Hot Takes from the Small Business Cyber Security Guy

The Small Business Cyber Security Guy

Hot Takes Hot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team. This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters: What does this mean for a real small business? Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF. We cover topics including cyber attacks, data breaches, ransomware, supply chain risk, Microsoft 365 security, compliance, Cyber Essentials, bad MSP behaviour, weak governance, and the many creative ways organisations manage to trip over their own shoelaces. No hoodies. No Matrix code. No corporate fog machine. Just straight talk, useful context, and clear takeaways for business owners, directors, IT teams, and anyone else trying to keep the lights on without becoming a full time cyber security analyst. Bold opinions. Practical advice. Made for small businesses.

  1. Jul 10

    FortiBleed, Fortinet, and the Firewall That Became the Failure

    FortiBleed, Fortinet, and the Firewall That Became the Failure Noel Bradford unleashes a withering critique of Fortinet following the FortiBleed vulnerability’s impact on British embassies, the Foreign Office, and the British Council. This is not a balanced analysis; it is a controlled explosion aimed at a vendor that keeps appearing in credential exposure stories despite its market dominance and recurring revenue model. Bradford demands answers: why does one of the world’s largest security companies repeatedly feature in edge device exploitation headlines? Why are customers paying annual licences for products that become the risk conversation? And why, in an era when frontier AI models like Anthropic’s Claude Mythos Preview are being deployed to hunt vulnerabilities in critical software, are we still watching firewalls, the devices sold as the safe bit, turn into national security incidents? He dismantles the familiar cycle of advisory, exploitation, and carefully worded apology, and asks whether recurring revenue comes with recurring responsibility or just recurring anxiety. Public bodies, MSPs, and the industry’s talent for turning failure into beige process language all come under fire. This is a rant, a reckoning, and a refusal to pretend this is fine. Chapters Cold Open Noel opens with cold fury, warning listeners this is a rant. FortiBleed has hit British embassies, the Foreign Office, and the British Council. He refuses to deliver the vendor-friendly version or pretend the complexity excuses the pattern. Fortinet’s ubiquity in critical infrastructure makes its repeated appearance in exploitation headlines unforgivable. The Safe Bit The firewall was sold as the safe bit, the thing with the green dashboard and the procurement-friendly quote. It turns out it was just another internet-exposed computer holding keys and terminating VPN sessions. Noel is tired of the cycle: advisory, exploitation, emergency guidance, carefully worded statement, patch advice, shuffle on. The Fortinet Question The question is not just whether customers patched. Fortinet sells security and confidence. Why does one of the largest security vendors on the planet keep ending up in headlines around exploited edge devices, credential exposure, and large scale customer panic? This is a reputational and governance problem. The Price Of Being Big All vendors have vulnerabilities, but frequency, pattern, and blast radius matter. If your kit is everywhere, your mistakes are everywhere. You do not get giant market share and giant recurring revenue, then act wounded when people expect giant levels of assurance. You wanted the market; now carry the weight. Hard Coded Credentials Noel drags the hard coded credentials issue back into the room, referencing Fortinet’s PSIRT entry for dummy testing data in FortiManager and FortiAnalyzer. Hard coded credentials in security software is a phrase that should make eyebrows leave faces. The optics are appalling when your commercial promise is trust. Mythos And Glasswing Anthropic has deployed Claude Mythos Preview, a frontier AI model, to find and fix vulnerabilities in critical software as part of Project Glasswing. Firewalls are critical software. Noel demands to know whether Fortinet has access to Mythos or an equivalent, because edge security appliances should be attacked internally before criminals get the pleasure. The Licence Model Fortinet’s business model is wrapped in recurring licences. Customers pay annually because threats move daily. But recurring revenue must come with recurring responsibility. If you charge every year, your product security has to move every day. Otherwise, what are customers renewing: protection, or access to the next apology? Subscription To Anxiety Customers were sold maturity, scale, and expertise. FortiBleed makes it feel upside down. The firewall became the risk conversation. The security vendor became the source of anxiety. The recurring licence starts to look like a subscription to anxiety with rack ears. Public Sector Trust British embassies, the British Council, and Foreign Office credentials are reportedly in the mix. People give data to public bodies because they have to. They do not get to inspect the firewall first. They just get the email afterwards, the one about an abundance of caution. Caution is never abundant before the breach. MSPs Do Not Get To Hide If you sold this kit, you own the conversation. If you manage it, you produce evidence. Vanishing behind a ticket note saying awaiting customer instruction is cowardice with a service desk reference. The edge is where the attack starts. If your definition of managed is occasionally aware, stop using the word managed. Why I Am Angry Noel is angry because the same story keeps coming back. A company with Fortinet’s scale should be held to a brutal standard. Customers pay recurring money for security and still wonder whether the security product is the problem. Hard coded credentials should haunt people longer than one advisory cycle. Public bodies always find caution after the fact. Final Vent Noel does not want the soothing statement or the partner deck. He wants someone to answer the question: why does one of the biggest security vendors keep ending up in these conversations? What is being done inside the product? Is frontier AI being thrown at the code? The firewall was meant to be the line of defence. FortiBleed made it look like the line of failure. Links https://www.anthropic.com/research/glasswing-ai-for-vulnerability-discovery https://www.fortinet.com/psirt https://www.ncsc.gov.uk/news/ncsc-issues-alert-fortinet-fortigate-vulnerability Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

