The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU'LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

  1. 2d ago

    Why a 0% Phishing Click Rate Might Be Lying to You

    They put a fat green 0% on the slide and everyone nodded like it meant victory. Gary, a builder with plasterboard and vans on his mind, sips his tea and wonders why cyber security suddenly sounds like someone else’s problem — until the hosts pull that cheerful number apart. What looks like perfect protection can be a mirage: a workforce trained to pass one test but not to spot the real, messy tricks criminals use when a delivery is late or an invoice changes. In this episode, Noel and Morvan walk Gary — and you — through the slow unravelling of that comforting 0%. We follow a year of simulated attacks from a vendor’s dataset and watch a story unfold: clicks fall, then spike, and finally settle — not because people got stupider, but because the tests got harder and started catching the vulnerabilities that easier simulations missed. Through vivid examples (the parcel everyone waits for, Dave who closes a window and hopes no one noticed, and a frantic phone call that saves the company money), the hosts tease out the real lessons. Clicks are not binary verdicts; they are one link in a chain that includes credential submission, MFA failures, and the crucial moment when someone chooses to report the suspicious message. Reporting becomes the episode’s hero: a single employee who says “this looks odd” can protect an entire team. The conversation turns practical — one big, easy-to-press button, quick acknowledgement, and a culture that thanks people for coming forward instead of shaming them. The narrative pivots from blaming individuals to building systems that survive human error. By the end you’ll see why insurers and dashboards obsessed with a single percentage get a dangerously incomplete picture, and why better metrics — credential leaks, reporting rates, testing difficulty, and report speed — reveal a healthier story. The episode closes with four concrete steps Gary can take on Monday morning and a rallying cry: don’t chase perfect green ticks; build processes that turn your people into the sensors that actually keep you safe.

  2. Sep 7

    When AI Could Make You Speak: Trust, Consent, and Synthetic Voices

    It begins with a simple, uneasy question: can the system make Graham say something he never said? The hosts — Lucy, Noel and Graham — turn a nagging fear into a tense, curious investigation as they lift the curtain on how this podcast is made. What follows is less technical lecture and more confessional road‑test: rehearsal recordings, AI voice models, and the missing line that could break a Monday‑morning episode. That single scenario becomes a moral pressure test for rules that sound good on paper but buckle the moment a deadline arrives. From the recorded conference call to the final rendered voice, the episode walks you through every trap: perfect transcriptions that lie by omission, an AI that ‘helps’ by inventing clearer phrasing, suppliers who change terms overnight, and the awkward realisation that consent to model a voice is not ownership over the person behind it. The hosts push their own policies until they crack, showing how context — who’s available, who’s under pressure, what the sponsors want — determines whether a guardrail holds or fails. Through punchy examples and studio anecdotes, the conversation pivots to the cornerstones of sensible governance: precise rules not vague aspirations, logging and provenance where decisions matter, incident plans written before disaster, and human authority that can actually say no. Small businesses eavesdropping on this exchange get a practical lesson: don’t pretend AI is brand‑new — apply the governance you already know, but shore it up where AI amplifies risk. Listeners will feel the tension between convenience and integrity as the hosts debate whether corrected facts, edited context, and late‑minute fixes can ever be rendered in someone else’s voice without permission. The episode doesn’t demonise the technology; instead it teases out the choices that make it trustworthy or dangerous. Identity protection, transparent disclosure, and who gets to approve final wording become the story’s beating heart. By the end you’re left with a challenge: imagine the moment when following the rule costs you time, money or an episode — and decide in advance which matters more. With humour, practical steps and a few studio confessions, this episode becomes a toolkit and a cautionary tale: design guardrails that survive a busy Monday morning, then try to break them before someone else does.

