The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups@SmallBizCyberGuyMain

0 followers
Follow

Season 2 episodes (20)

Birthday Audit: Brutal Lessons for Small Business Cybersecurity
S02:E24

Birthday Audit: Brutal Lessons for Small Business Cybersecurity

Noel Bradford and Mauven MacLeod mark the first anniversary of The Small Business Cyber Security Guy by doing what they ask of small businesses: an honest review. No self-congratulation, no marketing gloss. Instead, the hosts correct the mistakes that mattered, including overuse of misleading breach statistics, presenting multi-factor authentication as a finish line rather than a foundation, and underestimating the practical friction of supplier conversations. They revisit the year's core messages that held up under scrutiny: cyber security is a business problem, not just an IT task; backups are only meaningful if they have been tested; and certificates are not controls. Graham Falkner, Lucy Harper, and Corrine Jefferson each share what surprised them most during the year, touching on logging discipline, accountability gaps after breaches, and the increasing speed of identity-driven attacks. The episode closes with a clear-eyed look at what remains broken, including weak accountability structures, the persistent myth that small businesses are too small to target, and the widespread failure to test recovery processes. Listeners receive three practical actions for the week: test a file restore, strengthen MFA on privileged accounts, and disable old user logins. The hosts also introduce two new daily shows joining the SBCSG network in year two. The Daily Time Drop - https://open.spotify.com/show/033t7F4gTRfns0waaq7kHR?si=d859cf22a62f4f8f UK Government - https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024 National Cyber Security Centre - https://www.ncsc.gov.uk/collection/phishing-resistant-authentication  

If Your MSP Says ‘All Good’, Can They Prove It?
S02:E23

If Your MSP Says ‘All Good’, Can They Prove It?

It starts with a slow ticket, a missing laptop and a printer staging yet another tiny rebellion — the kind of problems every small business sees and understands. But behind those visible slips is a quieter, far more dangerous story: patches that didn’t run, MFA that wasn’t enforced, backups that wouldn’t restore. In this episode Noel Bradford and a panel of experts follow a simple, devastating question: if your MSP says everything is fine, what can they actually prove? Through a sharp, practical conversation with Mit Patel, founder of Assurix, we peel back the sales decks and the polite reassurances to show how “managed IT” can mean very different things. Mit explains the difference between promises and live evidence — not certificates from three years ago, but ongoing proof that patching, EDR, backups and identity controls are working over time. Graham brings the arithmetic that spoils the cheap quote, Corinne maps the attacker’s path, and Lucy explores the trust problem buyers face when asked to pick a provider with almost no usable evidence. Listeners are walked through the exact questions every business owner can ask without becoming a security expert: show me 90 days of patching and backup evidence; show me MFA enforcement and exceptions; explain your offboarding process and its real cost; who owns proactive maintenance and how much time do they spend on it? We hear why continuous assurance matters for cyber insurance and why a green report on one day isn’t the same as discipline over months. The episode doesn't preach panic — it prescribes better questions and better accountability. You’ll hear concrete examples of what good looks like: enforced MFA, tested backups, measurable patch compliance, named escalation paths, fair offboarding and evidence dashboards a human can understand. And if your MSP can’t show that evidence, the episode explains why price comparisons alone are dangerous and how under-resourced security becomes a real business risk. By the end you’ll understand the simple premise that guides the discussion: service is visible, security is invisible — until it fails. This episode arms small business leaders with a narrative and a checklist to turn vague reassurances into verifiable proof, and gives good MSPs a roadmap to show their value beyond the lowest price. Ask for evidence, not a fleece and a smile.

The 75¢ Clue: How a Tiny Billing Error Unmasked a Cold War Hacker
S02:E20

The 75¢ Clue: How a Tiny Billing Error Unmasked a Cold War Hacker

It begins simply: a worn hardback on a bookshelf, a black marker on the title page, and a 75-cent discrepancy in a lab bill. What sounds like a footnote in an accounting ledger becomes the hook of a detective story—one where curiosity, persistence, and a refusal to write off tiny anomalies expose an international spy ring. We pull you back to the mid-1980s at Lawrence Berkeley Lab, where phones, modems and shared terminals hum with a world before always-on internet. Cliff Stoll, a meticulous sysadmin, refuses to accept that the accounts are merely off. He unspools the ledger, reads the logs, and follows the faint, odd patterns of someone who shouldn’t be there: late-night dial-ins, strange commands, connections that don’t fit any researcher’s schedule. Stoll’s investigation reads like a thriller. He turns on exhaustive session logging, builds a crude beeper to alert him at home when the intruder connects, and—most audacious of all—keeps the intruder online just long enough for telephone engineers to trace the call. Printouts, persistence, and partnerships with the phone company slowly stitch together a trail that crosses oceans and points to a hacker in West Germany. From a paltry billing error to a Cold War espionage case, the narrative is both dramatic and instructive. Marcus Hess’s activities reveal how small anomalies can be the first sign of serious compromise, and how careful evidence collection and dogged investigation can turn a minor puzzle into a breakthrough. But this episode is not only history; it is a manual in disguise for the small-business owner in 2026. We translate Stoll’s playbook into modern terms: enable and retain logs, set simple alerts (the digital beeper), preserve evidence, work with your ISP and cloud providers, and resist the urge to “tidy up” an incident before it’s understood. The tools have changed, but the mindset hasn’t—curiosity, stubbornness, and methodical recording win more often than brilliant firewalls alone. Throughout the episode Noel Bradford, Graham Falkner and Maurven McLeod blend storytelling with hands-on advice—how long to keep sign-in records, what to do when you spot a 3am login from another country, and the small, affordable controls that make a huge difference. You’ll hear the thrill of discovery, the slow build of a trace, and the simple takeaways any small team can implement tomorrow. By the end, the story is both a cautionary tale and an invitation: treat the little things seriously, cultivate a culture that rewards curiosity, and remember that a tiny anomaly can save you from a catastrophe. If a 75-cent error once outed a spy, imagine what noticing the £1 blip on your SaaS invoice could save you. Tune in, be curious, and mind your logs.

