The HIDDEN Podcast by Babble

Lynn Murape

Cyber security is one of those things every growing business knows they should have under control… but very few feel truly confident about. This weekly podcast is designed to change that. Hosted by Lynn Murape, this show cuts through the noise, jargon, and scare tactics that often surround cyber security, and focuses instead on what actually matters for small and medium-sized businesses in the UK. Whether you’re a business owner, an IT manager stretched thin, or someone unexpectedly responsible for “keeping things secure,” you’ll find practical, real-world guidance you can actually use. Each episode tackles cyber security from a different angle. Sometimes, we break it down using the HIDDEN framework — a simple way to understand the six essential areas of protection. Other times, we unpack real-world events like major breaches, new regulations, or emerging threats, translating what they mean for your business in plain English. No fluff. No unnecessary complexity. Just honest conversations, real stories from the field, and clear takeaways to help you make smarter decisions and feel more in control. Because cyber security isn’t a one-off project: it evolves as your business grows. Ultimately, this podcast exists for one simple reason: so you can sleep well at night, knowing that you're business is secure.

  1. Sep 8

    Episode 12: Is your IT provider your cyber security team?

    Your IT provider might be doing an excellent job. But does that include actively watching for threats, investigating suspicious activity, and taking action if something goes wrong? In this episode, Lynn is joined by Nikoo Fullerton to unpack a distinction that catches a lot of businesses out: everyday IT management and specialist cyber security monitoring are not the same thing, even when they sound like they should be. Nikoo explains what a typical IT contract reasonably covers, why a genuinely good MSP can still fall short of providing round-the-clock threat monitoring, and why that gap usually comes down to an untested assumption rather than poor performance. The conversation also strips away the acronym soup around SOC, MSSP, MDR and MXDR, focusing on what buyers should actually be asking about outcomes, scope and authority to act. Nikoo walks through how to decide between managing security internally, outsourcing it, or blending both, why cyber security strategy can never be fully handed off to a third party, and the signs that a business is either under protected or quietly paying twice for overlapping cover. Because the goal isn’t more tools or more providers. It’s knowing exactly who’s watching, who’s investigating, and who’s authorised to act, agreed before anything goes wrong. If this episode leaves you with more questions than answers, join Babble’s upcoming Managed Cyber Security webinar, where we’ll unpack what to buy, how to buy it, and the questions worth asking before you do. Register for the webinar: How to Buy Managed Cyber Security Key takeaways: Why a good IT provider isn’t automatically your security teamWhat a SOC actually is (hint: not a room full of analysts)How to cut through SOC, MSSP, MDR and MXDR by focusing on outcomesHow to choose between internal, outsourced and hybrid modelsWhy cyber security strategy can’t be fully outsourcedThe exclusions and costs that catch businesses out Chapters: 00:00 Doing it well isn’t the same as watching for threats 00:50 Welcome to HIDDEN 01:43 Meet Nikoo Fullerton 03:07 Who’s actually responsible? 04:17 What your IT provider can reasonably cover 05:24 Where IT ends and security begins 06:28 How escalation actually works 07:17 Doing a good job doesn’t mean doing it all 08:34 What a security operations centre actually is 09:42 Cutting through the acronyms 11:02 Internal, outsourced or hybrid 12:37 Why you can’t outsource accountability 13:41 Why playbooks matter 15:24 Signs you’re under protected or overpaying 17:01 Know what you’ve got before you shop around 18:17 MSP, SOC, MSSP, MDR and MXDR explained 22:02 What 24/7 actually means 23:46 The costs that catch people out 25:56 The one thing that needs a named owner 27:22 Closing thoughts

    Episode 12: Is your IT provider your cyber security team?
  2. Sep 2

    Episode 11: Is anyone watching your business at 2am?