  2. Jul 3

    Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week)

    Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week) The Information Commissioner’s Office isn’t hunting your business, but that doesn’t stop small organisations from making the same three avoidable mistakes. Host Noel Bradford examines twelve recent ICO enforcement notices to identify the most common failures: no documented breach response process, insufficient staff training on what constitutes personal data, and no record of processing activities. These aren’t exotic compliance gaps requiring expensive consultants or new platforms. They’re basic governance failures that can be fixed with a one-page process document, practical staff training, and a simple spreadsheet. The real exposure isn’t regulatory enforcement, it’s the internal fog that leaves staff unable to recognise or report incidents, managers unclear on ownership, and directors unable to explain what data the business holds. This episode cuts through vendor fear-mongering and compliance theatre to deliver three practical actions any small business can implement immediately, with no budget required. Chapters Cold Open The ICO is not actively hunting small businesses, which makes the persistent compliance failures all the more frustrating. Intro Analysis of twelve recent ICO enforcement notices reveals three recurring, avoidable failures that don’t require consultants or expensive tools to fix. Failure One: No Documented Breach Response Process Organisations freeze when incidents occur because nobody knows who to call, what to document, or when the clock starts. The real damage begins with the paralysis, not the breach itself. Failure Two: No Staff Training on Personal Data Employees cannot recognise breaches if they don’t understand that personal data includes names, addresses, payroll information, and customer records, not just obviously sensitive material. Failure Three: No Record of Processing Activities Businesses cannot answer basic questions about what personal data they hold, why they hold it, where it lives, or how long they keep it. This isn’t bureaucracy, it’s stock control for trust. The Vendor Problem None of these three failures required vendor solutions to prevent. Fear-based marketing keeps small businesses terrified rather than informed, selling tools instead of addressing governance gaps. The Real Exposure The true risk isn’t ICO enforcement but internal fog: staff who don’t know what to report, managers unclear on ownership, and directors unable to explain data holdings when complaints arrive. What to Do This Week Three practical actions requiring no budget: write a one-page breach response process, train staff with real examples from your business, and build a basic record of processing activities. The Team Meeting Test Ask your team three questions: who would you tell if you sent personal data to the wrong person, what would you document, and where is our list of personal data holdings. Silence reveals your incident. Close Read three public ICO notices before your next management meeting to understand what small organisations keep getting wrong and why the fixes are boring, free, and available immediately. Links https://ico.org.uk/for-organisations/report-a-breach/ https://ico.org.uk/for-organisations/accountability-framework/records-of-processing/ https://ico.org.uk/action-weve-taken/enforcement/ Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

