The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups@SmallBizCyberGuyMain

0 followers
Follow
When AI Finds the Switch You Forgot: Attacks for Pocket Change
Ep. 64

When AI Finds the Switch You Forgot: Attacks for Pocket Change

Imagine waking on a Tuesday to discover an invisible army has been testing your doors for six days. It doesn’t need fancy zero-days or cinematic cleverness — just agents that can scan, read, adapt and move on. In this episode, we follow a financially motivated attacker using open-source AI tools to run 105 probing projects in under a week, harvesting card data and compromising organisations while the cost of each reconnaissance run averages just a few dollars. From Gambit Security’s reconstruction of a scaled campaign to New Zealand’s National Cyber Security Centre warning that frontier models accelerate reconnaissance, the story threads together into one uncomfortable observation: the problem isn’t a lack of security technology, it’s the gap between owning features and operating them. A critical TeamCity flaw with a published patch and known exploitation shows how a fixed vulnerability becomes a real ransomware entry when change processes stall and nobody can say for sure what is exposed. We even wind up in the optical spine of fiber broadband, where Quark’s Lab’s deep dive into passive optical networks exposes a familiar theme — standards and features can support strong protections, but optional choices and careless deployments turn capability into illusion. Whether it’s MFA, backups, EDR or encryption, a green tick on a dashboard is not the same as a control that will actually stop an attacker in the middle of the night. AI doesn’t need to be a brilliant mastermind. It just needs to cheaply and persistently test the weak signals you left lying around. That changes the economics: the marginal cost of trying the next company collapses, and opportunistic compromise scales. Small businesses aren’t suddenly interesting; they’re suddenly cheap to probe, and automation can take an exploit much further than old scanners ever could. But this isn’t fatalism — it’s a practical wake-up call. The defence that works is less about buying another product and more about operational discipline: know what your external world can reach, test whether MFA actually prompts for a second factor, restore a backup for real, and rehearse the decision pathways for critical patches. Ask: if someone could attack us cheaply tomorrow, what would make them stop? We tell the story through people and processes — the helpdesk pressured to reset accounts, the admin on leave, the server thought to be internal but quietly facing the internet — and pull tools into the background. The episode walks you through real moments where security features exist but controls don’t, then hands you a simple, evidence-first checklist to start closing those gaps today. By the end you’ll see the same pattern in different disguises: AI makes probing trivial, technology contains the answers, and operations decide whether those answers are actually used. It’s bleak, fixable, and urgent — because the next probe might be the one that finds the switch you forgot to turn on. Find our Skool community here - https://www.skool.com/small-biz-cyber-guy-2008

When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning
Ep. 63

When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning

Three headlines—an EU law delay, an AI-accelerated intrusion that went from weeks to hours, and a UK bill about to bring hundreds of IT providers under direct regulation—sound like stories from different podcasts. They aren’t. By the end of this episode, they meet in a single, worrying place: the gap between assumption and evidence. Follow Noel Bradford, Lucy Harper and Corrine Jefferson as they trace that gap through vivid scenes: a quiet lawroom in Brussels that postponed some deadlines but switched major penalties on; a Unit 42 investigation where one attacker, helped by AI, compressed reconnaissance, exploitation and extortion into under ten hours; and Westminster’s Cybersecurity and Resilience Bill that could force managed service providers to register, report incidents quickly, and face heavy fines. Along the way, the podcast lights up small, human details—a heating engineer’s paperwork, a builder’s son who inherited the IT, a host who reads breach reports like gas bills—to show how ordinary businesses get dragged into extraordinary risk. They don’t just explain the problems; they show how the threads tie together. The EU’s AI Act makes clear obligations for providers of large models but only if you can first answer the simple question: what AI do you actually use? The attack demonstrates the lethal value of time—alerts that wait in an inbox are useless when an attacker finishes a campaign before most people have their second cup of coffee. The UK bill exposes who truly owns the decision when an outsourced provider goes dark: legal reporting may hit the MSP, but operational pain lands with the client. Alongside sharp investigations into LG TV privacy claims and a cunning "click-to-fix" browser-cache exploit, the episode turns practical. It hands you three urgent morning-after questions to take to your board: what AI does your business use (and who owns it), could you detect and respond within ten hours, and is your IT provider positioned to be regulated? If you can’t answer those now, this episode will make it impossible to shrug them off. Listen for clear, actionable steps—visibility, speed and ownership—that every small business needs before the clocks of law, crime and regulation collide.

Why a 0% Phishing Click Rate Might Be Lying to You
Ep. 62

Why a 0% Phishing Click Rate Might Be Lying to You

They put a fat green 0% on the slide and everyone nodded like it meant victory. Gary, a builder with plasterboard and vans on his mind, sips his tea and wonders why cyber security suddenly sounds like someone else’s problem — until the hosts pull that cheerful number apart. What looks like perfect protection can be a mirage: a workforce trained to pass one test but not to spot the real, messy tricks criminals use when a delivery is late or an invoice changes. In this episode, Noel and Morvan walk Gary — and you — through the slow unravelling of that comforting 0%. We follow a year of simulated attacks from a vendor’s dataset and watch a story unfold: clicks fall, then spike, and finally settle — not because people got stupider, but because the tests got harder and started catching the vulnerabilities that easier simulations missed. Through vivid examples (the parcel everyone waits for, Dave who closes a window and hopes no one noticed, and a frantic phone call that saves the company money), the hosts tease out the real lessons. Clicks are not binary verdicts; they are one link in a chain that includes credential submission, MFA failures, and the crucial moment when someone chooses to report the suspicious message. Reporting becomes the episode’s hero: a single employee who says “this looks odd” can protect an entire team. The conversation turns practical — one big, easy-to-press button, quick acknowledgement, and a culture that thanks people for coming forward instead of shaming them. The narrative pivots from blaming individuals to building systems that survive human error. By the end you’ll see why insurers and dashboards obsessed with a single percentage get a dangerously incomplete picture, and why better metrics — credential leaks, reporting rates, testing difficulty, and report speed — reveal a healthier story. The episode closes with four concrete steps Gary can take on Monday morning and a rallying cry: don’t chase perfect green ticks; build processes that turn your people into the sensors that actually keep you safe.

When AI Could Make You Speak: Trust, Consent, and Synthetic Voices
Ep. 61

When AI Could Make You Speak: Trust, Consent, and Synthetic Voices

It begins with a simple, uneasy question: can the system make Graham say something he never said? The hosts — Lucy, Noel and Graham — turn a nagging fear into a tense, curious investigation as they lift the curtain on how this podcast is made. What follows is less technical lecture and more confessional road‑test: rehearsal recordings, AI voice models, and the missing line that could break a Monday‑morning episode. That single scenario becomes a moral pressure test for rules that sound good on paper but buckle the moment a deadline arrives. From the recorded conference call to the final rendered voice, the episode walks you through every trap: perfect transcriptions that lie by omission, an AI that ‘helps’ by inventing clearer phrasing, suppliers who change terms overnight, and the awkward realisation that consent to model a voice is not ownership over the person behind it. The hosts push their own policies until they crack, showing how context — who’s available, who’s under pressure, what the sponsors want — determines whether a guardrail holds or fails. Through punchy examples and studio anecdotes, the conversation pivots to the cornerstones of sensible governance: precise rules not vague aspirations, logging and provenance where decisions matter, incident plans written before disaster, and human authority that can actually say no. Small businesses eavesdropping on this exchange get a practical lesson: don’t pretend AI is brand‑new — apply the governance you already know, but shore it up where AI amplifies risk. Listeners will feel the tension between convenience and integrity as the hosts debate whether corrected facts, edited context, and late‑minute fixes can ever be rendered in someone else’s voice without permission. The episode doesn’t demonise the technology; instead it teases out the choices that make it trustworthy or dangerous. Identity protection, transparent disclosure, and who gets to approve final wording become the story’s beating heart. By the end you’re left with a challenge: imagine the moment when following the rule costs you time, money or an episode — and decide in advance which matters more. With humour, practical steps and a few studio confessions, this episode becomes a toolkit and a cautionary tale: design guardrails that survive a busy Monday morning, then try to break them before someone else does.

We Found the Admin Password in the Dark Web: A GRC Wake-Up Call
Ep. 60

We Found the Admin Password in the Dark Web: A GRC Wake-Up Call

It begins like a quiet, ordinary audit: an annual security check, the kind of routine that should leave you reassured. Instead, it ends with a single line of data that changes everything — the password for a shared Microsoft 365 admin identity appears in a dark web credential dump. What follows is not a thriller about dramatic hacks and midnight ransom notes, but a far more unsettling story about assumptions, convenience and the slow drift from policy to peril. Lucy, Noel and Graham walk you through the discovery as if you were in the room with them: the initial disbelief, the precise questions, the careful parsing of what the presence of that credential does — and does not — prove. It doesn’t prove an active compromise of the tenant. It doesn’t show that funds were stolen or files siphoned off. But it does prove that a secret is no longer secret, and that the one basic thing security is supposed to give you — accountability — had been quietly surrendered when a single identity came to stand for many people. From there the podcast moves from theory into instant reality. Decisions that once felt academic — whether to stop sharing logins, whether to require stronger authentication, whether to upgrade licensing — become urgent actions: rotate the credential, remove shared access, review sign-in history, audit privileges and hunt for suspicious activity. The hosts take you through the pragmatic steps of containment and investigation while unpacking why a shared admin account complicates every element of incident response and attribution. But this episode is more than a checklist. It’s a lesson in governance, risk and compliance told through human voices and wry commentary: who owned the decision to allow shared identities, how risks were underestimated for convenience, and why compliance isn’t a spreadsheet of green boxes but evidence you can show when someone actually looks. The narrative sharpens when the hosts confront the uncomfortable truth — reality will audit you for free, and often at the worst possible moment. Technology and nuance weave through the conversation: the protective value of MFA and conditional access only matters if they’re configured and enforced; for privileged roles, the hosts explain Microsoft’s move toward phishing-resistant authentication like passkeys and FIDO2 keys. Practical, bite-sized guidance sits next to the wider cultural point: security work is rarely thrilling, and yet its quiet, boring practices are the very things that stop bad things from happening. There are human touches too — the recurring joke about ‘Fred,’ the imaginary multi-person identity that logs in from everywhere, and the admission that the show itself uses AI in all aspects of production under strict guardrails. That revelation becomes a mini-case study about governance again: how consent, editorial control and strict boundaries turn the same technology that can impersonate into a tool for protection and clarity. The episode ends with a clear, actionable offer — ten free dark web credential scans and a final provocation: don’t ask whether anything bad has happened to you; ask what evidence you have that nothing bad has happened. It’s an eerie, practical close to a four-part series that began with frameworks and finished by meeting the messy, inconvenient truth of real systems. Listen for the human conversations, the forensic thinking, and the bitingly honest moment when a routine audit turns a hypothetical risk into a concrete problem. This is a story about small decisions with big consequences — and about the steady, sometimes boring work that keeps businesses secure.