    Your security software just flagged something suspicious. It’s 2am, your team’s asleep, and the office is closed. So what happens next? In this episode, Lynn sits down with Steve Hennessy to unpack what an alert actually means, and why it’s only ever the beginning of the story. Because detecting a threat isn’t the same as understanding it, containing it, or knowing who’s responsible for dealing with it once the noise starts. Steve walks through why not every alert carries the same weight, what genuinely happens in the hours between a 2am alert and a 9am login, and why expecting a small internal IT team to catch everything around the clock often isn’t realistic. He also breaks down what triage, investigation and containment mean in practice, and who should have the authority to isolate an account or device when the business itself can’t be reached. The conversation moves beyond the alert itself and into the harder questions: what a genuine 24/7 monitoring service should include, why the cost of proper cover is often more accessible than people assume, and why there’s no single right answer for every business. Because the real risk usually isn’t the alert. It’s not knowing who’s watching, what they’ll do, and when. If this episode leaves you with more questions than answers, join Babble’s upcoming Managed Cyber Security webinar, where we’ll unpack what to buy, how to buy it, and the questions worth asking before you do. Register for the webinar: How to Buy Managed Cyber Security Key takeaways: Why an alert is a warning sign, not a resolutionWhy not every alert requires the same responseWhat can happen in the hours before a 2am alert gets noticedWhether a small internal IT team can realistically provide round-the-clock coverWhat triage, investigation and containment actually involveWhy 24/7 monitoring means very little without a clear plan behind it Chapters: 00:00 Alerts are not the all clear 00:20 Welcome to HIDDEN 01:20 The 2am scenario 02:06 What an alert actually tells you 04:37 Ownership comes up again 05:28 Where does the alert actually go? 06:23 Breaking down MDR and MXDR 07:21 Six hours in the dark 09:04 Alert fatigue is real 12:33 What investigation needs to establish 15:51 What containment actually looks like 17:38 Who has the authority to act? 19:55 The run book as an incident response plan 22:07 What 24/7 monitoring should include 23:50 Does round-the-clock cover cost a fortune? 26:51 Build it in-house or bring in support? 29:06 Does every business need the same cover? 31:51 The one question to ask your MSP 33:54 Closing thoughts

    Episode 11: Is anyone watching your business at 2am?
  3. Aug 25

    Episode 10: Are you getting the cyber protection you’re paying for?

    You’re already paying for antivirus, Microsoft Defender, or an IT provider to keep your laptops and phones secure. So why do gaps still slip through? In this episode, Lynn sits down with Nisha Sondhi to unpack a pattern that shows up again and again in Babble’s HIDDEN assessments: businesses that have the right tools in place, but can’t always say how they’re configured, who’s checking them, or whether they cover every device accessing company data. Because having security software installed isn’t the same as being protected. Nisha explains what “fully managed” should actually mean in practice, why bring-your-own-device (BYOD) policies often have more grey area than businesses realise, and how personal privacy and business security can coexist without one compromising the other. The conversation also covers what happens when the person responsible for a security platform leaves the business, and why it’s usually ownership, not the technology, that quietly falls apart. This isn’t about pointing fingers or selling another tool. It’s about understanding what you already have, who’s accountable for it, and what evidence proves it’s actually working. Because before you consider buying anything else, it’s worth knowing whether your existing protection is doing its job. If this episode raises more questions than it answers, join Babble’s upcoming Managed Cyber Security webinar, where we’ll unpack what to buy, how to buy it, and the questions worth asking before you do. Register for the webinar: How to Buy Managed Cyber Security Key takeaways: Why installed security software doesn’t automatically mean protectionWhat “fully managed” should really includeThe BYOD grey area many businesses overlookHow personal privacy and business security can coexistWhy ownership, not technology, is usually what failsWhy MFA and zero trust remain non-negotiable basics Chapters: 00:00 Why installed doesn’t mean protected 00:27 Welcome to HIDDEN 01:44 What “protected” actually means 04:02 The BYOD blind spot 05:37 Who really owns your security 07:04 Getting more from Microsoft Defender 08:01 Where privacy ends and security begins 10:44 Policy vs. device management 12:58 When the person managing your tools leaves 14:15 Installed isn’t the same as managed 15:13 MFA, zero trust and the human check 17:17 Closing thoughts

    Episode 10: Are you getting the cyber protection you’re paying for?
  4. Jul 14

    Episode 9: Inside the TPI: Why some businesses make technology work and others don’t