The £10k False Economy: When Cheap IT Becomes Your Biggest Liability
S02:E18

The £10k False Economy: When Cheap IT Becomes Your Biggest Liability

It starts with a tempting spreadsheet: 25 staff, a cheaper IT quote that shaves £35 per user off the bill — £10,500 a year saved, instantly seductive. Noel Bradford and Mauven McLeod open this episode by turning that neat number upside down and asking the one question every business owner should be able to answer: what exactly has been removed from the service to make that price possible? They walk you through a story many business owners will recognise — a colourful LinkedIn pitch that sells confidence and hides compromises. The cheap provider isn’t performing miracles; they’re quietly cutting controls: enforced MFA, disciplined patching, active monitoring, behaviour-based endpoint defence, security training, incident response and documented processes. Those missing pieces turn an attractive short-term saving into a long-term gamble. Noel and Mauven do the arithmetic and show you the cold UK data: the DCIT survey found 43% of UK businesses suffered an incident in 2024, phishing hit 85% and even a 1% ransomware prevalence still means roughly 19,000 organisations were devastated. The average materially costly breach ran to about £8,260 in 2025 — already eclipsing that supposed annual IT saving — and real-world downtime, lost orders and reputational damage can push costs far higher. They then lift the curtain on what a security-first MSP actually spends on the plumbing: remote monitoring, EDR, DNS filtering, email protection, application control, backups, SOC monitoring, documentation and professional tooling. Strip it down honestly and the true cost lands well above fantasy bargains — industry reality makes anything under roughly £50 per user per month alarming, and in London nearer £75. Cyber insurance isn’t a free pass. Uptake has risen, but so have denials: missing MFA, poor patch evidence, misrepresented controls and late reporting regularly void claims. Insurers now demand proof — logs, timestamps and documented processes — and bargain providers rarely collect or produce that evidence. The result: a denied claim when you most need a payout. Ransomware is the horror story that pulls everything together. Usually seeded through phishing and unpatched systems, ransom incidents produce recovery costs that dwarf the payment demand. Noel and Mova explain why the ransom is only the opening act — downtime, forensics, legal costs, client fallout and reconstruction push many small firms to the brink. Regulators make the stakes worse. ICO fines and tougher technical expectations mean that skimping on controls isn’t just reckless, it can be an aggravating factor in enforcement. The cheapest IT quote won’t be an excuse in front of a regulator or in the aftermath of a client data breach. The episode ends with practical, plain-English advice: seven questions every business should ask their provider about certification, enforced MFA, patching, EDR, proactive monitoring, incident response and insurance compliance. The message is simple — don’t buy the smallest number on a spreadsheet without understanding what you’ve agreed to carry. Spend wisely, not blindly.

Cyber UK 2026: The Front Line Arrives — What Small Businesses Must Do Now
S02:E17

Cyber UK 2026: The Front Line Arrives — What Small Businesses Must Do Now

When a government minister stood on a podium in Glasgow and said, “the cyber front line is already here,” it did not sound like a warning. It sounded like a cold, unavoidable truth. In this episode, Noel Bradford is joined by Maurven and Graham, who attended Cyber UK 2026, to unpack what was said, what was left unsaid, and what it means for the small businesses quietly sitting inside UK supply chains. The scale of the threat is no longer theoretical. Nationally significant cyber incidents are rising sharply. A single breach at Jaguar Land Rover reportedly cost nearly £2 billion across its supplier network. Nation state actors and ruthless criminal gangs are attacking faster, harder, and with greater precision. The old excuse of “we are too small to be targeted” is now dangerously out of date. Noel, Maurven, and Graham break down the numbers, the reaction in the Glasgow conference hall, and the blunt reality behind the headlines. Government pledges may change the landscape, but they will not protect your business unless you act. The episode also examines the government’s voluntary Cyber Resilience Pledge and why it matters. The most important part may be the supply chain effect. Large organisations that sign the pledge could start expecting their suppliers to hold Cyber Essentials certification. That may make Cyber Essentials a practical requirement for winning and keeping business, even if it is not yet written into law. The team also explains why the £90 million funding commitment matters, but why small firms should not expect a sudden cash windfall. The immediate pressure will come from reputation, procurement, and customer expectations, not regulation. There is also a reality check on AI. Powerful new models can now find deep, old vulnerabilities in hours. That gives attackers more speed and scale. But for most small businesses, the answer is not a six figure AI security platform. It is getting the basics right, faster. Patch properly. Check whether your IT provider is ready for machine speed attacks. Start Cyber Essentials. Review AI use inside your business. Sign up to NCSC Early Warning. By the end of the episode, you will have five practical, low cost actions you can take this week to move from passive hope to active defence. If your business relies on larger customers, this episode gives you the timeline, the threat picture, and the checklist you need before the next procurement email lands.

"It's Not DNS" — Until It Is: The Office Mystery That Always Blames the Translator
S02:E16

"It's Not DNS" — Until It Is: The Office Mystery That Always Blames the Translator

Every office has that moment: the site won’t load, someone whispers “DNS,” and immediately half the room turns into a jury with opinions but no evidence. In this episode of Small Business Cybersecurity Guy, Noel Bradford, Mauven MacLeod, Lucy Harper and Graham Falkner turn that reflexive blame into a story—part detective work, part practical guide—about why DNS so often gets accused, what really breaks, and how to stop losing hours to assumptions.

