The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU'LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

  1. 4 days ago

    Passkeys Aren't Dead — What a Week of Panic Taught Us About Risk

    Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions. First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had. Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings. These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow. We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes. Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords. By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.

  2. 3 Aug

    Meet Dave: From Gas‑Safe to Cyber‑Safe — A Small Business Survival Story (Part1)

    Three letters—G‑R‑C—sound like corporate nonsense until they stand between a business that survives a bad day and one that doesn’t. Pull up a stool: this episode meets Dave, who runs a 14‑person heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. He’s gas‑safe, insured, and obsessive about paperwork when lives are at stake. But his cybersecurity? That lives in his head, or a post‑it, or a notebook in a top drawer—and that’s the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster. We tell Dave’s story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules they’re given; the business fails when nobody decided what the rules were. Governance isn’t a committee or a legal brief—it’s four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplier’s—and the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday. This episode uses storytelling to make the abstract vivid: the harmless phrase “we’re too small for this” becomes a trap, the notebook of passwords becomes a ticking time bomb, and a one‑page decision becomes the difference between chaos and calm. You’ll hear practical scenes, not slides—how a named human owner, a handful of decisions, and a quarterly 10‑minute review turn security into something usable, not terrifying. By the end you’ll have three simple actions you can do this week: name the person who owns your security out loud; start your one‑page governance sheet; and set a recurring three‑month GRC reminder. Small, concrete moves that take minutes and protect years of work. If you’re a small business owner who thinks cyber is someone else’s problem, this episode is the wake‑up call delivered over a pint—friendly, practical, and impossible to ignore.

  3. 6 Jul

    The Open Book Problem 2: How Public Records Teach Criminals Your Name

    Imagine someone who knows your director's calendar, your payroll provider, the IT stack listed in your job ad, and the name of the accountant who signs your invoices. They don't have to be a genius — they just read what you and the public have already told them. In this episode, Noel Bradford follows that clean, quiet path of reconnaissance from public registers to a phone call that sounds unmistakably legitimate. We open on a simple truth: most social engineering isn’t a cartoon villain guessing passwords in the dark. It’s research, timing and pressure dressed up as plausibility. Noel and Corin map the attacker’s five-step journey — selection, mapping, pretext, delivery and pressure — and show how every ordinary piece of public information becomes a tile in a convincing story. Set against the uniquely open UK landscape of registries, data brokers and oversharing on professional networks, the episode becomes a procedural drama. You’ll hear how a director’s LinkedIn post about a conference can set the stage for an urgent Friday payment request, how job ads can hand an attacker the exact platform to fake, and how a single helpdesk script can be the thin crack through which a whole company falls. Through vivid examples — supplier impersonation, emergency MFA resets, Teams messages that replicate a boss’s tone — the episode explains why static verification checks fail and why ‘because the director said so’ is an invitation to fraud. We discuss Scattered Spider not to sensationalise, but to show how identity support processes become attack surfaces and why attackers treat due diligence like reconnaissance with ill intent. Noel moves from problem to practice: concrete defensive moves you can implement today — map your public exposure, write down verification rules, require independent checks on sensitive requests, train staff on pretext and pressure (not just typos and bad links), and treat your helpdesk as a security control. The advice is practical, procedural and, yes, a little boring — because that’s exactly what prevents crime. By the end you’ll see the small, human moments that make social engineering succeed — a rushed payment, a polite phone call, a culture that prizes speed over verification — and how changing those moments can take away an attacker’s easiest building blocks. Tune in to learn what an attacker would find about your business before lunch, and what you can remove before they get hungry.

  4. 29 Jun

    The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap

    They didn’t break in. They didn’t plant malware. They opened tabs, clicked links and joined the dots. In this episode we follow the quiet, methodical work of an attacker who builds a usable portrait of a UK small business director from nothing more than public records and a search box. It begins like a detective story and ends like a cautionary tale: Companies House entries, electoral data, LinkedIn posts, DNS records and job adverts become the clues that make fraud feel personal — because it is. Through the voices of Noel Bradford and Corrine Jefferson, the episode walks you through the attacker’s timeline: the first flick through Companies House to find directors and filing rhythms, the enrichment of that picture with open-register addresses and marketing data, the human-mapping on LinkedIn, and the technical fingerprint left in DNS, MX and certificate logs. Each step is ordinary, lawful and, crucially, assembled without a single hack. We make it concrete. In twenty minutes an attacker can produce a director profile, infer email providers, spot hiring signals that leak technology stacks, and spot behavioral seams to exploit. The lure is tailored; the language is familiar; the victim feels the email is meant for them. Social engineering stops being magic and becomes efficient administration with malicious intent — a repeatable, industrialized craft that preys on transparency. But this episode isn’t just alarmism. It frames the tension between public accountability and personal risk, showing why transparency designed for credit checks and journalism also creates a joined profile attackers love. We tell the story of how digital glitter — once data leaves its source — glints everywhere, and why suppression or removal is never instant or total. By the end you’ll feel that uncomfortable nudge: search your company on Companies House, check service addresses, review LinkedIn and job adverts, and audit your domain’s email records. The narrative closes by setting the scene for the next chapter in the series and challenging every listener to ask: what did I find about myself that an attacker could use first?

Trailers

About

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU'LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

You Might Also Like