Prove It — When Boardroom Confidence Meets Real-World Controls
Ep. 59

Prove It — When Boardroom Confidence Meets Real-World Controls

We start with a number: 94% — the share of UK business leaders who say they’re confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require two‑factor authentication, 31% report board‑level ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident. In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isn’t a security control. Saying “we’d cope with ransomware” is not the same as proving you’ve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it. We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change — rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated. Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and high‑profile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it? ‘Compliance’ is rescued from the textbook. It becomes three things: policy (the decision you’ve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre — beautifully formatted fiction where every box is green — and replaces it with operational tests that matter. Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same ‘Fred.’ Accountability disappears, and with it the ability to respond credibly to an incident. There are no magic words or silver bullets: Cyber Essentials isn’t a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline — a prompt to prove the controls you claim to have. Before you turn off the show, the hosts hand you an unpretentious to‑do list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than one‑off paperwork. By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered — convinced that good security can be practical and affordable, but only if leaders stop saying they’re secure and start showing it.

Passkeys Aren't Dead — What a Week of Panic Taught Us About Risk
Ep. 58

Passkeys Aren't Dead — What a Week of Panic Taught Us About Risk

Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions. First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had. Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings. These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow. We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes. Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords. By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.

Meet Dave: From Gas‑Safe to Cyber‑Safe — A Small Business Survival Story (Part1)
Ep. 57

Meet Dave: From Gas‑Safe to Cyber‑Safe — A Small Business Survival Story (Part1)

Three letters—G‑R‑C—sound like corporate nonsense until they stand between a business that survives a bad day and one that doesn’t. Pull up a stool: this episode meets Dave, who runs a 14‑person heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. He’s gas‑safe, insured, and obsessive about paperwork when lives are at stake. But his cybersecurity? That lives in his head, or a post‑it, or a notebook in a top drawer—and that’s the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster. We tell Dave’s story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules they’re given; the business fails when nobody decided what the rules were. Governance isn’t a committee or a legal brief—it’s four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplier’s—and the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday. This episode uses storytelling to make the abstract vivid: the harmless phrase “we’re too small for this” becomes a trap, the notebook of passwords becomes a ticking time bomb, and a one‑page decision becomes the difference between chaos and calm. You’ll hear practical scenes, not slides—how a named human owner, a handful of decisions, and a quarterly 10‑minute review turn security into something usable, not terrifying. By the end you’ll have three simple actions you can do this week: name the person who owns your security out loud; start your one‑page governance sheet; and set a recurring three‑month GRC reminder. Small, concrete moves that take minutes and protect years of work. If you’re a small business owner who thinks cyber is someone else’s problem, this episode is the wake‑up call delivered over a pint—friendly, practical, and impossible to ignore.

The Open Book Problem 5: Closing it with Practical Defences for Small Businesses
Ep. 56

The Open Book Problem 5: Closing it with Practical Defences for Small Businesses

The final episode in the five-part Open Book series delivers a practical action plan for UK small business directors facing public data exposure. Noel Bradford and the SBCSG team rank OSINT risks by real attack potential, from identity compromise to technical targeting. Graham Falkner provides a 30-day implementation plan covering Companies House corrections, electoral register opt-outs, data broker removal, and process hardening. Mauven MacLeod examines the policy gaps that leave individuals absorbing systemic risk, while Lucy Harper summarises outstanding accountability questions for regulators and government. The episode includes a board-level conversation framework, guidance on when to seek help, and a tabletop exercise for testing verification processes. This is not about vanishing from the internet. It is about reducing avoidable harm, prioritising exposure that enables fraud, and turning regulatory frustration into collective pressure for structural reform.

The Open Book Problem 4: Who's Really Deleting Your Data?
Ep. 55

The Open Book Problem 4: Who's Really Deleting Your Data?

Delete Me and Incogni aren't scams. That's a sensible place to start. But as this episode of The Open Book Problem unfolds, a quieter, sharper scandal emerges: a paid subscription market built on a failure that should never have been dumped on ordinary people. Meet the protagonist of our story — a UK small-business director who wakes up one morning to discover their home address, director profile and personal history strewn across search results, broker sites and public registers. The immediate villains seem obvious: people-search sites, aggressive broker ecosystems and glossy removal services promising a clean slate. But the real antagonist is a broken system that forces busy people to choose between unpaid, tedious labour and handing their privacy to a subscription.

The Open Book Problem 3: When GDPR Meets the Data‑Broker Machine
Ep. 54

The Open Book Problem 3: When GDPR Meets the Data‑Broker Machine

GDPR promised control: erasure, access, objection, transparency. In this episode, Noel Bradford and Lucy Harper walk us into the yawning gap between those beautiful legal words and the grinding reality where data brokers collect, enrich and re‑sell people’s lives at scale. The narrative opens with a simple scene — a small business director, a home address, a labrador, a ring doorbell — and slowly reveals how that ordinary detail becomes a powerful asset when combined with brokered profiles.  

The Open Book Problem 2: How Public Records Teach Criminals Your Name
Ep. 53

The Open Book Problem 2: How Public Records Teach Criminals Your Name

Imagine someone who knows your director's calendar, your payroll provider, the IT stack listed in your job ad, and the name of the accountant who signs your invoices. They don't have to be a genius — they just read what you and the public have already told them. In this episode, Noel Bradford follows that clean, quiet path of reconnaissance from public registers to a phone call that sounds unmistakably legitimate. We open on a simple truth: most social engineering isn’t a cartoon villain guessing passwords in the dark. It’s research, timing and pressure dressed up as plausibility. Noel and Corin map the attacker’s five-step journey — selection, mapping, pretext, delivery and pressure — and show how every ordinary piece of public information becomes a tile in a convincing story. Set against the uniquely open UK landscape of registries, data brokers and oversharing on professional networks, the episode becomes a procedural drama. You’ll hear how a director’s LinkedIn post about a conference can set the stage for an urgent Friday payment request, how job ads can hand an attacker the exact platform to fake, and how a single helpdesk script can be the thin crack through which a whole company falls. Through vivid examples — supplier impersonation, emergency MFA resets, Teams messages that replicate a boss’s tone — the episode explains why static verification checks fail and why ‘because the director said so’ is an invitation to fraud. We discuss Scattered Spider not to sensationalise, but to show how identity support processes become attack surfaces and why attackers treat due diligence like reconnaissance with ill intent. Noel moves from problem to practice: concrete defensive moves you can implement today — map your public exposure, write down verification rules, require independent checks on sensitive requests, train staff on pretext and pressure (not just typos and bad links), and treat your helpdesk as a security control. The advice is practical, procedural and, yes, a little boring — because that’s exactly what prevents crime. By the end you’ll see the small, human moments that make social engineering succeed — a rushed payment, a polite phone call, a culture that prizes speed over verification — and how changing those moments can take away an attacker’s easiest building blocks. Tune in to learn what an attacker would find about your business before lunch, and what you can remove before they get hungry.

The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap
Ep. 52

The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap

They didn’t break in. They didn’t plant malware. They opened tabs, clicked links and joined the dots. In this episode we follow the quiet, methodical work of an attacker who builds a usable portrait of a UK small business director from nothing more than public records and a search box. It begins like a detective story and ends like a cautionary tale: Companies House entries, electoral data, LinkedIn posts, DNS records and job adverts become the clues that make fraud feel personal — because it is. Through the voices of Noel Bradford and Corrine Jefferson, the episode walks you through the attacker’s timeline: the first flick through Companies House to find directors and filing rhythms, the enrichment of that picture with open-register addresses and marketing data, the human-mapping on LinkedIn, and the technical fingerprint left in DNS, MX and certificate logs. Each step is ordinary, lawful and, crucially, assembled without a single hack. We make it concrete. In twenty minutes an attacker can produce a director profile, infer email providers, spot hiring signals that leak technology stacks, and spot behavioral seams to exploit. The lure is tailored; the language is familiar; the victim feels the email is meant for them. Social engineering stops being magic and becomes efficient administration with malicious intent — a repeatable, industrialized craft that preys on transparency. But this episode isn’t just alarmism. It frames the tension between public accountability and personal risk, showing why transparency designed for credit checks and journalism also creates a joined profile attackers love. We tell the story of how digital glitter — once data leaves its source — glints everywhere, and why suppression or removal is never instant or total. By the end you’ll feel that uncomfortable nudge: search your company on Companies House, check service addresses, review LinkedIn and job adverts, and audit your domain’s email records. The narrative closes by setting the scene for the next chapter in the series and challenging every listener to ask: what did I find about myself that an attacker could use first?