    Why do some businesses seem to get more value from technology than others? It’s a question that goes beyond budgets, sectors, or the latest AI tools, and it’s exactly what Babble set out to answer through the Technology Performance Index (TPI): an independent study of 1,000 UK SMB leaders. In this episode, Lynn is joined by Mark O'Dell and Jeremy Langley to unpack the findings, revealing three distinct groups of technology adoption: Tech Vanguards, Emerging Adopters, and Tech Bystanders. The conversation explores what separates these groups, why some organisations consistently turn technology into a driver of growth, while others find themselves stuck firefighting, and how businesses build confidence through structure, governance, and a clear focus on outcomes. You'll also hear why treating technology as a business investment (not simply an IT cost) changes the way organisations make decisions, prioritise projects, and measure success. Perhaps most importantly, this episode challenges the idea that successful technology adoption is about buying the right tools. Instead, it's about starting with the outcome you want to achieve and building the right strategy to get there. Whether you see your business in the Vanguard, Emerging Adopter, or Bystander category, this conversation offers practical insights to help you move forward with greater confidence, and a clearer understanding of how technology can become a genuine driver of productivity, growth, and resilience. Key takeaways: The three technology mindsets shaping UK SMBsWhat separates Tech Vanguards from everyone elseWhy confidence comes from structure, not bigger budgetsHow firefighting prevents long-term progressWhy outcomes, not technology, should drive every investmentHow AI and cyber security are widening the gap between businesses Explore the Technology Performance Index 📊 Take the free Technology Performance Index Assessment https://info.babble.cloud/tpi-assessment2026?hsCtaAttrib=425604937930 📖 Download the full Technology Performance Index Report https://145811431.hs-sites-eu1.com/hubfs/TPI/Report/The%20Babble%20Technology%20Performance%20Index%202026.pdf?hsCtaAttrib=425516543165 🔍 Explore more insights and resources https://www.babble.cloud/tpi Chapters: 00:00 Welcome: Meet Mark O'Dell and Jeremy Langley  01:39 What is the Technology Performance Index (TPI)?  02:34 Why did Babble ask 1,000 business leaders this question?  03:29 What really separates a Vanguard from a Bystander?  05:24 Which group does your business belong in?  06:37 The Bystander: Why are a third of UK businesses falling behind?  12:04 The Emerging Adopter: What’s stopping them from becoming a Vanguard?  15:51 The Vanguard: What are they doing differently?  19:03 Mark's advice for Bystanders, Emerging Adopters and Vanguards  22:22 How did this research change Babble's thinking?  24:58 Where will UK businesses be this time next year?  26:37 Conclusion

    Episode 9: Inside the TPI: Why some businesses make technology work and others don’t
  5. Jun 16

    Episode 8: What Network & Cloud Security Means in the AI Era

    For years, cyber security was built around a simple idea: protect the perimeter. But what happens when your applications live in the cloud, your data is spread across multiple platforms, and AI systems can access information, automate tasks, and make decisions on your behalf? In this episode, Lynn sits down with Keith Archer to explore how network and cloud security is evolving in the AI era, and why many of the security assumptions organisations have relied on for years no longer hold up. Because AI isn't just changing how businesses work. It's changing how cyber threats operate too. From agentic AI and prompt injection to shadow AI and tool hijacking, this conversation unpacks some of the newest risks emerging as organisations race to adopt AI-powered tools and platforms. Keith explains why traditional security controls often struggle to detect these threats, how attackers are beginning to weaponise AI, and why visibility has become one of the most important capabilities an organisation can have. The discussion also explores the growing challenge of shadow AI — where employees introduce AI tools without formal oversight — and the business impact of not knowing what systems, data, or applications those tools can access. Most importantly, this episode isn't about avoiding AI. It's about adopting it responsibly. Because organisations that balance innovation with governance will be far better positioned than those that either ignore AI altogether or deploy it without understanding the risks. A HIDDEN Cyber Security Snapshot helps organisations identify gaps across people, identities, data, recovery, devices, networks, cloud environments, and emerging AI usage; creating a clearer picture of where exposure actually exists. Key takeaways: Why traditional security perimeters no longer existWhat agentic AI means in practical termsThe risks associated with prompt injection and AI manipulationHow shadow AI creates visibility and governance challengesWhy traditional security tools struggle with AI-driven threatsWhere organisations should focus first to improve resilience in the AI era Chapters: 00:00 Introduction 01:12 Meet Keith Archer 02:59 The evolution from perimeter to cloud 05:20 Understanding agentic AI 07:11 Why traditional security tools are struggling 10:34 Jailbreaking and prompt injection explained 14:58 The rise of indirect prompt injection 16:19 The real business impact of AI threats 18:17 Shadow AI and the visibility challenge 19:58 When AI tools become attack paths 21:31 Where organisations are getting AI wrong 23:27 Immediate actions for security teams 25:49 Why human risk still matters 27:46 Keith’s wake-up call for business leaders 30:05 Conclusion