When Your Cyber Insurance Says 'No': How One Form Field Can Cost You Millions
S02:E15

When Your Cyber Insurance Says 'No': How One Form Field Can Cost You Millions

What if you did everything right — paid the premiums, bought the policy — and on breach day they simply said, "nope"? This episode opens with that cold shock: a tiny answer on a form you filled 18 months ago about MFA, a quiet clause about state-backed operations, and suddenly a million-pound disaster is met with silence. I'm Mauven McLeod, joined by Noel Bradford and the velvet tonsils of Graham Faulkner, and we walk you into the room where insurers, forensics and legal tests meet your reality. We tell the story through the eyes of small business owners — the manufacturer in Leeds, the dental practice in Cardiff — who thought they had done the right thing. You hear the panic calls, the blame-shifting over who completed the proposal form, and the slow, meticulous forensic process that turns your answers into evidence. This is not a lecture; it's a play-by-play of how a policy transforms from protection into an argument when paperwork and proof diverge. Along the way we unpack the legal scaffolding that makes insurers act this way: the Insurance Act 2015 and the duty of fair presentation, the three flavours of misrepresentation (innocent, negligent, reckless), and why a single "yes" about multi-factor authentication can become Exhibit A in a claim dispute. We bring to life the tension between good intentions and hard evidence, and why the regulator expects a real connection between the breach and any policy condition. We get technical without losing the plot. MFA becomes the episode's poster child; backups, patching, supported software and default admin accounts follow. You hear real examples of partial deployments, legacy carve-outs, and the kind of sloppy patching that turns an insurer's willingness to pay into a months-long negotiation. We explain how forensic teams reconstruct your environment and why the proposal form is no longer just a quote-getter — it's the baseline against which you will be judged. Then we raise the stakes: Lloyd's model clauses and the state-backed cyber exclusion that can turn collateral damage from a global campaign into a denied claim. Attribution is messy, the wording can be sweeping, and even a small business can find itself arguing with the market if a headline-grabbing attack drags them into a wider campaign. But this is a practical show as much as a cautionary tale. We hand you a pre-breach checklist you can act on this week: pull your proposal and policy, run a line-by-line reality check, harden MFA, tidy backups and patching, document tests and keep the proof. We explain what to do in the first 24–72 hours of a live incident — contain, preserve evidence, call the insurer or hotline, avoid freelance ransom payments, and keep a simple incident log that becomes priceless later. By the time we close, you'll understand the ugly truth and the hopeful fix: cyber insurance can save your business, but only if you treat it as a living contract that matches the reality of your IT. This episode is a roadmap and a warning: prepare a little now, keep the evidence, ask awkward questions about your insurance, and you hugely increase the chance you get the support you paid for when it matters most.

Digital Sour Milk: When Your Tech's 'Still Turns On' is a GDPR Time Bomb
S02:E14

Digital Sour Milk: When Your Tech's 'Still Turns On' is a GDPR Time Bomb

Imagine opening the office fridge and finding a cloudy, unlabeled bottle of milk. You wouldn’t drink it — so why are businesses still running tills, routers and servers on ancient, unsupported software? In this episode Graham, Noel, Lucy and Mauven turn the mic onto the maddening normality of ‘mystery’ machines: the Windows XP till behind the counter, the router older than your youngest employee, the dusty NAS holding the only copy of customer data. With equal parts humour and hard sense, they map food-safety instincts — ‘use by’, ‘best before’, the sniff test — onto the tech that keeps small businesses running. Through real-world stories (from cafes and dental practices to corner shops and manufacturers) the hosts show how ‘still turns on’ is not the same as ‘still secure’. End-of-life and end-of-support dates are the invisible expiry stickers businesses ignore at their peril: when security updates stop, so does your defence. Graeme lays out pragmatic steps for a no-nonsense tech audit — list devices, note what they do, check support windows, then slap “used by” or “best before” labels on the kit that matters. For anything internet-facing, handling payments, or storing sensitive data, the rule is simple: if it’s out of support, replace it. For unavoidable legacy kit, segment it, lock it down, and plan its retirement. Practical, urgent and often funny, this episode is a wake-up call for anyone running a small business: don’t let your tech go off the rails just because the lights still come on. Follow the simple 30-minute ‘milk check’ homework, colour-code your inventory by risk, and commit to one concrete fix this month — whether that’s replacing a router, budgeting for a refresh, or scheduling an audit. Share the episode with that friend still running a mystery Windows box. Your customers — and the regulator — will thank you.

When Confidence Becomes the Vulnerability: How Ego Opens the Door to Breaches
S02:E12

