Listen as Noel Bradford — the Small Business Cyber Security Guy — pulls back the curtain on a criminal economy that looks eerily like a legitimate market. The story begins not with a hooded hacker in a basement but with supply chains, service desks, affiliate margins and racks of phones pretending to be people: an industrialised machine that Europol lays bare in IOCTA 2026.
Imagine a landlord who rents lockups to burglars and never asks why everyone arrives at 3am. Now imagine that landlord runs a global network of proxies, bulletproof hosting and sim farms that let criminals create millions of fake accounts, receive one-time codes and vanish with the money. Noel walks you through that rack of 40,000 SIMs and the jaw-dropping scale — 49 million accounts created — and shows how criminal services chain together into a repeatable, low-cost supply model.
He tells the story of the modern ransomware franchise: not a lone crew but brands, affiliate programs and negotiation services, with some gangs offering affiliates 80–85% of ransoms. This isn’t cinematic drama — it’s commercial logic. Criminals buy speed, scale and plausible deniability; law enforcement chases the velocity gap. AI writes the scams, proxies hide the origin, crypto moves the money, and encrypted platforms slow evidence gathering. The result: a faster, stealthier, more connected threat.
Noel’s narrative turns the Europol report into a mirror for small businesses. It’s not just about technical fixes — it’s about whether the products and certificates you buy actually match the way crime now works. He uses vivid examples (sim farms, DNS abuse, data-leak extortion) to make one blunt point: a backup is crucial, but it doesn’t unsend stolen customer lists or unpublish payroll files. Your recovery plan must cover communications, legal, insurers and reputational damage — not only server restore points.
Through sharp, practical storytelling Noel gives you three immediate actions small businesses can do this week: email your IT supplier and ask if they’ve read IOCTA 2026, audit every SMS-based workflow that handles money or identity, and rethink your ransomware plan around stolen data being published. He frames these as homework, not panic — small, urgent steps that cut through vendor theatre and certificate-shaped comfort.
By the end of the episode you’ll see the threat differently: no longer isolated buckets of ransomware or fraud but a joined-up criminal economy exploiting weak identity, cheap infrastructure and slow institutional response. Noel doesn’t just warn you — he shows you how to start fixing it, with plain questions to suppliers and concrete checks you can run in a day. This is a wake-up call dressed as a podcast episode: direct, unflinching and built to move small businesses from complacency to grown-up risk management.