The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency
Ep. 51

The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency

A firewall cannot save you from being badly run. For years, small businesses have been sold the idea that a perimeter box equals protection. When Fortinet disclosed exploited authentication bypass vulnerabilities, added to CISA's Known Exploited Vulnerabilities catalogue, the uncomfortable truth surfaced again: the firewall is not a wall. It is a computer at the edge of your network that runs software, has management access, and can be compromised. Defence in Depth means using multiple security layers so that when one fails, another slows the attacker, limits damage, or helps you spot the problem. The NCSC describes this as reducing single points of failure. Yet many small businesses still operate flat networks with exposed management, weak identity, old firmware, missing logs, and untested backups. This episode unpacks the Fortinet advisory, challenges the green dashboard culture, and delivers a practical checklist for the twenty-person firm. The panel argues about MSP accountability, board responsibility, and the difference between buying comfort and buying outcomes. No vendor worship. No reassurance fog. Just evidence, ownership, and the hard questions businesses should ask before the next advisory drops.  

Erased from the Web: The Fight Over a Child's Moment
Ep. 50

Erased from the Web: The Fight Over a Child's Moment

Should Schools Remove Pupil Photos from Public Websites? A school removes all identifiable pupil photos from its website and social media. A parent complains their child's sporting achievement has been erased. The safeguarding lead sees reduced risk. The marketing lead sees lost warmth. The headteacher is caught in the middle. This What If Wednesday unpacks the tension between celebration and safeguarding in an era of facial recognition, AI manipulation, and permanent digital trails. The panel explores lawful basis, consent limits, metadata risks, and why public celebration no longer requires handing children's identities to the open internet. Practical guidance covers policy design, parent communication, safer storytelling, image audits, and leadership decisions. Schools can still celebrate pupils without treating them as searchable marketing assets. Chapters Cold Open: The Complaint A school strips identifiable pupil photos from its public channels. A parent says their child's sporting achievement has been erased. The tension between pride, safety, and marketing is introduced. Welcome: What If Wednesday The panel frames the scenario as a practical discussion for schools, parents, and trustees navigating image use in a changed online landscape. The Trap Schools Walked Into Why schools published pupil photos for good reasons, and why that old model now needs urgent review in light of scraping, AI tools, and permanent exposure. Consent Is Not a Magic Cloak Lawful basis, transparency, withdrawal rights, and why parental consent does not eliminate technical or safeguarding risk once images are public. The New Risk Is Not Theoretical Scraping, facial matching, AI manipulation, metadata, blackmail, and cumulative exposure. The threat landscape around public pupil images has fundamentally changed. Midroll Bumper: The Decision Point A short reset. The parent, marketing lead, and safeguarding lead are all justified. The answer is safer celebration, not silence or defensiveness. What The School Should Say To The Parent Empathetic communication that acknowledges pride, explains the decision, and offers safer alternatives without reversing the safeguarding boundary. What Marketing Should Do Instead How schools can still convey warmth, identity, and community without relying on identifiable pupil faces on open platforms. Storytelling, not just stock images. What The Policy Needs On Monday Morning Practical action list: audit existing images, classify risk levels, define review questions, update parent communication, fix workflows, train staff, and review annually. The Leadership Decision Leaders must decide what public celebration looks like now, give staff cover, avoid informal negotiation after every event, and frame the policy as protection and recognition. Outro: The Answer Hold the safeguarding line. Explain properly. Offer safer celebration. Do the boring work. A school can celebrate children without turning them into searchable marketing assets.

MFA Fatigue Is a Management Failure, Not a User Problem

MFA Fatigue Is a Management Failure, Not a User Problem

Multi-factor authentication is essential, but not all MFA is equal. When users receive vague, repeated, or poorly explained prompts, they start treating them like cookie banners: accept, accept, make it go away. Attackers exploit this fatigue by triggering prompts under pressure, impersonating IT support, or using social engineering to bypass weak helpdesk processes. This is not a user failure; it is a design and management failure. Businesses must reduce unnecessary authentication noise, use phishing-resistant methods like number matching, train staff to recognise unexpected prompts as attack signals, and strengthen identity verification processes. A reported prompt that turns out to be nothing is a working security culture. A prompt nobody reports because everyone fears looking stupid is how expensive conversations with insurers begin. MFA is a control, not a confession booth. If it fails, look at the whole process: the prompt design, the training, the helpdesk, the call-back procedures, and the culture that prioritises speed over verification. Stop blaming users for predictable mistakes in badly designed systems.

Shadow AI Is Just Shadow IT Wearing a Cape
Ep. 49

Shadow AI Is Just Shadow IT Wearing a Cape

Shadow AI has already arrived in most UK small businesses, often through browser tabs, SaaS tool sidebars, and helpful buttons that promise to improve text. Staff are using AI to rewrite emails, summarise meetings, polish proposals, and speed up admin tasks, frequently without approval, policy, or controls. This is shadow IT all over again, but faster and with better branding. The problem is not the technology itself, but unmanaged data movement into systems nobody has reviewed. Noel Bradford explains why banning AI without offering safe approved routes will fail, why hope is not an AI governance model, and why businesses need practical data controls that give staff clear lanes: low-risk generic tasks, controlled handling of customer data, and hard stops for sensitive material. UK Government guidance and NCSC advice make clear that AI changes the threat landscape, but the basics still matter. This episode cuts through the hype to deliver straightforward guidance on approved tools, supplier checks, human review, and early mistake reporting. AI policy is not about stopping progress; it is about stopping progress from leaking your business into someone else's platform.

Pop-Ups, Upsells & Risk: Taming the Noisy World of SaaS Admin Dashboards
Ep. 47

Pop-Ups, Upsells & Risk: Taming the Noisy World of SaaS Admin Dashboards

Imagine opening your SaaS admin panel and walking into Times Square: flashing upsells, trial banners, an AI button nobody asked for, and a marketplace pitch vying for your click. In this episode, Noel Bradford—your Security Guy—takes you through that sensory overload and shows how it’s not just annoying design; it’s a security problem. When every notification screams for attention, the real alarms get lost in the noise. Through vivid scenes and sharp examples, Noel explains how attention itself is a control: systems that drown users in marketing clutter train people to ignore banners, default prompts, and even vital security warnings. He weaves practical stories about suspicious sign-ins buried under upgrade offers, API tokens created beside glossy feature tours, and admin portals that bury logs behind paywalls, painting a clear picture of how SaaS sprawl turns convenience into hidden risk for small businesses. The episode moves from diagnosis to action. Noel lays out a no-nonsense checklist—inventory your SaaS estate, assign owners, remove unused integrations and dormant admins, enforce MFA, and route genuine security alerts to a monitored place—then challenges listeners to ask vendors hard questions about log access and whether security features are deliberately gated behind premium plans. Part cautionary tale, part practical guide, this episode blends storytelling with actionable advice so listeners leave energized to declutter their dashboards and protect their businesses. If your work tools look like a shopping center, expect people to treat warnings like adverts. Listen in, then reclaim attention as the critical control it is.

AI vs The Patch Queue: When Faster Discovery Breaks Business
Ep. 46

AI vs The Patch Queue: When Faster Discovery Breaks Business

Noel Bradford opens the episode with a wry grin and a simple warning: AI has put a jet engine on vulnerability discovery, and that turbocharged speed is coming straight for your patch queue. He paints a scene that starts idyllic—researchers, vendors, and defenders holding hands in a meadow—and then smashes it into the small-business reality everyone knows: an ageing accounts package, two neglected servers, a printer that suddenly has feelings, and a spreadsheet last updated by someone called Maybe James. Through sharp, conversational storytelling, Noel follows the trail from shiny headlines about faster vulnerability discovery to the quieter, nastier truth: more findings mean more advisories, more tickets, and more decisions. For teams already drowning in alerts—endpoint warnings, vendor advisories, and countless scanner results—AI doesn’t rescue them. It simply shines a brighter light on the rot. The episode becomes a practical parable about what actually prevents breaches: fundamentals. Noel walks listeners through the essentials as if he were guiding a reluctant business owner around a cluttered workshop—build a real asset inventory (not a mythical one), assign clear ownership, book maintenance windows that aren’t pretend, and document exceptions with accountability. He explains how these mundane actions are the real defenses, not the latest headline-grabbing CVE score. But the story isn’t all doom. Noel argues that AI can help—if your processes are mature. Faster discovery can help defenders and vendors if decisions are made quickly and sensibly. The heart of the episode is a leadership appeal: patch management is a business problem that touches operations, budgets, and reputations. When the business says “no” to maintenance and “later” to upgrades, it builds a swamp, and IT is left to slog through it. The episode closes on a clear, rallying note: the AI patch wave is coming, and the question isn’t whether new vulnerabilities will appear—it’s whether your organisation has a process or just Dave, a spreadsheet, and a headache. Listen for practical measures, memorable metaphors, and a call to treat patching as governance, not theatre—because speed is now the test of your maturity.