When Confidence Becomes the Vulnerability: How Ego Opens the Door to Breaches

Tonight’s episode opens in an empty studio, a fridge with two bottles of Prosecco and a conspicuously absent Noel — the perfect stage for a conversation that is equal parts wry and urgent. Three hosts trade jokes and a refill, but the real story soon emerges: many cyber disasters don’t begin with cinematic black‑hat brilliance. They begin with everyday confidence, with the quiet sentence, “We’ll revisit that next quarter.” We tell the story through small, human scenes: Davina from IT documenting a firewall hole and being ignored; a busy owner insisting the dashboards look fine; staff pasting customer notes into an AI co‑pilot because it saves time. Those moments feel ordinary, even sensible. But together they create an irresistible path for attackers — unpatched servers, excessive permissions, reused credentials, and shadow SaaS tools that no one thought to approve. The breach that looks sophisticated in a post‑incident writeup often starts with a password used in the wrong place, or a medium finding waved away until it can be chained with others. We push back against comforting myths: that a tool equals a process, that your business is too unique to be targeted, or that a theoretical finding can safely wait. Instead, we reframe humility as a security control — a practical habit of updating your view when evidence changes, surfacing awkward truths quickly, and learning without scapegoating. Psychological safety isn’t a workshop buzzword here; it’s the difference between catching a problem early and making headlines. The episode then moves into practical, bite‑size remedies you can use this week. Start by asking: what have we delayed because it’s inconvenient? who has more access than they need? what unsanctioned tools or AI are people using? and where do people raise concerns, and what happens when they do? Make a stop‑doing list: pick one convenience‑led risk and fix or formalize it. Give staff a boring, reliable route to flag risks — a 10‑minute slot in an ops call, a simple shared list, or a no‑blame MSP review — and reward the person who brings bad news early. We finish with a quiet but powerful leadership practice: say out loud, “I might be wrong.” That sentence flips the dynamic. It turns performative certainty into honest curiosity, shrinks blast radius by encouraging early action, and makes resilience a habit rather than a purchase order. No giant security teams required — just cleaner permissions, timely patches, governed AI use, and the grit to listen when someone like Davina says, calmly, that something is off. By the end of the episode the mood is hopeful. The hosts have had their Prosecco, given practical checklists, and reminded listeners that strong organizations don’t sound the most certain — they admit uncertainty early, correct course quickly, and make space for truth before convenience becomes a liability.

Don’t Buy the Badge: The Real SMB 1001 Guide for UK Small Businesses
S02:E11

Don’t Buy the Badge: The Real SMB 1001 Guide for UK Small Businesses

Do small businesses really need another cyber security badge? In this episode, Noel Bradford, Mauven MacLeod and Graham Falkner dig into SMB 1001, a five tier cyber security standard aimed at small and medium sized businesses. They break down what the bronze, silver, gold, platinum and diamond levels actually mean, where the framework came from, and whether it has any real value for UK firms. The team also looks at how SMB 1001 compares with Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance and ISO 27001. More importantly, they ask the question many business owners should be asking already. Do you need another logo for the website, or do you need security controls that actually work? Expect plain English, practical analysis, and a healthy level of scepticism about cyber theatre, vanity certifications and providers who still cannot get clients to the basics. In this episode What SMB 1001 is and who it is for How the five certification levels work Why it is not a replacement for Cyber Essentials in the UK Where it aligns with good practice and where it does not Which level is realistic for most UK SMEs Why good security matters more than collecting badges Why listen? If you run a UK small business, buy IT support, fill in supplier questionnaires, or keep hearing about standards and certifications, this episode will help you cut through the noise. What should you actually focus on first? And what is just expensive reassurance dressed up as strategy?

Willow vs Danzel — Navigating Cyber Essentials V3.3 Before the Deadline
S02:E10

Willow vs Danzel — Navigating Cyber Essentials V3.3 Before the Deadline

Imagine your website is a billboard: a shining Cyber Essentials badge promising security and trust. Now imagine a regulator, insurer or large customer asks one awkward question — and that glossy logo turns from an asset into potential evidence against you. In this episode we walk into that exact moment and refuse to let it be a surprise. Join Graham Falkner, Noel Bradford and our resident translator of tech, Lucy Harper as they pull apart the new Cyber Essentials changes and stitch the pieces back together into something a small business can actually use. We start with the simple truth: the requirements document (V3.2, V3.3 and whatever comes next) is the standard you must meet, and the Willow and Danzel question sets are the forms you fill in when you buy certification. Get the wrong combination, or try to recycle last year’s answers, and assessors will fail you — quietly at first, then painfully when a tender or a claim comes along. From there we map the conflict: scope, cloud and asset management. V3.3 pulls the rug on the old ‘that’s someone else’s problem’ attitude — cloud services, BYOD devices that touch organisational data, and remote workers are in the frame. If your asset list is a half-dead spreadsheet and some post-it notes, you cannot honestly answer whether you are compliant. The drama here is avoidable, but only if you stop pretending the messy bits aren’t part of your estate. We decode the five controls — firewalls, secure configuration, security update management, user access control and malware protection — and translate them into Monday-morning tasks: lock down admin interfaces, remove default accounts, document inbound firewall rules, treat vendor configuration changes as security fixes, and make sure anti-malware actually blocks things rather than sitting in the tray. Authentication gets a starring role. V3.3 clarifies passwordless (hello FIDO2 and passkeys) and treats modern approaches as valid multi-factor methods. SMS is grudgingly still acceptable, but it’s the floor, not the ceiling. If your tenant runs on Microsoft 365 or Google Workspace, we give concrete examples of what ‘good enough’ looks like for normal users and admins. We don’t stop at problems — we hand you a plan. Nail your scope and inventory; map assets to the five controls; enable MFA everywhere; clean up admin accounts; ensure critical vendor fixes are applied within the 14‑day window; and prepare evidence in a spreadsheet before you pay for the portal. Treat certification as a living process, not a sticker you won once. For the procrastinators, we lay out a rapid action plan: days 1–10 define scope and update your asset list; days 11–30 enable MFA, tidy accounts and prove you can hit 14‑day patches; days 31–60 tighten firewall rules, confirm anti-malware and run a dry self-assessment against Willow or Danzel depending on your purchase date. This episode is equal parts wake-up call and field guide — built for business owners who don’t have a security department but do have customers, contracts and reputations to protect. Listen for the practical checklist, the red flags that bite in tenders and post-breach enquiries, and the honest reassurance that Cyber Essentials will help you — if you stop gaming the edges and start being truthful about what you actually run. By the end you’ll either feel the pressure to act or you’ll be able to explain your scope in 30 seconds. Either way, we give you the first steps: patch your systems, turn on MFA, and stop pretending the cloud is somebody else’s problem.