  3. Jul 2

    When Your Security Stack Becomes the Attack Surface

    When Your Security Stack Becomes the Attack Surface Microsoft’s security tools are supposed to protect small businesses, but recent vulnerabilities have turned that premise on its head. GreatXML exploits weaknesses in BitLocker and the Windows Recovery Environment, allowing attackers with physical access to bypass disk encryption protections. RoguePlanet, meanwhile, leverages a race condition in Microsoft Defender’s malware protection engine to escalate privileges to SYSTEM level. Both issues highlight an uncomfortable reality: the integrated security stack that SMBs have been told to trust can itself become part of the threat model. This episode examines what went wrong, where responsibility lies, and why small businesses must stop treating vendor tooling as articles of faith. BitLocker and Defender remain valuable components of enterprise defence, but they require proper configuration, monitoring, and a realistic understanding of their limitations. Physical access attacks matter when laptops travel with staff. Local privilege escalation matters when attackers already have a foothold. And vendor responses matter when defenders are left scrambling to assess risk while corporate statements remain vague. The episode dissects both vulnerabilities, critiques Microsoft’s handling of the disclosure process, questions the researcher’s approach to public release, and ultimately argues that SMBs must move from buying comfort to buying outcomes. Security tools reduce risk; they do not eliminate the need for judgement, hardening, or accountability. Chapters Cold Open Microsoft security tools became part of the attack surface. Intro Setting up the issue: when the safety rails become the attack path, and why small businesses should care. What GreatXML Is Explaining the BitLocker and Windows Recovery Environment vulnerability that exploits unattend.xml and recovery state. What RoguePlanet Is Breaking down the Microsoft Defender race condition that enables local privilege escalation to SYSTEM level. Who Am I Angry At? Assigning responsibility between Microsoft’s process failures and the researcher’s public disclosure approach. The Real Business Lesson Why SMBs must stop buying comfort and start demanding outcomes, configuration discipline, and monitoring. The Closing Punch Final verdict on trust, transparency, and the need for engineering responses over brand management. Links https://nvd.nist.gov/vuln/detail/CVE-2026-50656 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656 Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

  4. Jun 6

    Your Business Is an Open Book

    Your Business Is an Open Book Most small businesses have been building a public intelligence profile for years without realising it. Every LinkedIn update, team photo, and website contact page adds detail to a picture that anyone can view, including those with malicious intent. This episode examines open source intelligence (OSINT) and how publicly available information becomes the foundation for targeted attacks like spear phishing and invoice fraud. Noel Bradford walks through the reconnaissance process, from Companies House filings to social media posts, demonstrating how an attacker can map your business, identify key staff, and craft convincing impersonation emails in under twenty minutes. The episode provides practical steps for auditing your own digital footprint, including what to check on search engines, how to review your Companies House entry, and why listing every software tool on LinkedIn might not be wise. This is not about disappearing from the internet; it is about making conscious choices about what you publish and understanding who else is reading it. Chapters Welcome Introduction to the concept of OSINT and how small businesses inadvertently publish reconnaissance material about themselves through normal business activities. Body A detailed walkthrough of public information sources including Companies House, LinkedIn, business websites, and social media. Explains how attackers use this data to construct targeted spear phishing campaigns, with practical examples of reconnaissance leading to invoice fraud and credential theft. Concludes with five actionable steps for auditing and managing your business’s public profile. Outro Final reminder that OSINT is simply reading publicly available information with intent, and that small businesses can reduce risk by auditing their own footprint and making conscious publishing decisions. Links https://www.gov.uk/government/organisations/companies-house https://www.linkedin.com https://www.ncsc.gov.uk/guidance/phishing Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

