to watch because, again, it's happening.

10:22We know that this is not something new. It's just more advanced. Now you have things like Eleven Labs and all these great. used for good, but unfortunately the bad people use them for bad. And they figured that out. So again, Newman and the element, don't be afraid to ask. Don't be afraid to call them on the phone, use external channels, Slack channels, things like that to communicate. And again, verify when it comes to money, I will say this and I teach all my clients. I don't care. You pick up that phone and say, hey, I just sent you the invoice. Did you get it? And verify with me what the account number you have.

11:02Verify. Because again, BEC is real. It's happening over and over. Ransomware will always be around. I mean, it's unfortunate. You're not going to get away with that. But I think cryptographic changes are coming over the next three to six, three years, I would say. That's really going to change that. That's really going to help prevent how those keys are viewed and everything, and really will probably eliminate some of this ransomware stuff that we see today. I mean, you have to forget, you've got quantum computing coming, right? It's already being - Oh my gosh, I can't even imagine. We've already got the COBM that came out this past year.

11:43Everybody's larger enterprises will have to really take a deep look at the cost that it's gonna cost them to transition these legacy systems to get compliant. And that's gonna be critical. You know, so we have a lot of things going on out there. But those were my - Yeah, we do. I hope I answered your question. Oh, and then some, Michelle. How do you work with people? And, you know, what are the services? What does it look like when folks are engaging with you? Yeah, so my services, again, are to understand their cybersecurity posture. I help them build a baseline compliance platform. So I go in there and I identify where they're at.

12:20I ask them a lot of deep questions about how their businesses run, what they currently do, what they don't do. I do kind of an assessment, a gap analysis with them, but I really get to know them. What's their pain point? Because that's really what matters. At the end of the day, nobody cares about anything. They want you to solve a problem for them, right? We help small businesses understand how to comply with those rules and regulations. That's what I do day in and day out. And I teach them what they can do, right? So they can set themselves up for success. It's very critical that they understand what they're up against.

12:52And, you know, I get a lot of ahas. There are a lot of things that are out there that unfortunately, again, most of my clients are not aware of. And even if they have internal teams, they think somebody else is taking care of it. You know, yeah, one of the pitfalls I see all the time is, you know, they've hired that external MSP or that external vendor thinking they're monitoring their systems and they're going to catch everything. It doesn't work that way. Right. And they don't know any better. And they're paying for these services, but they don't get them compliant. They're not giving them the documentation, the audit trails, and everything else that they need, that if an auditor walks in, whether it's the IRS, FTC, the state, whatever it is, that they need to prove that they're compliant.

13:33And they're no longer just having it on paper. They're governing it, right? That's the critical. And that's what I teach them. It's not about having MFA anymore. It's about having it tested. Is everybody on your team have it? Have you implemented training on it? So there are a lot of elements that we do. And again, I've always, my mission, teach one client. That's it. Yeah, I mean, it's tough. If you've got, even if you just have a few dozen folks on the team, contractors and so forth, you might be wildly attentive to best practice for security. But that doesn't mean that everybody on the team is.

14:15And, you know, I heard that, you know, that's usually your biggest vulnerability is your people and, you know, kind of the decisions that they make. And so, well, Michelle, your website, which we have all linked up, is cardinalsbytes.com. So a friend can kind of click and see what you have to offer here. And you do a risk assessment review. What do you do on that call? Yeah, so there's two parts. When you're going into a client, there's two parts of that. by law, you have to ask a series of questions that align with all types of frameworks. I use NIST, right? That's the standard framework that we use to test the client to see where they stand.

14:55There's about 90 questions that we ask them, right? To identify their element and their gaps within their policies, their procedures, and how they handle things within their element. The second part of that is we go in and we do an actual testing of their systems and their ecosystem. All of their systems are tested. We run some beautiful programs that kind of give us a divulge of everything. If there's vulnerabilities there, if there's possible what we call IOCs, I'll keep it very simple, incident compromises. And then we take a roadmap of that. So that's the first element. Once we understand how they handle things and what their systems look like, their ecosystem, then we put that all together in a nice, beautiful report for them, bolded executive summary.

15:37and we start outlining all the things that we need to remediate. We build off of that over the next one to five years, obviously hitting the priorities of critical, right? If there are things there that, you know, I've found plenty of things, right? You know, I've found breaches. We deal with a lot, right, Josh? It's not just a one and go, you know. You never know when you're going in and you're testing a company's system what you're going to find, right? If it's just configuration problems, we fix those. If it's something that looks like something was breached or ex-expetrated, then, you know, we get our forensic partners involved.