When Cybercrime Stops the Till: Why It's a Business Problem, Not IT's
Ep. 45

When Cybercrime Stops the Till: Why It's a Business Problem, Not IT's

Noel Bradford opens the episode with a blunt question: what does a cyber attack really cost your business? He takes us out of the server cupboard and into the meeting room, where time lost, money gone, reputations dented and growth stalled are the metrics that actually matter. Through vivid examples—payment fraud that empties a ledger, ransomware that freezes production, a supplier breach that hands customers to a competitor—Noel shows how an email, a weak password or a forgotten server can cascade into an existential business crisis. The narrative follows small businesses facing an uncomfortable truth: cybercrime is no longer an edge-case IT headache, it’s a predictable criminal business model that targets people, process and trust. Noel cites fresh data that brings the story to life—fraud, scams and attacks are climbing—and he paints a picture of criminals with playbooks, support desks and supply chains that mirror legitimate industry behaviour. The result? An urgent call to move cyber from back-office grudge purchase to front-page boardroom agenda. Rather than drowning listeners in technical jargon, the episode uses sharp, practical questions to reframe risk: what would stop you trading? which systems must be restored first? who can authorize emergency spend? Those questions drive the story into real-world decisions—payment controls, MFA, backup testing, supplier access reviews—and expose how leadership failures, not just missing patches, make incidents costly. Noel’s voice guides listeners from complacency to clarity. He unmasks common excuses—‘that server’s fine’, ‘we’ll sort it after the quarter’—and shows the human moments that save or sink companies: the staff member who spots a scam, the CFO who questions a change of bank details, the manager who can’t find an incident owner when minutes matter. The stakes are personal: customers lose trust, staff waste time, opportunities evaporate and the business pays the bill. The episode closes as a call to arms and to common sense. Cybersecurity becomes business continuity with a login prompt: add cybercrime to the risk register, map systems that stop trading, budget for resilience and, crucially, assign accountability. Noel leaves listeners with a clear storyline to act on—lead from the top, test your recovery, and treat cyber the cost of doing business before it treats you like lunch.

Don't Worship the Green Tick: Why Backups Won't Save You
Ep. 44

Don't Worship the Green Tick: Why Backups Won't Save You

Noel Bradford opens the episode with a provocation: backups are sacred in small businesses, but too often they're a comforting myth. Picture a bright Monday at 9am — the backup dashboard is full of green ticks, the MSP report lands in an inbox that breathes a little easier, and then a criminal in muddy boots asks the question nobody practised: what can you actually recover, by when, and who knows how? This episode walks listeners through the moments when assumptions collapse. It's not the encryption that usually kills a business — it's the downtime, the missing passwords, the licence keys lost in a cupboard of doom, the renamed folders that quietly excluded critical data for years. Bradford stitches together real-world missteps into a narrative that makes the stakes painfully clear: a back-up is an ingredient, not a plan. You'll hear why green ticks and dashboards are little more than participation trophies unless somebody has rehearsed the restore. The host paints vivid scenes of restores that take days, data that is stale, and the awkward management meetings that follow: "Why didn't anyone test this?" — a question delivered with the cool late-arrival of hindsight. Practical guidance arrives as character and plot: follow the NCSC ransomware guidance, heed ICO data-protection duties if personal data is involved, and for U.S. listeners map the same hard lessons to Stop Ransomware guidance. The episode turns policy into action — keep protected copies, separate backup admin access, document recovery priorities, and most importantly, test restores so that belief becomes evidence. Bradford dismantles cloud complacency with a sharp scene: Microsoft 365 or Google Workspace may keep a service running, but platform availability is not the same as your ability to recover a deleted or compromised dataset. That gap is where assumptions die — and where attackers exploit your good intentions. The heart of the episode is a series of hard questions that force organisations out of warm thinking and into recovery planning: what systems must be back by lunchtime, who declares the incident, who calls the insurer, how do you contact staff and customers if email is gone, and where are the credentials if your password manager is offline? Each question is a beat in the story, a test of whether a business has a plan or just hope. By the end, the message is plain and urgent: buy recovery, not reassurance. Test restores, document processes, define Recovery Time and Point Objectives in plain English, protect copies from deletion, and rehearse the incident playbook until the drama becomes boring. The episode closes like a scene change — make recovery ordinary now, before attackers make it dramatic.

Curiosity Is a Cybersecurity Control: The Cheapest Defense You're Ignoring

Curiosity Is a Cybersecurity Control: The Cheapest Defense You're Ignoring

Cybersecurity Guide — Noel Bradford takes you inside a familiar office on an ordinary afternoon, where the threat isn’t a dramatic breach but the quiet, avoidable moment someone decided not to ask a question. This episode treats curiosity as a defence: not a flashy tool or dashboard, but the simple act of saying, "hang on, that looks wrong," and the cultural choices that kill it. Through vivid, everyday examples — the receptionist who spots a strange supplier request, the apprentice surprised by an overseas sign-in prompt, the accounts clerk seeing a slightly altered bank account — Noel shows how small hesitations can be the thin line between routine work and an expensive compromise. He explains why cyber criminals prefer polite, rushed offices and how well-meaning efficiency often becomes a buffet for fraud. This is part cautionary tale and part playbook. Noel explores how organisations teach the right words — report scams, protect accounts, patch systems — but then reward speed over sense, punish false alarms, and make reporting cumbersome. The result: curiosity is trained out of people, and the last reasonable question is smothered by eye rolls and impatience. Actionable changes are surprisingly simple. Make reporting take ten seconds. Praise the person who raises a false alarm. Add a mandatory pause and callback verification for supplier bank changes. Make senior leaders follow the same rules as everyone else. Treat reports as signals to be measured and celebrated, not interruptions to be tolerated. Noel reminds listeners that curiosity doesn’t replace MFA, patching, backups or email security — tools matter — but people catch what automated controls miss. He argues that a culture that protects and rewards questioning is the most cost‑effective control a small business can buy: priceless, free, and often ignored. By the end of the episode you’ll hear a clear, one‑sentence improvement managers can make today: if something looks wrong, stop and ask. That sentence costs nothing, irritates bad managers, and may save thousands. This is a rallying call to treat curiosity as a measurable, defendable security control and to build workplaces where asking a sane question is always the right move.

Your CCTV Is Listening: The Cameras You Forgot Are a Cyber Problem

Your CCTV Is Listening: The Cameras You Forgot Are a Cyber Problem

I’m Noel Bradford and this episode opens with a simple, unsettling image: a little black NVR humming away since 2017 like a haunted toaster with network access. That hum is not background noise — it’s the beginning of a story about negligence, default settings and the strange ways everyday devices turn into windows into your business. We follow a typical small-business scene: an installer fits cameras, the mobile app works, the owner checks the yard from home and everyone breathes easy. Then five years pass. Broadband changes, the person who knew the password leaves, firmware becomes ancient and, because nobody asked the grown-up question, some cameras are quietly recording sound. The feature was on by default. The question was never asked: why are we recording audio? The episode traces how that missed question multiplies into risk. Cameras and recorders aren’t just bolt-and-forget hardware; they’re networked computers with IP addresses, admin portals, cloud relays and user accounts. Left unmanaged, they sit on the same flat network as payroll, tills and file servers and become tempting footholds for attackers who don’t care about your business — they care about what’s exposed. Through vivid, practical examples, we show how an attacker doesn’t need your footage — they need the position. Pivoting, harvesting credentials, persistence, or using that device as infrastructure are all within reach when devices lack ownership, patches and sensible access controls. And if audio is enabled, suddenly the risk is also a privacy problem: staff conversations, sensitive customer details and whispered passwords can turn up on a clip nobody intended to exist. But this isn’t meant to spark panic. It’s a call for grown-up management. We walk listeners through the steps that change risk into control: find the devices, walk the site, inventory every camera, NVR and smart gadget; document owners, network segment and audio capability; segment networks so devices don’t talk to everything; replace default accounts with unique credentials and MFA; patch or plan replacements for unsupported kit; and, crucially, decide and document whether audio should be enabled — not leave it to a wizard’s default. Along the way we paint the human moments — the frustrated owner, the installer who moved on, the staff member who keeps a camera app on their phone — to make the technical problems feel immediate and solvable. By the end of the episode listeners will understand that cameras bolted to walls are part of the attack surface, microphones double that risk, and the single most powerful question in cybersecurity is simple: who owns this thing? This episode is practical, candid and aimed at small businesses that think their CCTV is just facilities kit. Treat your cameras like computers, treat microphones like privacy, and start fixing the things you’ve forgotten. Start with a walk round, a list, and someone who is responsible — it’s dull, but dull beats emergency meetings with the emotional temperature of a bin fire.

The Coffee Shop Myth — How Identity, Not Wi‑Fi, Lets Attackers In
Ep. 42

The Coffee Shop Myth — How Identity, Not Wi‑Fi, Lets Attackers In

Noel Bradford rips into the cyber marketing circus and pulls back the curtain on the real threat modern businesses are ignoring. He opens with a laugh — and a damning image: a hip vegan coffee shop, oat milk lattes, a creator’s scare-ad for a VPN, and an affiliate link. It’s funny until you realise the joke’s on us. In 2014 we defended the network; in 2026 attackers simply walk through the front door by stealing identity. This episode traces that evolution like a detective story. Noel shows how HTTPS, smarter phones, and better browsers made old fears obsolete, while criminals moved upstream into session hijacking, OAuth abuse, and adversary‑in‑the‑middle phishing that steals tokens after MFA succeeds. He paints scenes that stick — the tired traveller connecting to an almost‑right SSID at an airport, the finance director approving payroll from an unmanaged iPhone — and explains why those moments matter far more than a packet sniffed over biscotti. Through vivid anecdotes and no‑nonsense analysis, Noel lays out what small businesses actually face: mobile devices that are portable identity containers, brittle MFA habits, and session tokens that act like keys to the castle. Then he flips to solutions that aren’t clickbait: shorten token lifetimes, move privileged users to phishing‑resistant MFA and passkeys, enforce device compliance and mobile device management, revoke sessions aggressively, and treat personal phones like the powerful admin tools they are — not accessories. Part rant, part roadmap, the episode gives you the sharp, practical perspective you need to stop worrying about ghosts in coffee shops and start defending what matters: trust, sessions, and the identity stack. Tune in for hard truths, clear steps you can act on, and the kind of hot take that actually helps you protect your business before the next breach arrives.