Three and a Half Pence: The Currys Breach That Took Nine Years to Matter
S02:E08

Three and a Half Pence: The Currys Breach That Took Nine Years to Matter

Picture yourself tapping your card at a bustling store, the till chirps, you walk away thinking that’s the end of the story. For millions of Currys' customers, that ordinary moment in 2017 was the opening scene of a nearly decade-long drama that would ripple through courtrooms, regulator offices and countless inboxes. This episode unpeels that story — malware on thousands of point-of-sale terminals, 14 million people exposed, and a legal fight that turned a monumental failure into what worked out as roughly three and a half pence per person under the old law. We set the scene as a crime thriller: silent malware skimming payment data across 5,390 tills for nine months, basic security absent where it mattered most, and a regulator reaching for the only enforcement tool it had under an older statute. Then the plot thickens. DSG fights back, tribunals slice and dice the ICO’s case, and years of appeals stretch this into a slow-motion moral fable about who the system really protects. But this isn’t just legal theatre — it’s human fallout. We follow the people on the receiving end: anxious customers, stalled group claims, and a lone litigant whose attempt at compensation is bounced between courts and stays. By the time the Court of Appeal finally says the obvious — a retailer that can link card numbers to people must treat them as personal data — most victims are already out of time to sue. The episode shows how the machinery of justice can leave ordinary people stranded. Alongside the outrage, we pull apart the courtroom arguments that nearly let a multinational off the hook: the dangerous idea of judging identifiability from a hacker’s viewpoint, and the peril of treating data fragments as harmless. The Court of Appeal’s eventual clarity is legally important, but the delay exposes a chilling truth — if you’ve got deep pockets, you can litigate and wait out consequences while victims go uncompensated. This is also a playbook episode for anyone who runs a small or mid-sized business. We translate the Court of Appeal’s ruling into a simple controller’s-eye test you can run on Monday morning: if you, as the organisation, can link data to a person, it’s personal and worth protecting. From that test we give concrete, low-cost actions: map your data, cut unnecessary access, name who watches your logs, patch and MFA the essentials, and keep a one-page accountability pack that proves you took reasonable steps. We don’t just point fingers — we hand you a route out. The Currys' saga becomes the cautionary tale that makes the normal business case for basics suddenly urgent: monitoring that notices intrusions, access reviews that kill zombie accounts, and documentation that shows you’re not winging it. Do these things and you move from case study risk to trusted steward of customer data. Finally, the episode is a story of how law, business and people collide — a vivid reminder that prevention matters more than litigation, and that the protections for customers are only as strong as the choices organisations make before the breach. Tune in to feel the outrage, understand the legal twists, and walk away with practical steps to stop your business from becoming headline fodder nine years from now.

Locked In: Palantir, Microsoft and the Hidden Political Risk in Your Cloud
S02:E07

Locked In: Palantir, Microsoft and the Hidden Political Risk in Your Cloud

Picture this: you’re a minister in Europe and Washington quietly asks for a peek. Your emails, drafts and cabinet notes aren’t in a secret vault — they live on someone else’s servers. This episode opens on that impossible, very real moment and follows the ripple effects: threats of sanctions, a neutral Switzerland walking away from Palantir, and the uncomfortable truth that the UK handed that very company the keys to its health, defence and policing systems. We meet the players: Noel Bradford, the Small Business Cybersecurity Guy, who’s spent four decades turning tape backups into survival tactics; Corinne Jefferson, an ex-US intelligence officer who refuses to say “told you so”; Mauven MacLeod, the ex-UK government cyber analyst with biscuits and sarcasm; and Graham Falkner, whose voice narrates the creeping, bureaucratic apocalypse with unnerving charm. Together they pull the camera tight on Palantir — a firm born with CIA-connected funding, hardened in intelligence use, repackaged for civilian life — and show how its DNA matters for everyone from governments to your local charity. The episode walks you through the high-stakes decisions: Switzerland’s 2024 risk assessment that warned data could be reached by American authorities and that leaks from Palantir are architecturally unavoidable; the UK’s contrasting embrace of the same tools across NHS, the MOD and border planning; and how this divergence should set off alarms for every organization that has leaned on US SaaS as neutral plumbing. We translate the legal jargon into a human story. Think of the Cloud Act like an American landlord who can be ordered to open a warehouse — even if your files are stored in London. Encryption doesn’t save you unless you control the keys. UK and EU data rules complicate the picture but don’t yet provide a clean escape. That legal murk leaves businesses and charities sitting on unquantified exposures — not because they’re spies, but because convenience and market share created choke points that politics or courts can exploit. This isn’t fearmongering; it’s a practical wake-up call. Noel guides you through what to do next: a simple Cloud Act exposure audit, naming your crown-jewel data, and deciding which systems deserve extra protection or customer-managed keys. The episode offers concrete, manageable steps — split sensitive fields, demand clear vendor answers, build exit plans — so your small firm isn’t left exposed if geopolitics changes the rules. By the end you’ll see the world differently: your email and CRM aren’t just tools, they’re legal and geopolitical choices. The narrative closes on an urgent but solvable note — map your dependencies, protect what matters, and start asking the awkward questions. The story lands as both a warning and a roadmap: serious, fixable, and essential for anyone who cares where their data really lives.