  5. Jun 5

    Cyber Essentials Platform Transition: What the July Deadline Means for You

    Cyber Essentials Platform Transition: What the July Deadline Means for You The Cyber Essentials scheme is transitioning from its Willow platform to the new Danzell version, with a go-live date now set for 6 July. Noel Bradford cuts through the noise to explain what this extension actually means for small businesses holding or pursuing certification. If you are mid-assessment, you need to check with your certification body about completion requirements. If you are planning a new assessment, you will be working under the updated Danzell question set, which brings tightened wording and updated evidence requirements across the five core technical controls. Businesses often hear the word ‘extended’ and relax, but your certificate expiry date has not changed. Contract requirements remain in force. This episode walks through the practical steps you need to take now, whether you are renewing, starting fresh, or supporting clients through the transition. The platform update reflects real shifts in how small businesses operate, from cloud services to remote working. Prepare properly, read the updated guidance, and do not wait for your assessor to chase you. Chapters Welcome Noel Bradford introduces the topic: the Cyber Essentials platform transition, a shifted deadline, and why businesses need to update their plans accordingly. Platform Transition Explained The Cyber Essentials scheme is moving from Willow to Danzell, with a new go-live date of 6 July. Noel explains what each platform is, who runs the scheme, and why the word ‘extended’ does not mean businesses can relax. He covers what the transition means for mid-assessment businesses, those starting fresh, and the practical differences in the Danzell question set. The five core technical controls remain, but wording, scope questions, and evidence requirements have been updated. Noel warns against reusing old templates, stresses the importance of checking your certificate expiry date, and highlights the risk of confusing the platform delay with your personal compliance deadline. He also addresses MSPs and IT support businesses, urging them to communicate the change to clients now rather than waiting for panic calls later. Outro Noel summarises the key actions: talk to your certification body if you are mid-assessment, get the Danzell guidance if you are planning a new assessment, and check your certificate expiry date today. The extension is not a problem; ignoring it is. Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

    Cyber Essentials Platform Transition: What the July Deadline Means for You
  6. Jun 4

    Passkeys Are Not Magic, But They Are Better Than Passwords

    Passkeys Are Not Magic, But They Are Better Than Passwords Noel Bradford examines passkeys, a rare security improvement that reduces phishing risk and removes the burden of password memorisation. Drawing on NCSC guidance, he explains why passkeys are resistant to credential theft, how they use cryptography tied to the service you’re logging into, and why they can be easier for users than traditional passwords. He then offers practical adoption advice for small businesses: prioritise high-value accounts, choose approved credential managers, plan device recovery carefully, and train users without the hype. Passkeys won’t fix bad governance or unmanaged devices, but they do represent a serious upgrade from password-based authentication. For accounts that touch money, data, or admin access, this is progress worth planning properly. Chapters Welcome Noel opens by framing passkeys as a rare security improvement that may make life safer and less annoying. He notes the NCSC recommends using passkeys over passwords wherever they’re available, and describes passwords as tired after decades of asking normal people to behave like flawless security robots. Why Passkeys Are Better Than Passwords Noel explains that passkeys move the security burden from human memory to devices proving identity properly. They are resistant to phishing because they use cryptography tied to the service, so fake sites cannot trick users into handing over reusable secrets. He offers practical adoption advice: prioritise high-value accounts (admin, finance, email, cloud), choose approved credential managers, plan device recovery, train users in plain English, and avoid half-rolled-out projects. Passkeys do not fix bad governance or unmanaged devices, but they do reduce credential theft risk. Outro Noel closes by saying passkeys are not magic, but they are a serious upgrade from passwords. They reduce phishing risk and password fatigue. Check which key business services already support passkeys, prioritise critical accounts, document recovery, train users, and keep strong passwords and multi-factor authentication where passkeys are not yet available. Links https://www.ncsc.gov.uk/collection/device-security-guidance/authentication-policy/use-passkeys-instead-of-passwords https://www.cisa.gov/secure-our-world/use-strong-passwords Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