16:14If they have cyber insurance, they have to go to cyber insurance, report it as a duty to report, and then they take over. So, you know, those things have to be looked at. And then you follow the protocols. So we walk them through that. But the next step after that is I create their WISP, which is their written incident security plan, which they're all required to have now. Right. And then we work with them on creating their IRP plan or incident response. So if they do have a breach, what are the steps they take? Who do they notify? How do they eradicate? How do they get back up running? All of their, you know, MTTR time, all of that good stuff, right?

16:49That's kind of what we do. Again, we're compliant. We provide them with all the documentation to support this, the audit logs, their trails, everything. So I know it's a lot, but we do everything. you know it's just like the it guys sitting up your router yeah we look at your router to see if it's configured right yeah you know it's just like you know i'm thinking you know just you know regard you know it's like terror attacks you know they only have to be right once um you know and it can potentially put a company out of business everything you've worked for you know your whole life or you know everything you've put into it um you know you you can end up with some really really messy problems that could put all that in jeopardy.

17:30It's an ounce of prevention. Michelle Novak, again, your website, cardinalsbites.com. We've got that all linked up in the show notes for this episode. It's been a great conversation, Michelle. Thank you so much for being one of the good guys. All right. Now let's both look left and right. Yeah. Okay. All right. We're not AI. Thank you, Michelle, for this great conversation. You're welcome. Thank you.

17:59Thanks for listening to The Thoughtful Entrepreneur. If your goal is to grow your business, increase revenue, and build authority without gimmicks, this show is designed for you. Each episode gives you practical insight from leaders who have turned trust and credibility into real business results. If you value short, thoughtful conversations that respect your time, make sure you're subscribed. We publish daily 15-minute episodes focused on growth that actually compounds. And if you're interested in being a guest or you want to turn podcast appearances into measurable business growth, visit podverified.com.

18:35You can start for free with your podverified score, along with free podcast guest training and a free media kit builder. These tools are built to help you get booked on better shows, deliver stronger interviews, and convert audience trust into revenue. No more desperate sales. You truly can enjoy all the business you like by generously sharing your wisdom. Everything we offer is built by podcasters for guests with a focus on trust, organic growth, and long-term business success. Thanks again for spending your time with us. I'll see you next time.

From the publisher
The AI-Driven Threat Matrix: Architectural Cybersecurity and Compliance for Small Firms with Michele Novack

In a recent episode of The Thoughtful Entrepreneur Podcast, host Josh Elledge sat down with Michele Novack, the host and founder of Cardinalsbyte, to break down the rapidly evolving cyber vulnerabilities that threaten the financial solvency of small businesses. As a veteran risk strategist specializing in the financial services sector, Michele highlights how CPAs, accountants, and tax professionals have become prime targets for sophisticated, automated digital attacks. This conversation delivers an intentional operational roadmap for mid-market founders and executive teams looking to navigate tightening federal mandates, identify hidden security gaps within their existing infrastructure, and defend their enterprise value against highly advanced, AI-powered corporate fraud.

The Anatomy of Digital Defense: Mitigating Algorithmic Vulnerabilities through Zero-Trust Protocols

The rapid proliferation of consumer-facing artificial intelligence has weaponized the digital threat landscape, enabling bad actors to execute automated, hyper-personalized social engineering campaigns at an unprecedented scale. Michele Novack cautions that small businesses can no longer rely on traditional, passive firewall defenses as cybercriminals increasingly deploy sophisticated voice cloning, automated phishing sequences, and deepfake video streams to bypass conventional security guardrails. A single compromised corporate email account can result in catastrophic financial loss, as demonstrated by emerging corporate wire fraud schemes where payroll managers are manipulated by synthetic, AI-generated replicas of their CEO during live video conferences. To counter this automated disruption, executive leadership must enforce rigid, non-negotiable zero-trust verification protocols—requiring multi-channel, manual confirmation for all financial movements and high-stakes data extractions completely independent of digital messaging networks.

Insulating a firm against regulatory penalties and liability requires a disciplined commitment to formalizing internal data compliance programs rather than treating security as an ad-hoc IT checklist. Tightening federal mandates, such as the revised FTC Safeguards Rule and IRS security guidelines, now legally obligate financial services providers to maintain comprehensive, written documentation detailing their operational defenses. Many business owners operate under the dangerous assumption that their external Managed Service Provider (MSP) inherently handles regulatory compliance, leaving the enterprise exposed to massive liability gaps due to a complete lack of formal Written Information Security Programs (WISPs) and documented Incident Response Plans (IRPs). True enterprise resilience is achieved when leadership takes proactive ownership of corporate compliance, closing security gaps by performing routine endpoint audits, implementing geographical IP blocking, and maximizing the advanced, built-in security features native to enterprise cloud suites like Microsoft 365 or Google Workspace.