Edge Devices Under Siege — 393 Days of Unnoticed Access
S02:E06

Edge Devices Under Siege — 393 Days of Unnoticed Access

In this episode of Small Business Cybersecurity Guy, host Maurven McLeod and guest Dr Corinne Jefferson (former US government intelligence analyst turned London-based consultant) unpack Google Threat Intelligence’s alarming report on the Defence Industrial Base (DIB) and explain exactly why it matters to small and medium-sized businesses. They move straight from the uncomfortable headline — Chinese state-linked hackers averaging 393 days of dwell time inside victim networks — to practical implications for 50–80 person companies across manufacturing, logistics, and software supply chains. Topics covered include clear definitions (APT, UNC), the distinction between edge devices and endpoints, why firewalls and VPN appliances are attractive, under-monitored targets, and why EDR often misses the real entry points. They discuss documented campaigns (UNC-3886, UNC-5221/Brickstorm) and how multiple zero-day exploits against edge vendors have been used to gain long-term access and persistence. The episode also examines other nation-state tradecraft: Russian actors targeting messaging apps and device-linking features, North Korean operatives obtaining remote jobs inside companies, and sophisticated recruitment-themed phishing using AI-generated reconnaissance. Maurven and Dr Jefferson highlight how attackers map supply chains professionally — meaning you can be a target even if you don’t self-identify as a defence contractor — and how ransomware and dual-use manufacturing create huge blast radii that can stop production and bankrupt small firms. Most importantly, the hosts give a pragmatic, non-bankrupting 90-day plan for SMEs: an immediate “Edge Reality Check” to interrogate MSP visibility on VPNs/firewalls, a short-term segmentation win to reduce blast radius, and phased rollout of phishing-resistant MFA for key admin and finance accounts. They offer exact questions to ask your MSP, the metrics and controls procurement teams will soon demand, and how to frame the business case to your board. Listeners should expect a mix of blunt intel, real-world examples, and actionable next steps to reduce risk without breaking the bank — plus a call to assume compromise, improve edge monitoring, and stop treating VPNs as magic shields. Tune in for practical guidance, concrete conversation starters for your MSP, and the motivation to make measurable security improvements this quarter.

Four Campaigns, One Nightmare: How 2026's Attacks Bypass Every Small-Business Defence
S02:E04

Four Campaigns, One Nightmare: How 2026's Attacks Bypass Every Small-Business Defence

In this urgent episode of Small Business Cybersecurity Guy, hosts Mauven MacLeod and Graham Falkner join the notably fed-up Noel Bradford to unpack four simultaneous, high‑impact campaigns that emerged between late January and early February 2026. We walk listeners through detailed research from Trellix, Securonix, Rapid7 and Microsoft and explain why these attacks matter to every small business — even if you think you’re too small to be a target. We open with APT28 (Fancy Bear) exploiting CVE‑2026‑21509: a weaponised Office document that triggers on open, drops an Outlook backdoor (MiniDoor/NotDoor) and a C++ implant (Beardshell) injected into svchost.exe, exfiltrating email and system data while blending traffic into legitimate cloud services. Next, Securonix’s “Dead Vax” campaign shows how commodity criminals now match nation‑state tradecraft. Phishing delivers VHD files that mount like drives, bypass mark‑of‑the‑web warnings and execute fileless loaders that ultimately deploy AsyncRAT — giving attackers remote control, keylogging and full data access. Rapid7’s analysis of the Chrysalis backdoor reveals a supply‑chain compromise of Notepad++ hosting infrastructure: poisoned installers selectively targeted victims, abused DLL side‑loading and trusted signed binaries to achieve persistent, encrypted backdoors and lateral movement tools. This is supply‑chain risk in practice. Microsoft’s macOS research details multiple Stealer campaigns (Digit Stealer, Mac Sync, ClickFix, Atomic Stealer and more) distributed through poisoned Google Ads, fake AI tools and messaging apps. These attacks live off native macOS utilities, use AppleScript and Python, and harvest passwords, crypto wallets, SSH keys and cloud credentials — exposing the myth that Macs are immune. We connect the dots: all four campaigns abused legitimate platforms and native features, used memory‑resident or fileless techniques that bypass signature AV, injected into trusted processes, and moved faster than patch cycles. The real victims are not random users but procurement staff, developers and privileged employees. Small businesses face the same capabilities for a fraction of the cost via malware-as-a-service. On the regulatory front we cover the Data Use and Access Act (DUAA) changes that took effect in February 2026: cookie and e‑marketing fines jump to £17.5m or 4% of global turnover, new rules around children’s higher protection matters, a new lawful basis for limited public interest processing, and mandatory complaints handling procedures coming into effect on June 19. We explain why a breach today risks vastly larger financial and compliance consequences. Finally, we give practical, prioritized guidance for small businesses: immediate zero‑cost steps (patch Office, verify Notepad++ versions, show file extensions, audit cookie banners, start a complaints procedure), technical controls to adopt (EDR/behavioral monitoring, managed email security, Mac MDM/EDR, fractionally engaged CISO/CIO), and realistic budgets and trade‑offs for a 20‑person company. Links to all source research and a detailed blog post are in the show notes for listeners who want the technical deep dive.

Security Theatre Exposed — Passkeys, the CISA Leak, and the Hidden Value in Your Cyber Insurance
S02:E04

Security Theatre Exposed — Passkeys, the CISA Leak, and the Hidden Value in Your Cyber Insurance