    Episode 8: What Network & Cloud Security Means in the AI Era
  6. Jun 9

    Episode 7: Who’s Watching the Phones and Laptops?

    Your cyber security is only as strong as the devices connecting to your business. Laptops. Phones. Tablets. Personal devices. Corporate devices. They’ve never been more essential to how we work … and they’ve never been more attractive to attackers. In this episode, Lynn sits down with Callum Archer to explore why endpoints remain one of the most targeted attack surfaces in modern cyber security, and what organisations can do to improve visibility, detection, and response before a small compromise becomes a much bigger problem. Because attackers don’t need to break into every device. They just need one. This conversation unpacks why outdated software, inconsistent device standards, and alert fatigue continue to create opportunities for attackers, particularly in SMB environments where IT teams are often stretched thin. Callum also explains how endpoint security has evolved beyond traditional antivirus, why behaviour-based attacks are becoming more common, and how modern endpoint detection and response tools help organisations identify and contain threats faster. Most importantly, this episode explores the importance of speed. Because when a device is compromised, every second matters. The faster you can detect a threat, contain it, and respond, the less opportunity attackers have to move through your environment and cause damage. Our HIDDEN Cyber Security Snapshot helps organisations identify hidden gaps across devices, monitoring, policies, and response capabilities; creating a clearer picture of where endpoint risks actually exist. Key takeaways: Why endpoints remain a primary target for attackersThe risks created by outdated devices and inconsistent standardsWhy traditional antivirus is no longer enough on its ownHow behaviour-based attacks are changing cyber securityThe importance of detection, response, and threat containmentWhat good endpoint protection looks like today Chapters: 00:00 Introduction 01:09 Meet Callum Archer 02:08 Why devices remain a prime target 04:19 The unseen cost of vulnerabilities and alert fatigue 07:25 What happens after a device is compromised 09:00 Why antivirus alone isn't enough 10:51 The rise of malware-free attacks 13:10 How inconsistent device standards create risk 16:25 The non-negotiables of endpoint protection 17:39 Measuring your security maturity 19:47 Callum’s advice on what to do when a device is compromised 20:10 Conclusion