Square-Wheeled Security: Inside a Vendor Meeting That Failed Small Business

Square-Wheeled Security: Inside a Vendor Meeting That Failed Small Business

The call starts like any other—slides, a sales voice, a tidy monthly price—and then it goes sideways. Noel Bradford walks listeners into a vendor meeting that feels less like a sales pitch and more like a cautionary tale: a shiny cyber bundle advertised to small businesses, but missing the muscle when real danger arrives. Against the hum of corporate growth statistics and glowing dashboards, Noel spots the cracks that too many packages hide. He pulls back the curtain on the industry’s boom—2,603 active firms, rising revenues, an army of portals—and shows how that growth can multiply confusion rather than protection. The narrative tightens around a single, telling moment: a product called out for what it is, and a sales rep who shuts the deck when asked the uncomfortable but essential question—what does incident response actually mean? Through sharp, conversational storytelling, Noel illustrates the difference between a list of features and real incident ownership. Dark web scanning, phishing simulations, insurance—each sounds useful, but each can become a dangerous reassurance without the people, process, and authority to act when the alarm sounds. The episode makes the cost of misunderstanding painfully real: £25 a month promises comfort but may leave a business exposed when response work—legal coordination, evidence preservation, communications and technical recovery—becomes urgent and expensive. Listeners are led scene by scene through the meeting: the casual assumptions, the defensive sales pivot, the moment the vendor chooses convenience over clarity. Noel’s voice threads in professional hard-won detail about what proper incident response entails—triage, containment, insurer liaison, decision logging—and why those things are not optional extras hidden behind a portal. Finally, the episode becomes a rallying cry for both buyers and sellers. Small business owners get a checklist of the blunt, necessary questions to ask before they buy a bundle. Vendors are challenged to stop masking light services with heavy language. The story closes on a clear, practical warning: cyber sold like broadband builds a stronger case for doing nothing, and attackers are patient. Engaging, candid, and sharply observant, this episode of Small Business Cybersecurity Guy gives you the scene, the stakes, and the straight talk you need to see past slick packaging—because when your business is on fire, you don’t want a signpost, you want someone who owns the incident.

When the Authenticator Stops Being a Shield: CVE‑2026‑41615 Exposed

When the Authenticator Stops Being a Shield: CVE‑2026‑41615 Exposed

I'm Noel Bradford, and today the app millions of us told our users to trust has just become the story. Microsoft Authenticator — the little green tick that used to mean 'you’re safe' — has a flaw: CVE-2026-41615. It sounds like a dry line on a vulnerability list, but the reality is cinematic. An app on a phone, a single tap, and a service can be tricked into handing an attacker the very token that proves you are who you say you are. That’s not an academic problem; that’s an open door to email, Teams, SharePoint, OneDrive, finance systems and the privileged keys that run your business. Picture tokens as wristbands at a festival: once you’ve got one, you don’t queue for every stall. Great for productivity. Terrible if a thief pinches it. This flaw is an information disclosure — but the information being disclosed is an access token. An attacker still needs to trick a human into approving a legitimate-looking request, but humans are busy, distracted, and persuasive social engineers know it. ‘Requires user interaction’ is not the same as ‘hard to exploit.’ The scandal isn’t that Microsoft shipped a bug — all software has bugs. The scandal is how many organisations built their identity on an app they do not inventory, version-check, or treat as critical infrastructure. Automatic updates, wishful thinking, and an unmonitored fleet of personal phones are not a security strategy. The fix exists: updated versions (Android: 6.2605.2973+, iOS: 6.847+). The harder work is knowing who has those versions and who doesn’t. This episode walks you through what actually matters: identify which users — especially privileged ones — are exposed; push or instruct updates; verify versions; review sign-in logs; and consider revoking sessions and tightening conditional access after patching. Patching closes the door, but tokens may linger. That’s why you must treat sessions, tokens and admin accounts as living assets that need governance, not artifacts you paid once for and then hoped would behave. I’ll cut through the CVSS score arguments and the analyst chatter. Whether some lists call it critical or high, the business question is simple: can a work account token be exposed after user interaction? Yes. Is Microsoft Authenticator part of the trust chain for your cloud identity? Yes. Do many small businesses rely on it without visibility? Also yes. The answer to all three is enough to move from complacency to action. By the end of this episode you’ll understand the attack in plain English, what to check first (privileged accounts, device management, update versions), and the practical steps your MSP or in-house IT must take today. This is not fear-selling; it’s a call for grown-up identity hygiene. MFA remains essential — but it isn’t magic. Treat the app as software, the token as a valuable asset, and your identity controls as infrastructure that must be governed. Update the app. Verify the versions. Review tokens and sessions. Move high‑privilege users toward phishing‑resistant authentication. Don’t assume automatic updates are proof. Turn the green tick back into an engineered assurance, not a poster on the wall. This episode is a wake-up call for anyone who thought ticking the MFA box was the end of the story.

When Cybercrime Became a Business: IOCTA 2026 Exposes the Machine
Ep. 41

When Cybercrime Became a Business: IOCTA 2026 Exposes the Machine

Listen as Noel Bradford — the Small Business Cyber Security Guy — pulls back the curtain on a criminal economy that looks eerily like a legitimate market. The story begins not with a hooded hacker in a basement but with supply chains, service desks, affiliate margins and racks of phones pretending to be people: an industrialised machine that Europol lays bare in IOCTA 2026. Imagine a landlord who rents lockups to burglars and never asks why everyone arrives at 3am. Now imagine that landlord runs a global network of proxies, bulletproof hosting and sim farms that let criminals create millions of fake accounts, receive one-time codes and vanish with the money. Noel walks you through that rack of 40,000 SIMs and the jaw-dropping scale — 49 million accounts created — and shows how criminal services chain together into a repeatable, low-cost supply model. He tells the story of the modern ransomware franchise: not a lone crew but brands, affiliate programs and negotiation services, with some gangs offering affiliates 80–85% of ransoms. This isn’t cinematic drama — it’s commercial logic. Criminals buy speed, scale and plausible deniability; law enforcement chases the velocity gap. AI writes the scams, proxies hide the origin, crypto moves the money, and encrypted platforms slow evidence gathering. The result: a faster, stealthier, more connected threat. Noel’s narrative turns the Europol report into a mirror for small businesses. It’s not just about technical fixes — it’s about whether the products and certificates you buy actually match the way crime now works. He uses vivid examples (sim farms, DNS abuse, data-leak extortion) to make one blunt point: a backup is crucial, but it doesn’t unsend stolen customer lists or unpublish payroll files. Your recovery plan must cover communications, legal, insurers and reputational damage — not only server restore points. Through sharp, practical storytelling Noel gives you three immediate actions small businesses can do this week: email your IT supplier and ask if they’ve read IOCTA 2026, audit every SMS-based workflow that handles money or identity, and rethink your ransomware plan around stolen data being published. He frames these as homework, not panic — small, urgent steps that cut through vendor theatre and certificate-shaped comfort. By the end of the episode you’ll see the threat differently: no longer isolated buckets of ransomware or fraud but a joined-up criminal economy exploiting weak identity, cheap infrastructure and slow institutional response. Noel doesn’t just warn you — he shows you how to start fixing it, with plain questions to suppliers and concrete checks you can run in a day. This is a wake-up call dressed as a podcast episode: direct, unflinching and built to move small businesses from complacency to grown-up risk management.

We Got the Cyber Headline Wrong: The 43% That Isn’t What It Seems
Ep. 40

We Got the Cyber Headline Wrong: The 43% That Isn’t What It Seems

The 43% Cyber Attack Statistic: Are We Being Sold Fear? Every spring, the UK government drops a cyber statistic that makes headlines, fills vendor slide decks, and gives nervous business owners another reason to stare bleakly into their coffee. The claim? Around 43% of UK businesses suffered a cyber breach or attack last year. Sounds terrifying, doesn’t it? Except there is a problem. A bloody big one. The methodology counts phishing emails as breaches even when nobody clicked, nobody engaged, and nothing happened. In other words, your business could block thousands of dodgy emails, suffer no damage, lose no money, and still get swept into the headline figure. Buried deeper in the same government report is a far more useful number. In this episode, the team pulls apart ten years of survey data and asks an uncomfortable question: who benefits when cyber risk gets inflated? Government comms teams get a stronger headline. Vendors get better scare copy. Compliance theatre gets another curtain call. Meanwhile, small businesses are left wondering whether they are genuinely at risk or just being sold another steaming plate of fear. We also admit something important. We fell for the 43% number ourselves two weeks ago. So this episode is not just a takedown. It is a correction. What should a 20 person business actually do with this information? Ignore cyber risk? Absolutely not. Panic buy another shiny security product because someone waved a big scary percentage at you? Also no. The answer sits somewhere far more useful: understand the real risk, ask better questions, spend money where it matters, and stop letting fear based marketing write your security strategy. Links Department for Science, Innovation and Technology Cyber Security Breaches Survey 2026 Office for Statistics Regulation Office for National Statistics Home Office Computer Misuse Act 1990 FBI IC3 Annual Reports NCSC Cyber Essentials Overview