In this urgent episode of The Small Business Cybersecurity Guide, hosts Noel Bradford, Mauven McLeod and Graham Faulkner bring together three experts to answer one question: why you’re doing security wrong and what practical steps will actually protect your business. We cover four pressing, unconnected problems that share the same root cause — a massive gap between perceived and real security. Dr. Sarah Chen explains passkeys in plain English: how they remove the shared secret that makes passwords vulnerable, why they defeat phishing, credential stuffing and most brute-force attacks, and exactly how small businesses should pilot them this week. She outlines a three-step rollout (check your identity platform, pilot with five users, support them through setup), recovery and accessibility considerations, device and cost guidance, and the measurable benefits — including dramatically fewer password reset tickets. Former US government cyber analyst Corinne Jefferson unpacks the CISA ChatGPT incident, where the acting director uploaded sensitive government contracting documents to public ChatGPT despite an approved internal alternative. Corinne explains how exceptions become normalized, why convenience often defeats policy, how this damages security culture, and what organizations should do: enforce technical controls, require documented risk assessments for privileged exceptions, and ensure detection is coupled with a consistent response regardless of who triggers the alert. Seamus O’Leary shares a practical small-business win: after realising he’d never introduced himself to his insurer’s incident response team, he discovered £18,000+ of pre-incident services already included in his cyber policy — IR plan templates, tabletop exercises, forensics retainers, quarterly scans and a 24/7 breach hotline. The episode walks through the five-week process he used to onboard the insurer’s IR team, fix gaps, run a tabletop, uncover critical weaknesses (unverified backups, unclear ransomware authority, GDPR notification issues) and win board-level funding to replace vulnerable infrastructure. Noel and the team close with a structural look at cloud sovereignty and vendor concentration: why relying on US cloud providers (AWS, Azure, Google) creates real legal and operational risk regardless of where data is physically stored, how the Cloud Act and post‑Schrems II rules change transfer obligations, and practical mitigation options — encryption with external key control, transfer impact assessments, supplementary measures, vendor diversification and multi‑cloud planning. Key takeaways for listeners: enable and pilot passkeys to eliminate credential-based attacks; enforce technical controls and documented approvals so seniority doesn’t become an exception to security; call your insurer’s IR contacts and use the services you’ve already paid for; treat cloud region selection as latency choice, not legal sovereignty, and perform real transfer impact assessments and mitigation. The episode mixes concrete how-to steps, governance advice, and real-world examples — from phishing-defeating authentication to saving thousands by activating policy services — all aimed at helping small businesses turn security theatre into dependable protection.

Who’s in Charge When Ransomware Hits? Building Your Incident Response Team
S02:E03

Who’s in Charge When Ransomware Hits? Building Your Incident Response Team

In this episode of Small Business Cybersecurity Guy, hosts Mauven MacLeod, Noel Bradford and Graham Falkner walk you through Module One of their six-part incident response plan series: building your response team. Through the real-world Katie Roberts case study (name changed), they show why independence matters when a breach hits — and how an unbiased incident manager can quickly uncover the truth, coordinate response, and save a business from far worse outcomes.   Topics covered include the four core incident roles (external incident manager, technical lead, business continuity coordinator, communications lead), how to find and contract an external IM (insurance, IT referrals, retainer vs pay-per-incident), what an IM can and cannot do, authority and spending limits, and realistic costs and timelines. The hosts explain a simple, achievable four-week setup plan that takes roughly four hours of actual work, and they share templates for team structure, external contacts, authority scripts, implementation timelines, and validation checklists.   Key points and takeaways: why impartial coordination matters, how to avoid common provider cover-up biases, the practical steps Katie used to stabilise her business, a real case study of an architecture firm saved from a Friday-afternoon ransomware attack, and concrete homework: find your IM, assign three internal roles, document everything on a single page, brief and validate your team. Listeners will leave with a clear, actionable plan, links to downloadable templates, and the promise that preparation reduces cost, stress, and downtime.

114 Updates, 1 Active Exploit — January Patch Tuesday: Patch Today or Pay Tomorrow
S02

114 Updates, 1 Active Exploit — January Patch Tuesday: Patch Today or Pay Tomorrow

Hosted by Graham Falkner, this episode is a rapid, no‑nonsense January Patch Tuesday breakdown aimed at small businesses and IT owners. Graham walks listeners through Microsoft’s unusually large release of 114 security updates, explains the essential jargon (CVE and CVSS), and highlights why severity scores don’t replace real‑world risk assessments. The show covers the one vulnerability already being actively exploited (CVE‑2026‑2805 in Desktop Window Manager) and two other high‑risk items used in targeted attacks, plus three zero‑day bugs. Graham takes a deep dive into the critical on‑premises SharePoint emergency (Toolshell campaign, CVE‑2025‑53‑700‑70 and related issues), urging immediate patching and incident response for exposed servers. He also explains the severe Kestrel/ASP.NET Core HTTP request smuggling flaw (CVE‑2025‑55315) and the practical impact on web apps and deployment teams. The episode reviews other major vendor fixes: SAP’s 16 security updates (including four critical vulnerabilities), Apple’s two WebKit zero days, Adobe’s 32 patches (eight critical affecting Acrobat, Reader and creative apps), HPE OneView’s unauthenticated RCE (CVE‑2025‑37164), and ongoing VMware ESXi risks. Graham calls out long‑delayed Fortinet SSL‑VPN vulnerabilities (including CVE‑2020‑12812) and newer FortiCloud SSO bypasses, stressing that overdue patching still causes widespread compromises. Practical guidance and priorities are clear and actionable: patch Windows cumulative updates, exposed SharePoint servers, Fortinet edge devices and HPE OneView within 24 hours; address .NET/web app fixes and SAP critical patches within the next 72 hours to one week; then continue with routine maintenance for browsers, Adobe, Cisco and other software. The episode also flags upcoming deadlines and logistics—Oracle’s critical patch update on January 20 and the end of Windows 10 support—so listeners can plan maintenance windows and migrations. Key takeaways: assume compromise if you haven’t patched exposed services, verify systems after applying updates, assign owners who can patch and redeploy quickly, and treat cumulative Windows updates as all‑or‑nothing. There are no external guests—this episode is hosted solo by Graham Faulkner and aimed at helping small organizations act fast and reduce risk in the wake of an intense Patch Tuesday.