    Passkeys Are Not Magic, But They Are Better Than Passwords
  7. Jun 3

    MFA Fatigue Is a Management Failure, Not a User Problem

    MFA Fatigue Is a Management Failure, Not a User Problem Multi-factor authentication is essential, but not all MFA is equal. When users receive vague, repeated, or poorly explained prompts, they start treating them like cookie banners: accept, accept, make it go away. Attackers exploit this fatigue by triggering prompts under pressure, impersonating IT support, or using social engineering to bypass weak helpdesk processes. This is not a user failure; it is a design and management failure. Businesses must reduce unnecessary authentication noise, use phishing-resistant methods like number matching, train staff to recognise unexpected prompts as attack signals, and strengthen identity verification processes. A reported prompt that turns out to be nothing is a working security culture. A prompt nobody reports because everyone fears looking stupid is how expensive conversations with insurers begin. MFA is a control, not a confession booth. If it fails, look at the whole process: the prompt design, the training, the helpdesk, the call-back procedures, and the culture that prioritises speed over verification. Stop blaming users for predictable mistakes in badly designed systems. Chapters Welcome Noel defends MFA while attacking poor MFA design, lazy user blame, and weak verification processes. Not all MFA is equal: some is clear and strong, some is so noisy and vague that users treat prompts like cookie banners. That is design failure, not user failure. Body Noel explains why MFA fatigue happens and how attackers exploit pressure, urgency, and process gaps. Attackers trigger repeated prompts, impersonate IT, and use social engineering. Businesses must ask why users received repeated prompts, why prompts were unclear, why training was absent, and why helpdesk processes were weak. MFA is a decision point, not a magic forcefield. UK SMBs should use number matching, reduce pointless prompts, teach staff what unexpected prompts mean, and strengthen helpdesk verification. MFA fatigue is often a management failure wearing a user blame costume. People are not the weakest link; unsupported people are. Outro Noel closes by stating that MFA is a control, not a confession booth. If it fails, look at the whole process: the prompt, the training, the helpdesk, the call-back process, the culture. Move away from simple push approval, train staff to report unexpected prompts, reduce authentication noise, and strengthen identity checks. Stop blaming users for predictable mistakes in badly designed systems. Links https://www.ncsc.gov.uk/collection/small-business-guide https://www.cisa.gov/ https://www.ftc.gov/business-guidance/small-businesses https://www.fcc.gov/general/cybersecurity-small-business Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

    MFA Fatigue Is a Management Failure, Not a User Problem
  8. Jun 2

    WiFi Surveillance: When Your Router Becomes a Camera

    WiFi Surveillance: When Your Router Becomes a Camera WiFi feels like plumbing. It’s boring, invisible, and trusted by default. But research from Karlsruhe Institute of Technology shows that ordinary WiFi signals can now identify people with near-perfect accuracy, even when they’re not carrying an active device. This isn’t science fiction or a reason to panic. It’s a signal that infrastructure we consider neutral can become surveillance without looking like it. For small businesses, the challenge isn’t the technology itself. WiFi, sensors, CCTV, door access, and meeting room systems can all be genuinely useful. The problem is treating them as operational kit rather than privacy decisions. Noel Bradford walks through the uncomfortable reality that clever dashboards, vendor promises, and boring boxes on the ceiling can quietly collect more data than anyone has thought through. The solution isn’t to rip access points off the wall. It’s to stop assuming that boring infrastructure is harmless infrastructure, and to ask the awkward governance questions before the router starts behaving like a camera. Chapters Welcome Noel introduces WiFi identification research and frames it as an invisible surveillance problem, not a reason to panic. Body Noel explains the WiFi sensing research in plain English and connects it to privacy, small business infrastructure, CCTV-style thinking, and practical governance. Outro Noel closes by saying WiFi surveillance is not a panic story, but it proves infrastructure can become surveillance and needs governance. Links https://www.sciencedaily.com/releases/2026/05/260522.htm Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/

    WiFi Surveillance: When Your Router Becomes a Camera

About

Hot Takes Hot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team. This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters: What does this mean for a real small business? Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF. We cover topics including cyber attacks, data breaches, ransomware, supply chain risk, Microsoft 365 security, compliance, Cyber Essentials, bad MSP behaviour, weak governance, and the many creative ways organisations manage to trip over their own shoelaces. No hoodies. No Matrix code. No corporate fog machine. Just straight talk, useful context, and clear takeaways for business owners, directors, IT teams, and anyone else trying to keep the lights on without becoming a full time cyber security analyst. Bold opinions. Practical advice. Made for small businesses.