Private Life on Display: How Endpoint Compromise Exposed a Celebrity

Private Life on Display: How Endpoint Compromise Exposed a Celebrity

The Celebrity Stalkerware Leak: Not Encryption, Endpoint Compromise In late April 2026, headlines screamed about 86,000 private screenshots leaked from a prominent European celebrity's phone. The story dominated tech press coverage, but crucial context went missing. This was not hackers breaking encryption or sophisticated cyber warfare. It was endpoint compromise: stalkerware capturing screenshots directly from a device after messages had already been decrypted on screen. The database, allegedly linked to the collapsed Cocospy spyware ecosystem, contained WhatsApp chats, Instagram activity, invoices, intimate images and more. Whilst the core reporting appears sound, the framing obscured important truths. A VPN would not have stopped this attack. Encrypted messaging apps could not protect against malware already installed locally. And beneath the sensational headlines lies a grim pattern: commercial spyware marketed as parental monitoring or employee oversight, repeatedly exposed in breaches that reveal its real use in coercive control and domestic abuse. This episode unpacks what actually happened, why the technical details matter, and why we need to stop calling this surveillance software anything other than what it is. Chapters Intro Noel introduces the celebrity stalkerware leak story from April 2026, cutting through sensational headlines to frame what this incident actually was: endpoint compromise, not encryption failure. What The Story Claimed Breaking down the original ExpressVPN report by researcher Jeremiah Fowler, which detailed 86,859 screenshots from a celebrity's device, including encrypted app content, intimate images and personal data. This Was Not Breaking Encryption Clarifying the critical technical misunderstanding: the spyware did not crack WhatsApp or Signal encryption. It simply captured screenshots after messages were already decrypted and displayed on screen. The Cocospy Bit Unpacking the Cocospy connection. The spyware ecosystem collapsed in 2025 after a massive breach, but leftover infrastructure appears linked to this incident, which targeted one victim rather than millions. The VPN Problem Addressing the uncomfortable commercial context: the story appeared on ExpressVPN's blog, yet a VPN would not have prevented this attack. Transparency and vendor-owned media ecosystems matter in security reporting. The Bigger Issue Nobody Talks About The depressing normalisation of stalkerware. Marketed as parental monitoring, these tools repeatedly surface in breaches exposing their use in coercive control and domestic abuse, not legitimate oversight. Outro Final verdict: the core story appears accurate, but framing matters. This was endpoint compromise, not encryption failure. And the industry should stop euphemising commercial spyware designed for abuse. Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

Yellowkey Exposed: Why BitLocker 'On' Isn't Enough

Yellowkey Exposed: Why BitLocker 'On' Isn't Enough

Noel Bradford delivers a direct examination of YellowKey, the reported BitLocker bypass that exploits the Windows Recovery Environment on TPM-only configurations. This episode strips away vendor comfort narratives and green-tick dashboards to focus on what default encryption settings actually protect against when a laptop is stolen or accessed physically. He explains how YellowKey targets trusted recovery paths rather than breaking encryption mathematics, why TPM-only BitLocker represents a convenience trade-off rather than maximum assurance, and how businesses confuse enabled controls with proven protection. The episode provides practical guidance on identifying high-risk devices, reviewing BitLocker protectors, implementing TPM plus PIN where appropriate, locking firmware settings, restricting USB storage, and properly escrowing recovery keys. The episode argues that physical access remains a normal business risk through stolen laptops, lost devices, and compromised bags, not merely a theoretical attack scenario. The episode challenges boards and decision-makers to move beyond checkbox assurance and ask what their laptop security actually proves under adversarial conditions.

Monopoly, Neglect and a Near‑Million Pound Fine: Lessons from South Staffordshire Water

Monopoly, Neglect and a Near‑Million Pound Fine: Lessons from South Staffordshire Water

They said the fine was £828,000 in some headlines — the ICO said £963,900. Numbers matter, but the real scandal is deeper than a headline figure: this is about trust, monopoly, and a regulator that finally acted. In this episode the Small Business Cybersecurity Guide tells the story of how a single phishing email in September 2020 became a twenty‑month lodger inside a utility network, and how a monopoly provider of an essential service left hundreds of thousands of people exposed. It starts small: a malicious attachment, a foothold, then complacency. For almost two years the attacker lived in the estate, quiet and unseen, until May 2022 when they began a methodical campaign of lateral movement and privilege escalation. By July they held domain administrator access — the keys to the kingdom. They weren’t stealthy ninjas; they were guests who moved in, opened the cupboards, and helped themselves. Detection? Not artisanal monitoring or heroic threat hunting. It was system performance degradation — the IT equivalent of noticing the house is on fire because the TV has melted. The compromise produced a failed ransom demand and, eventually, a dump of more than four terabytes of stolen data on the dark web: names, addresses, emails, dates of birth, phone numbers, account details, bank sort codes, service credentials and even information that could infer disability status for priority customers. 633,887 UK people were affected. The ICO’s findings are the part that should make every director and IT lead sit up. This wasn’t a story of exotic attack techniques — it was a catalogue of basic control failures: outdated software (Windows Server 2003 in a live environment), inadequate logging and monitoring, weak vulnerability management, no meaningful scans for long periods, and a third‑party SOC only watching 5% of the estate. That is not coverage; it’s a comfort blanket. Hear the frustration and the anger: when customers can’t vote with their feet, protecting their data isn’t optional. This episode pushes past corporate press releases and settlements to ask what really matters — the people. What does this exposure mean for vulnerable customers, staff, and anyone who trusted a critical service provider to keep their information safe? Then the episode turns outward with hard lessons every organisation must learn. Know your estate — you cannot protect what you cannot see. Retire legacy systems properly. Enforce least privilege so domain admin access is exceptional, not daily. Monitor the entire environment, not a token slice. Scan, patch, remediate. Test your incident response and your communications before chaos forces you to explain to frightened customers what happened to their data. Above all, this is a governance failure. Cybersecurity isn’t just an IT problem or a checkbox for audit season — it’s board‑level risk management. The board must own the risk, demand evidence, and stop hiding behind vendor portals and PDFs that mean nothing in a crisis. The episode pulls no punches: if you haven’t modelled the cost of a breach, you’ve found the root problem. The ICO finally acted — good. But the real question the episode leaves listeners with is uncomfortable and direct: if the regulator walked into your business tomorrow, what could you actually prove? This is a wake‑up call to utilities, regulated sectors and every UK business. Basic controls, evidence, and leadership matter. If you wait for criminals, regulators or journalists to force the issue, you’ll have bought a public kicking on credit. Listen as the Small Business Cybersecurity Guide blends forensic detail, sharp critique and practical advice to turn a headline into a blueprint: how to stop being the next story. — Noel Bradford

Patch Tuesday May 2026 — 4 Fixes That Matter to Every UK Small Business
Ep. 39

Patch Tuesday May 2026 — 4 Fixes That Matter to Every UK Small Business

It’s that time of the month: Patch Tuesday. The headlines shout 137 CVEs and a perfect 10.0 somewhere in the noise, but this episode narrows the story down from global panic to what actually matters for a small business with a server room, a handful of laptops, and a CEO who needs to log in on Monday morning. I’m Graham Falkner and in this edition of the Small Business Cyber Security Guy I walk you into the trenches of May 2026’s update cycle — the numbers, the new role AI is playing in vulnerability hunting, and the four bugs you can’t ignore. I tell the story of how an unpatched domain controller can become the pivot point for a full-blown takeover (think Zero Logon’s ghost), why every Windows endpoint’s DNS client suddenly matters again, and how an Atlassian single sign‑on plugin could let an attacker impersonate any user. These aren’t abstract CVEs on a spreadsheet; they’re concrete threats with reachable fixes. You’ll hear exactly what to do, in the order to do it: find and patch on‑prem domain controllers in the next 48 hours (NetLogon — CVE‑2026‑41089, KBs by Windows Server version), push a small test ring for endpoint updates and watch for BitLocker recovery prompts (CVE‑2026‑41096), and treat on‑prem Dynamics 365 and Atlassian SSO as high‑priority if you run them locally. I give the KB numbers, realistic time estimates — an hour per domain controller — and a no‑hype deployment schedule that keeps your business running while you secure it. The narrative also walks through an operational snag that will catch teams off guard: some devices may prompt for a BitLocker recovery key after reboot. I explain the three pre‑deployment checks to prevent a CEO‑level outage (adjust a TPM group policy, verify where recovery keys live, and reapply baselines later), and why you should demand a plan from your MSP before they push updates. Along the way I bust headlines that distract — the CVE‑2026‑42826 “Perfect 10” in Azure DevOps is already mitigated by Microsoft, so there’s no customer action — and remind you that other vendors patched too: Adobe, SAP, AMD, Apple. Patch week is not a one‑vendor event. By the end of the episode you’ll have a simple, prioritized checklist you can act on this week: identify DCs and patch them now, test endpoints tomorrow, roll out by week’s end, and verify Atlassian plugins separately. This is a story about practical choices under pressure — stop chasing every headline and start fixing what can actually hurt your business.