    Episode 7: Who’s Watching the Phones and Laptops?
  7. Jun 2

    Episode 6: Why Backup Isn’t the Same as Recovery

    “We have backups.”  It’s one of the most common phrases in cyber security conversations (and one of the most misunderstood).  Because having a backup doesn’t automatically mean your business can recover.  In this episode, Lynn sits down with Steve Hennessy to unpack the critical difference between backup, recovery, business continuity, and resilience, and why testing matters just as much as the backup itself.  When systems go down, the real question isn’t whether a copy of your data exists. It’s how quickly you can get your business operational again.  This conversation explores why untested backups create a false sense of security, how ransomware attackers increasingly target backup systems first, and why assumptions around recovery often fall apart during real-world incidents.  Steve also breaks down the concept of Recovery Time Objectives (RTOs), why downtime impacts every business differently, and how organisations should think about resilience beyond just data storage.  Most importantly, this episode reframes recovery planning as something proactive, not reactive. Because calm, structured decision-making during a crisis only happens when the planning, testing, and preparation have already happened beforehand.  From restore testing and disaster recovery planning to identifying single points of failure, this episode is all about understanding what happens after something goes wrong and whether your business is truly prepared for it.  A Cyber Security Snapshot helps organisations identify hidden gaps across backup strategy, resilience, recovery planning, and operational risk: creating a clearer picture of where vulnerabilities exist.  Key takeaways:  Why backups and recovery are not the same thing  The risks of relying on untested backups  Why ransomware attackers target backup systems first  What Recovery Time Objectives (RTOs) mean  How business continuity planning improves resilience  Why testing and preparation matter more than assumptions   Chapters:  00:00 Introduction  01:11 Meet Steve Hennessy  02:15 Why backups alone aren’t enough  05:33 The importance of restore testing  08:17 The danger of assuming recovery will work  10:15 Why attackers target backup systems  13:17 Understanding Recovery Time Objectives (RTOs)  14:41 What downtime really costs a business  10:15 Cyber security and backup systems  18:07 Backup vs recovery explained  19:35 Why business continuity planning matters  22:20 The non-negotiables for resilience  25:50 Steve’s advice on staying calm during a cyber crisis  27:02 Conclusion

    Episode 6: Why Backup Isn’t the Same as Recovery
  8. May 26

    Episode 5: Taking Control of Your Data

    Your business data is constantly moving. Shared across Teams. Stored in cloud drives. Downloaded onto devices. Sent externally. Duplicated. Renamed. Forwarded. And in many SMBs, nobody has full visibility of where it all lives anymore. In this episode, Lynn sits down with Nisha Sondhi to unpack the growing challenges of data governance, oversharing, and data sprawl. They also discuss why controlling your data has become one of the biggest cyber security challenges facing modern businesses. Because data doesn’t usually become exposed through one dramatic event. It happens gradually. A file gets overshared. Access permissions are never reviewed. Sensitive information sits in the wrong place. A link gets sent externally. And over time, organisations lose track of what’s sensitive, who has access to it, and what’s happening to it. This conversation explores why data classification is often missing in SMB environments, how human behaviour quietly increases risk, and why “everyone has access to everything” creates far more problems than it solves. Nisha also breaks down the growing pressure coming from compliance requirements, insurers, and customers — who increasingly expect organisations to prove they understand where their data lives and how it’s protected. Most importantly, this episode reframes data governance as something practical, not overwhelming. Because good data security isn’t about locking everything down. It’s about balance, visibility, and putting the right controls around the data that matters most. A Cyber Security Snapshot helps organisations identify hidden gaps across data sharing, access, governance, and user behaviour: creating a clearer picture of where risk actually exists. Key takeaways: Why data sprawl creates hidden security risksThe dangers of oversharing inside and outside the businessWhy data classification is often missing in SMBsHow compliance and cyber insurance are reshaping data governanceWhat good data governance actually looks like in practice Chapters: 00:00 Introduction 01:10 Meet Nisha Sondhi 02:10 Why businesses lose track of their data 07:20 Why governance and compliance now matter more 09:05 The problem with unclassified data 12:31 How human behaviour increases data risk 19:20 What to do when sensitive data is exposed 24:04 Conclusion

    Episode 5: Taking Control of Your Data

Trailer

About

Cyber security is one of those things every growing business knows they should have under control… but very few feel truly confident about. This weekly podcast is designed to change that. Hosted by Lynn Murape, this show cuts through the noise, jargon, and scare tactics that often surround cyber security, and focuses instead on what actually matters for small and medium-sized businesses in the UK. Whether you’re a business owner, an IT manager stretched thin, or someone unexpectedly responsible for “keeping things secure,” you’ll find practical, real-world guidance you can actually use. Each episode tackles cyber security from a different angle. Sometimes, we break it down using the HIDDEN framework — a simple way to understand the six essential areas of protection. Other times, we unpack real-world events like major breaches, new regulations, or emerging threats, translating what they mean for your business in plain English. No fluff. No unnecessary complexity. Just honest conversations, real stories from the field, and clear takeaways to help you make smarter decisions and feel more in control. Because cyber security isn’t a one-off project: it evolves as your business grows. Ultimately, this podcast exists for one simple reason: so you can sleep well at night, knowing that you're business is secure.