UK Government Admits Cyber Chaos — 28% of Systems ‘Cannot Be Defended’: What SMBs Need to Know
S02:E02

UK Government Admits Cyber Chaos — 28% of Systems ‘Cannot Be Defended’: What SMBs Need to Know

In this episode of the Small Business Cybersecurity Guy, host Noel Bradford is joined by Mauven McLeod and Graham Falkner to unpack the Cabinet Office’s January 2026 Government Cyber Action Plan — a blunt, 100‑page admission that the UK government’s cybersecurity posture is “critically high” risk and that many of its own targets are unachievable. The trio break down the report’s headline findings, case studies of high‑profile failures, and why this matters to you even if you’ve never worked with government. Key revelations from the Plan covered in the episode include: roughly 28% of government IT is legacy and cannot be defended with modern tools; repeated systemic failures across departments (poor patching, weak passwords, lack of monitoring); high‑cost incidents such as the British Library ransomware recovery and the CrowdStrike outage that cost the UK economy billions; and the Electoral Commission breach that exposed millions of voter records. The hosts explain the language the report uses — from “historical underinvestment” to “not achievable” targets — and what those admissions mean in plain English. The episode also examines the Cabinet Office’s proposed response: new accountability rules giving accounting officers (permanent secretaries) personal responsibility for cyber risk, routine cyber risk reporting to boards, escalation mechanisms, and potential consequences including removal or public parliamentary scrutiny. The hosts discuss how this mirrors the health & safety/HSE accountability model and why public‑sector reform will likely set the precedent for private‑sector regulation (including implications of forthcoming cyber security and resilience legislation). Financing and timelines are analysed too: the government has allocated around £210 million to kickstart a central cyber transformation unit with milestones through 2029, but the hosts stress this is a down payment — true remediation will take years and likely billions. The Plan’s investment priorities (visibility/monitoring, accountability, supply‑chain assurance, incident response and skills) form a checklist for businesses to adopt now. Supply‑chain requirements are a central takeaway: departments will require security schedules, certification (Cyber Essentials, Cyber Essentials Plus, ISO 27001 where appropriate), and documented evidence of controls. These requirements will cascade down through primes to second‑ and third‑tier suppliers, so small businesses should expect tightened demands for proof of security and that compliance will become a competitive advantage. The hosts finish with practical, actionable advice for small businesses: treat cyber risk as board‑level risk; establish personal accountability and clear escalation; prioritise visibility and monitoring; inventory and pragmatically manage legacy systems; obtain appropriate certifications (Cyber Essentials Plus, ISO etc.) if you have or might have public‑sector exposure; segregate and protect government work; build or improve incident response capability; and use this moment to push cultural change so security is embedded across the organisation. Throughout the episode Noel, Mauven and Graham provide candid analysis, real examples from recent government failures, and specific steps SMBs can take now to reduce risk and gain a competitive edge as regulation and procurement expectations tighten. Listeners are pointed to the full Government Cyber Action Plan on gov.uk and the podcast blog for a detailed breakdown and sources.

When MFA Isn’t Enough: Inside Adversary‑in‑the‑Middle Attacks
S02:E01

When MFA Isn’t Enough: Inside Adversary‑in‑the‑Middle Attacks

In this episode Mauven McLeod and Graham Faulkner (with Noel Bradford joining partway through) unpack a worrying trend: adversary‑in‑the‑middle (AITM) attacks that steal session tokens and completely bypass conventional multi‑factor authentication (MFA). Using Microsoft’s recent telemetry (a 146% jump in AITM incidents) as a backdrop, they explain how transparent proxy phishing pages relay credentials and MFA approvals to capture session tokens and gain hours of unrestricted access to Microsoft 365 accounts. The hosts explain, in plain technical terms, why SMS codes, authenticator app push prompts and one‑time codes fail against these attacks and why the stolen session token becomes a single‑factor credential for attackers. They describe what attackers typically do after compromise — mailbox reconnaissance, forwarding rules, OAuth app persistence, and registering new authentication methods — and highlight the scale of automated phishing‑as‑a‑service tools that make these attacks cheap and fast. The episode then walks through the practical, phishing‑resistant solutions every small business should consider: Windows Hello for Business, hardware security keys (YubiKey, Authentrend and similar), and passkeys on mobile devices. For each option they cover how it works, deployment requirements, licensing or purchase costs, user experience trade‑offs, and which users to prioritize for rollout. Mauven and Graham recommend a tiered, risk‑based rollout strategy: protect admin and privileged accounts first, then finance/HR/executives, and finally the wider workforce over months. They discuss real‑world gotchas — legacy apps that don’t support modern auth, BYOD complications, mobile workflows, and the need for a secured “break glass” account — plus expected labour, training and hardware costs for a typical 30‑user small business. Beyond replacing or upgrading MFA, the hosts cover essential complementary controls: conditional access policies, continuous access evaluation (CAE) to shorten token windows, blocking legacy authentication (SMTP/IMAP/POP), impossible‑travel detection, and concrete incident response steps (revoking sessions, removing rogue MFA methods and OAuth apps, checking forwarding rules and mailbox rules, and doing forensics on accessed data). The episode closes with an immediate to‑do list for small businesses: verify MFA is actually enabled, remove SMS/email MFA methods, plan a phishing‑resistant rollout starting with tier‑1 users, enable conditional access and CAE, and budget for training and support. They also preview an upcoming multi‑episode series to help businesses build a practical incident response plan. Listeners can expect a technically grounded but actionable discussion aimed at business owners and IT staff: why traditional MFA is still valuable, why it’s not enough against AITM, and exactly how to adopt phishing‑resistant authentication to close that gap.