When Germany's .de Went Missing: A DNSSEC Fable of One Bad Signature

When Germany's .de Went Missing: A DNSSEC Fable of One Bad Signature

How a Broken DNSSEC Signature Knocked Out .de Sites One bad signature. Millions of websites. Gone. On 5 May 2026, Germany's .de domain vanished from the internet for three hours. Amazon.de, Deutsche Bahn, Spiegel, DHL, major banks: all unreachable. Not hacked. Not ransomwared. One broken cryptographic record from the registry that manages 17.9 million domains. The servers were perfectly healthy. Nobody could find them. Corrine Jefferson and Graham Falkner break down what went wrong, why your business has the exact same invisible dependency, and what to do about it. Read the full analysis: How a Broken DNSSEC Signature Knocked Out .de Sites

Chrome's Hidden AI: The 4GB Surprise Eating Your Disk and Bandwidth
Ep. 38

Chrome's Hidden AI: The 4GB Surprise Eating Your Disk and Bandwidth

Hot Take: Google Chrome, Gemini Nano, and the 4 GB Consent Problem Show Notes Google Chrome has been quietly downloading a roughly 4 GB AI model called Gemini Nano onto user devices in the background. No clear consent prompt. No notification. Just a file called weights.bin turning up in a folder called OptGuideOnDeviceModel like it pays the mortgage. In this Hot Take, Noel breaks down why this is not an "AI is evil" story. It is a consent story. A governance story. And a vendor entitlement story that every UK small business needs to take seriously. What Noel Covers Why a 4 GB background download is not a minor browser update What Google's own developer documentation confirms about model lifecycle management, background downloads, and full model updates Why "it was in the documentation" is not consent The governance mess this creates for managed business devices PECR and the ICO's guidance on storage and access technologies The environmental cost at Chrome scale (67.97% worldwide browser share) Why AI Mode in Chrome and on-device Gemini Nano are not the same thing, and why the confusion matters The embarrassingly simple fix Google has not implemented What UK small businesses should actually do about it right now Key Quote "We have somehow built frontier AI and still can't manage the radical engineering challenge of a bloody consent prompt." Read the Full Analysis The full article includes the complete source documentation, PECR regulatory detail, competitive advantage strategies, board-level talking points, and a step-by-step action list for UK small businesses. Read the full article on the blog Sources Referenced All 14 primary sources, including Google's own developer documentation, ICO PECR guidance, and StatCounter market share data, are cited in the full blog post. Full source table in the article

Why 43% of UK Businesses Got Hit — and Why the Basics Let Them Down
Ep. 37

Why 43% of UK Businesses Got Hit — and Why the Basics Let Them Down

Imagine watching the house next door burn and nodding sympathetically about smoke alarms — then never changing the battery in your own. That image opens our episode as Noel Bradford sits with Mauven MacLeod, Lucy Harper and Graham Falkner to unpack the UK Cybersecurity Breaches Survey 2025–26. This isn’t clickbait panic; it’s a weather report built from 2,112 businesses and 1,085 charities. The headline is simple and ugly: awareness rose after a year of big breaches on the news, but the boring, decisive basics slipped backwards. The numbers feel like a betrayal: risk assessments fell from 48% to 41%, formal cybersecurity policies from 59% to 52%, and business continuity plans covering cyber plunged from 53% to 44% — nine points lost in a year. Those figures land harder when you remember that 43% of businesses still reported a breach or attack in the last 12 months. This is not rare misfortune; it’s roughly 612,000 organisations experiencing harm, often more than once — the median victim suffered three crimes in a year. What explains the gap between knowing and doing? The episode frames it as a human story of overload, inertia and the tilt of daily fires over preventative work. Small-business owners juggle payroll, inventory and phone calls; cyber becomes a preventative chore that slides down the to-do list until a miserable Tuesday forces theatre rather than true repair. Awareness rose because the news was loud; conversion into diaries, policies and tested routines didn’t. Phishing is still the thief in the night: 69% of the most disruptive incidents, and for 51% of breached businesses phishing alone was the culprit. The old advice — spot the typos, spot the scam — is breaking down as AI writes believable bait. The human being is no longer the reliable last line. So the fight shifts to identity: two-factor authentication and other account protections stop one mistake becoming total catastrophe. Progress exists — MFA adoption climbed from 40% to 47% — but more than half of firms remain exposed. The survey throws up other startling blindspots: 22% of the most senior people responsible for cyber didn’t know if their organisation had cyber insurance; only 15% formally review immediate suppliers and a tiny 6% review the wider supply chain; 31% of businesses are using or considering AI but only 24% of those have any controls in place. These are not theoretical gaps — they are the plumbing and the paperwork that determine whether a single clicked link turns into a multi-week catastrophe. We refuse to finish on gloom. The episode turns evidence into a razor-sharp, do-able checklist you can act on this week. Five prioritised moves: turn on MFA everywhere that matters; get your cyber insurance confirmed in writing and save the policy where two people can find it; write a one-page breach list with names and first actions; institute three simple AI rules (don’t paste customer data into public tools, don’t feed contracts or financials into unknown models, and always human-check AI outputs before sending); and review the three suppliers who can touch your systems or customer data. There’s also practical advice on when to DIY and when to pay. If you’re tiny and organised, you can implement the basics yourself. If your Microsoft tenancy, sensitive customer data, or backups are beyond your comfort, pay for competence — spend where mistakes are expensive. The point of each suggestion is the same: decisions, dated and tested, beat good intentions left on the sofa. By the episode’s close Noel, Mauven, Lucy and Graham press the same ask: turn concern into calendar time. Pick one thing this week — MFA, insurance confirmation, a breach list, supplier questions or simple AI rules — and do it. These are small, affordable, and powerful first steps. The survey’s verdict is harsh but useful: the fixes are often obvious. The hard part is choosing to stop drifting. Listen for the stories, the statistics and the practical push to act. If this episode rattles you, let it. Drift kills small firms. One decision, one scheduled action, can change the story from a miserable Tuesday to a business that survives the next headline.

167 CVEs and Counting: Patch Tuesday Throws the Kitchen Sink
Ep. 36

167 CVEs and Counting: Patch Tuesday Throws the Kitchen Sink

167 vulnerabilities. Two zero-days. One already used in live attacks. Graham Falkner breaks down April's Patch Tuesday and what your business needs to do today — in under 10 minutes.   For full show notes etc: see https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-april-2026-sharepoint-zero-day-uk-smb/

From Tokens to Copilot: Fixing the Gaps in Your Microsoft 365 Defenses
Ep. 35

From Tokens to Copilot: Fixing the Gaps in Your Microsoft 365 Defenses

They said they were secure because they’d turned on Microsoft 365 and MFA. That should have been the end of the conversation — except it wasn’t. In this episode we follow a small-business sagawhere confidence meets complacency: a tidy subscription, a proud admin ticked off in the dashboard, and then a perfectly ordinary Tuesday when the finance inbox receives a believable invoice and the lights go out on the company bank balance. This is not a movie heist; it’s bureaucratic sabotage — dull, precise, and devastating. We pull the curtain back on how attackers pick the quietest path: mailbox rules that hide replies, forgotten connectors that bypass protections, OAuth prompts that invite parasites in, and session tokens that act like stolen wristbands. We show how MFA, while invaluable, is only one plank in a creaky bridge — and how adversary‑in‑the‑middle phishing, device‑code tricks, and consent abuse let threat actors walk straight across it. Through vivid examples — a supplier invoice quietly altered, a payroll request that arrives at just the wrong time, an attacker living in a thread already trusted by your staff — the episode explains why ordinary-looking messages are the most lethal. We interview the patterns, the tiny settings that become permanent vulnerabilities, and the human moments where haste replaces verification. The drama is mundane; the impact is not. We also look at the shiny things: Copilot and other productivity tools that can amplify both good work and a breach. If your permissions are messy, Copilot becomes a supercharged searchlight for attackers. If your tenant is tidy, it’s a time-saver. The story shows how the same feature can be helpful or harmful depending on the housekeeping behind it. Finally, we turn tension into action with a clear, practical plan: check DMARC, hunt for forwarding rules, revoke suspicious app consents, remove unnecessary admins, and insist on a second verification channel for any money-moving requests. The episode closes with a simple promise — you do not need a fortress on a sandwich budget, you need fewer stupid gaps, better checks, and a bit more suspicion. Listen to this as a warning, a how‑to, and a Monday‑morning checklist for making your business noisier to attackers and faster to respond when things go wrong.

March 2026 Patch Tuesday — Take It or Stay Vulnerable

March 2026 Patch Tuesday — Take It or Stay Vulnerable

Listen in as the Small Business Cybersecurity Guy rips through March 2026 Patch Tuesday like a mechanic with a torque wrench: blunt, precise, and impossible to ignore. This episode opens on a single, brutal premise — Windows updates are not a choose‑your‑own‑adventure. They are binary. You either deploy the cumulative payload or you leave every unpatched edge of your estate like a neon target for attackers. The stakes aren’t fireworks; they’re the slow, quiet escalation chains attackers use after a single phishing click. We trace the real playbook attackers follow: step one, land as an ordinary user; step two, chain an Elevation of Privilege. This month Microsoft shipped six EOP fixes — graphics, kernel twice, accessibility, SMB, and WinLogon — and slapped them with "exploitation more likely." In plain English, these are the exact plumbing pieces an intruder needs to turn a compromised laptop or RDS session into full environment control. You’ll hear why delaying the patch is an active, informed choice to leave those doors open. Then the narrative sharpens into a thriller: Copilot in Excel. A critical CVE that reads like a very small script with an outsized punch — a near‑zero‑click XSS‑style flaw that can make Copilot agent mode obediently hand over internal secrets. Picture your finance lead or CEO, spreadsheets and Copilot live, and a crafted workbook quietly acting as an insider. No macros, no drama — just a nudge that sends data where it shouldn’t. The episode makes the risk vivid and personal, not academic. We also unpack two more critical Office RCEs via the preview pane — the sort of everyday behavior (previewing mail, browsing SharePoint) that real people do all day. Microsoft says exploitation is less likely, but only if you’re patched. The episode forces you to confront the gap between marketing calm and the real-world tradeoffs IT teams make when budgets and reboot windows collide with executive convenience. Finally, the show gives you a short, brutal checklist — what to do this week if you run a small business or juggle multiple clients: verify actual build numbers, identify who has Copilot agent mode, sanity‑check DLP and egress for AI tools, and roll in third‑party updates like Acrobat alongside Office and Windows. It’s not a six‑month project; it’s triage and discipline. The narration is urgent but practical, a call to action delivered with the weary authority of someone who’s patched one too many servers at 2 a.m. Tune in for a tight, no‑fluff ride through what looks quiet on the surface but is dangerously loud under it — because the difference between a quiet month and a disaster is how long you choose to stay vulnerable. Hit the blog for scripts, guides, and the deeper dive promised at the end of the episode.