  3. Aug 31

    We Found the Admin Password in the Dark Web: A GRC Wake-Up Call

    It begins like a quiet, ordinary audit: an annual security check, the kind of routine that should leave you reassured. Instead, it ends with a single line of data that changes everything — the password for a shared Microsoft 365 admin identity appears in a dark web credential dump. What follows is not a thriller about dramatic hacks and midnight ransom notes, but a far more unsettling story about assumptions, convenience and the slow drift from policy to peril. Lucy, Noel and Graham walk you through the discovery as if you were in the room with them: the initial disbelief, the precise questions, the careful parsing of what the presence of that credential does — and does not — prove. It doesn’t prove an active compromise of the tenant. It doesn’t show that funds were stolen or files siphoned off. But it does prove that a secret is no longer secret, and that the one basic thing security is supposed to give you — accountability — had been quietly surrendered when a single identity came to stand for many people. From there the podcast moves from theory into instant reality. Decisions that once felt academic — whether to stop sharing logins, whether to require stronger authentication, whether to upgrade licensing — become urgent actions: rotate the credential, remove shared access, review sign-in history, audit privileges and hunt for suspicious activity. The hosts take you through the pragmatic steps of containment and investigation while unpacking why a shared admin account complicates every element of incident response and attribution. But this episode is more than a checklist. It’s a lesson in governance, risk and compliance told through human voices and wry commentary: who owned the decision to allow shared identities, how risks were underestimated for convenience, and why compliance isn’t a spreadsheet of green boxes but evidence you can show when someone actually looks. The narrative sharpens when the hosts confront the uncomfortable truth — reality will audit you for free, and often at the worst possible moment. Technology and nuance weave through the conversation: the protective value of MFA and conditional access only matters if they’re configured and enforced; for privileged roles, the hosts explain Microsoft’s move toward phishing-resistant authentication like passkeys and FIDO2 keys. Practical, bite-sized guidance sits next to the wider cultural point: security work is rarely thrilling, and yet its quiet, boring practices are the very things that stop bad things from happening. There are human touches too — the recurring joke about ‘Fred,’ the imaginary multi-person identity that logs in from everywhere, and the admission that the show itself uses AI in all aspects of production under strict guardrails. That revelation becomes a mini-case study about governance again: how consent, editorial control and strict boundaries turn the same technology that can impersonate into a tool for protection and clarity. The episode ends with a clear, actionable offer — ten free dark web credential scans and a final provocation: don’t ask whether anything bad has happened to you; ask what evidence you have that nothing bad has happened. It’s an eerie, practical close to a four-part series that began with frameworks and finished by meeting the messy, inconvenient truth of real systems. Listen for the human conversations, the forensic thinking, and the bitingly honest moment when a routine audit turns a hypothetical risk into a concrete problem. This is a story about small decisions with big consequences — and about the steady, sometimes boring work that keeps businesses secure.

  4. Aug 24

    Prove It — When Boardroom Confidence Meets Real-World Controls

    We start with a number: 94% — the share of UK business leaders who say they’re confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require two‑factor authentication, 31% report board‑level ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident. In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isn’t a security control. Saying “we’d cope with ransomware” is not the same as proving you’ve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it. We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change — rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated. Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and high‑profile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it? ‘Compliance’ is rescued from the textbook. It becomes three things: policy (the decision you’ve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre — beautifully formatted fiction where every box is green — and replaces it with operational tests that matter. Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same ‘Fred.’ Accountability disappears, and with it the ability to respond credibly to an incident. There are no magic words or silver bullets: Cyber Essentials isn’t a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline — a prompt to prove the controls you claim to have. Before you turn off the show, the hosts hand you an unpretentious to‑do list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than one‑off paperwork. By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered — convinced that good security can be practical and affordable, but only if leaders stop saying they’re secure and start showing it.

  5. Aug 11

    Passkeys Aren't Dead — What a Week of Panic Taught Us About Risk

    Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions. First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had. Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings. These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow. We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes. Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords. By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.

  6. Aug 3

    Meet Dave: From Gas‑Safe to Cyber‑Safe — A Small Business Survival Story (Part1)

    Three letters—G‑R‑C—sound like corporate nonsense until they stand between a business that survives a bad day and one that doesn’t. Pull up a stool: this episode meets Dave, who runs a 14‑person heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. He’s gas‑safe, insured, and obsessive about paperwork when lives are at stake. But his cybersecurity? That lives in his head, or a post‑it, or a notebook in a top drawer—and that’s the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster. We tell Dave’s story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules they’re given; the business fails when nobody decided what the rules were. Governance isn’t a committee or a legal brief—it’s four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplier’s—and the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday. This episode uses storytelling to make the abstract vivid: the harmless phrase “we’re too small for this” becomes a trap, the notebook of passwords becomes a ticking time bomb, and a one‑page decision becomes the difference between chaos and calm. You’ll hear practical scenes, not slides—how a named human owner, a handful of decisions, and a quarterly 10‑minute review turn security into something usable, not terrifying. By the end you’ll have three simple actions you can do this week: name the person who owns your security out loud; start your one‑page governance sheet; and set a recurring three‑month GRC reminder. Small, concrete moves that take minutes and protect years of work. If you’re a small business owner who thinks cyber is someone else’s problem, this episode is the wake‑up call delivered over a pint—friendly, practical, and impossible to ignore.

Trailers

About

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU'LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

You Might Also Like