Transforming an organization's digital posture ultimately relies on establishing a transparent, security-first corporate culture that bridges the gap between complex technical tools and human operational habits. Because human manipulation remains the primary vector for enterprise data breaches, continuous, jargon-free employee training is a vital piece of operational infrastructure. Rather than deploying clinical, one-and-done IT lectures that fail to change day-to-day employee behavior, founders must implement continuous, interactive education loops and safe phishing simulations that sharpen frontline skepticism. When clear behavioral habits, automated endpoint monitoring, and verified compliance documentation are synthesized under a unified governance architecture, a business successfully limits its operational risk. This proactive stance converts cybersecurity from a costly technical burden into a powerful, high-valuation corporate asset that fiercely protects the organization's market authority.

About Michele Novack

Michele Novack is the host, founder, and chief risk strategist of Cardinalsbyte, and a premier authority on small business data security and financial compliance management. Drawing from decades of specialized experience within the financial services and accounting sectors, Michele focuses on demystifying complex technical architecture to make regulatory frameworks accessible for corporate executives. She is a dedicated educator and advisor who specializes in constructing high-accountability cyber defense models designed to protect small-to-mid-sized enterprises from advanced electronic corporate theft.

About Cardinalsbyte

Cardinalsbyte is an elite risk management and cybersecurity compliance consultancy that provides custom data-protection solutions, vulnerability assessments, and regulatory mapping for professional services firms. The company specializes in translating complex federal guidelines, such as NIST frameworks and IRS mandates, into actionable corporate playbooks including Written Information Security Programs (WISPs). Through proactive technical testing, executive risk summaries, and white-glove incident response coordination, Cardinalsbyte enables mid-market organizations to eliminate administrative security debt and shield their bottom lines from systemic digital threats.

Links Mentioned in This Episode


Key Episode Highlights

  • The AI Weaponization Trap: Analyzing how deepfakes, automated voice cloning, and synthetic media bypass traditional corporate communication filters to enable catastrophic wire fraud.
  • The MSP Compliance Gap: Understanding why standard IT vendors fail to provide mandatory regulatory documentation, and how to self-correct using structured WISPs.
  • Maximizing Built-In Cloud Security: Leveraging and configuring the advanced, pre-existing anti-phishing dashboards embedded within Microsoft 365 and Google Workspace.
  • The Multi-Channel Verification Mandate: Implementing mandatory human-in-the-loop protocols that require dual physical authorization for high-volume financial movements.
  • Building a Skeptical Corporate Culture: Shifting internal security training from a static annual checklist into continuous, interactive education that reduces human error on the frontline.

Conclusion

The conversation with Michele Novack underscores that true cybersecurity resilience is an ongoing exercise in structural governance and human vigilance rather than an expensive software purchase. By standardizing internal corporate compliance, executing rigorous endpoint audits, and building an inclusive culture of behavioral accountability, business leaders can transform a vulnerable digital setup into a highly secure, enterprise-grade corporate asset.

More from The Thoughtful Entrepreneur

🎙️ Want to be featured on The Thoughtful Entrepreneur? Get your voice in front of 50K+ listeners. 👉 Schedule your guest spot here »

🤝 Consultant doing 6+ figures? Let’s introduce you to your next big client, partner, or referral source. 👉 See how here »

📡 Thinking of launching your own podcast? We’ve built over 250 shows for leaders who land dream guests weekly. 👉 See the system here »

🚨 What’s Your PodVerified Score? Find out how you rank as a podcast guest — and get matched with hosts who actually want you. 👉 View the platform »

📬 Subscribe to The Thoughtful Entrepreneur New episodes daily to fuel your impact, visibility, and influence. Thanks for listening — now go build something extraordinary!

To discover more strategies for scaling your impact and growing your authority, explore the resources available at UpMyInfluence.com. If you are a founder or executive with a story to share, we’d love to hear from you—click here to apply as a guest on The Thoughtful Entrepreneur Podcast!

More from The Thoughtful Entrepreneur

All 987 episodes
2443 - What Every Accountant Needs to Know About Cybersecurity Compliance in the Age of AI with CardinalsByte's Michele NovackThe Thoughtful Entrepreneur · 19 min
Listen in VO