They're Not 'Hacking' — They're Logging In: The Dangerous Myth Small Businesses Fall For

They're Not 'Hacking' — They're Logging In: The Dangerous Myth Small Businesses Fall For

Imagine an attacker not as a hoodie-wearing wizard wrestling with your firewall, but as someone quietly slipping through an unlocked back door with keys they bought on the dark web. In this episode we sit down with Corrine Jefferson, a former government cyber professional who now helps UK small businesses understand how real attackers operate. Grounded in Palo Alto Networks Unit 42's Global Incident Response Report 2026, our conversation is built on more than 750 serious, real-world investigations from October 2024 to September 2025. Not theory. Not vendor marketing. Actual cases. The numbers are stark: identity weaknesses featured in nearly 90% of incidents, and 65% of all initial access was identity-driven. We start by setting the scene: your people live in the browser. Outlook, payroll, Teams, your CRM, and a pile of SaaS tools. That ordinary click is the battleground. Attackers buy credentials, harvest session tokens, and exploit OAuth grants. Once they have a valid login, they blend into normal traffic and move silently. Corrine brings these statistics to life with vivid examples of reused passwords, push-MFA fatigue, shared admin accounts, and contractors who still have permanent access three years after leaving. The stakes are immediate. Unit 42 found that the fastest quarter of intrusions reached data theft in just 72 minutes, down from 285 minutes the previous year. A simulated AI-assisted attack did it in 25 minutes. That means from one careless click to your customer data being packaged for extortion can happen faster than a cup of tea. This episode guides you away from romantic myths about firewalls and sophisticated exploits and toward the uncomfortable truth: most breaches are enabled by preventable exposure and excessive identity trust. We walk through the failure modes that make small businesses attractive targets: recycled passwords, MFA that's easy to social-engineer, standing global admin accounts, and forgotten integrations that act like zombie doors. Corrine explains why these aren't technical puzzles for nation-states. They are human, operational, and fixable. She also lays out how attackers exploit browser-based OAuth flows and session cookies to live off long-lived access without ever triggering an alert. This is not just a lecture. It is a plan. If you do one thing this quarter, make it identity. If you do one thing this week, do these three: deploy phishing-resistant MFA for admins and finance roles; remove or disable all ex-employee and contractor accounts across Microsoft 365, your VPN, and remote support tools; and cut standing admin rights while shortening session lifetimes on sensitive applications. By the end of the episode you will see the difference between spending on another perimeter box and actually locking the doors that matter. This is a call to action for small businesses: stop hoping you will not be targeted and start hardening the identities attackers are already using. Three Actions You Can Take This Week Action 1: Deploy Phishing-Resistant MFA What: FIDO2 hardware security keys or passkeys. Not SMS codes. Not basic push notifications. Where to start: Administrators, finance roles, and anyone with access to sensitive data or privileged systems. Why it matters: Standard push-based MFA is vulnerable to adversary-in-the-middle attacks and push-bombing. FIDO2 provides phishing resistance, guessing resistance, and theft resistance. NCSC guidance: FIDO2 is recommended by the NCSC as the strongest available MFA type for UK organisations. Hardware options include Authentrend, Keys, Platform options include Windows Hello for Business and Apple Touch ID. Action 2: Remove Zombie Access What to audit and disable: All accounts belonging to former employees All accounts belonging to former contractors Unused service accounts Dormant OAuth integrations and app permissions Where to look: Microsoft 365 Admin Centre, your VPN gateway, remote support tools, and any SaaS platform connected to your business. Why it matters: Unit 42 found that 99% of 680,000 cloud identities had excessive permissions, many unused for 60 days or more. Each one is an unlocked back door. How to find OAuth zombies: In Microsoft 365, go to Azure Active Directory > Enterprise Applications > All Applications. Sort by last sign-in date. Revoke anything unrecognised or unused. Action 3: Eliminate Standing Admin Rights What: Move from permanent administrator accounts to just-in-time (JIT) privilege elevation. How: Remove persistent administrator role grants Require time-bound elevation through Microsoft Entra Privileged Identity Management or equivalent Shorten session lifetimes on sensitive applications Enable strong logging on all privilege escalation events Why it matters: A compromised account with no standing privileges yields nothing. JIT elevation changes the attacker's calculation from "I have the keys" to "I have nothing." Sources and References     Source Resource Palo Alto Networks Unit 42 Global Incident Response Report 2026 (Full Report) Palo Alto Networks Unit 42 Global Incident Response Report 2026 (Executive Edition) Palo Alto Networks Unit 42 Global IR Report 2026: Blog Summary NCSC Multi-Factor Authentication for Your Corporate Online Services NCSC Recommended Types of MFA NCSC Authentication Methods: Choosing the Right Type NCSC Cyber Essentials Scheme Overview NCSC NCSC: Information for Small and Medium-Sized Organisations FIDO Alliance FIDO2: Web Authentication Standards MITRE ATT&CK T1219: Remote Access Tools (Referenced in Unit 42 C2 Data)   #CyberSecurity #SmallBusinessSecurity #IdentitySecurity #MFA #FIDO2 #Passkeys #UKBusiness #CyberEssentials #CyberSecurityPodcast #SecurityAwareness #TechPodcast #NoBS #SmallBizTech #CyberResilience #DirectorAccountability #BusinessRisk #DataProtection #GDPR #ZeroTrust #CloudSecurity #SaaSSecurity #IncidentResponse #ThreatIntelligence #IdentityManagement #SessionSecurity #Unit42 #PaloAltoNetworks #NCSC #CyberAware #UKCyber   Disclaimer This podcast provides general cybersecurity guidance based on publicly available research and industry best practices. It is not a substitute for professional security assessment or legal advice. Organisations should consult qualified security professionals and legal counsel to address their specific circumstances and regulatory requirements. All statistics cited from the Unit 42 Global Incident Response Report 2026, published by Palo Alto Networks, covering incident response engagements between 1 October 2024 and 30 September 2025. NCSC guidance referenced is published by the UK National Cyber Security Centre. All URLs verified at time of publication.

February 2026 Patch Tuesday: Six Actively Exploited Flaws — DWM Strikes Twice
Ep. 34

February 2026 Patch Tuesday: Six Actively Exploited Flaws — DWM Strikes Twice

Host Graham Falkner breaks down Microsoft’s February 2026 Patch Tuesday: more than 50 vulnerabilities across Windows and Microsoft 365, including six that were actively exploited before patches arrived. This episode explains which flaws matter, who’s affected, and the practical steps businesses should take immediately. Coverage includes the six confirmed actively exploited vulnerabilities (triple January’s count): three security‑feature bypasses that remove user protections (including a Word document bypass that is not triggered by Outlook preview), Desktop Window Manager (DWM) flaws that allow privilege escalation — and are being exploited for a second month — a Remote Desktop Services elevation issue found by CrowdStrike, and a Remote Access Connection Manager VPN crash vulnerability with a ready‑made exploit tool in criminal circulation. CISA has added all six to its known exploited list, with federal agencies required to patch by March 3. The episode also highlights developer‑focused risks: three serious GitHub Copilot flaws that let hidden malicious instructions run commands on a developer’s machine, and a 9.8‑severity flaw in Microsoft’s Azure Cloud Tools for Python. Faulkner explains why developers are high‑value targets and why organizations that build or buy software must prioritize these fixes. Other major items: January’s three out‑of‑band patches rolled into February’s cumulative update; Microsoft’s upcoming certificate updates that begin expiring from June (important for old or rarely‑connected hardware); SAP’s 26 security notes including a 9.9 remote‑command vulnerability and multiple high‑risk issues that can impact supply chains; Adobe’s 40+ fixes (27 critical), and updates from BeyondTrust, Ivanti, Cisco, Fortinet and others. Note: Google’s Android bulletin for February reported no security fixes. Special callouts: an Outlook vulnerability that can capture credentials just by previewing a crafted email in the reading pane (apply all related Outlook patches), and Microsoft’s gradual retirement of NTLM which may break legacy business apps unless you plan ahead. Actionable priorities and patch playbook: First wave (within 24 hours) — apply all six actively exploited fixes, the Azure Python tool patch for developer teams, and all Outlook fixes. Second wave (within 72 hours) — SAP (if you run it), Exchange Server, GitHub Copilot mitigations for developer teams, BeyondTrust remote‑support fixes. Third wave (within one week) — remaining SAP and Adobe updates, Cisco, Fortinet, and other important but not‑yet‑exploited updates. Faulkner stresses verifying deployment, testing remote desktop and Office workflows, and building patch management into incident response playbooks. Who should listen: IT managers, small business owners, developers, MSPs, and security teams responsible for patching and remote access. The episode gives clear, prioritized guidance to reduce exposure quickly and recommends sharing the full CVE tables and patch tiers with your IT team or managed service provider.   Find the Blog Post here: - https://noelbradford.squarespace.com/blog/patch-tuesday-february-2026-six-zero-days-uk-smb-guide-2026   podscan_adfmJQJllh7XQBrNPLHkG9va1aIn6VKo