The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy

The UK’s leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU’LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

  1. 4d ago

    Your Security Kit Is their Way In

    Your Security Kit Is the Way In The things you bought to keep attackers out are how they’re getting in. Citrix, Fortinet, forgotten WordPress backups, fake ChatGPT adverts, and the AI in your business that nobody owns. Some time in early September, somebody found a way through a door that thousands of businesses use to let their staff in from home. The owners didn’t know. Then the emergency fix arrived, patched boxes started rebooting, and that turned out to be another hole attackers were already using. This week Noel Bradford, Lucy Harper, and Graham Falkner follow one thread through every story: something was trusted, and nobody was in charge of checking that trust. Citrix NetScaler zero-days exploited for weeks before disclosure. A FortiMail flaw with fixes still pending, and Noel’s long-running grievance with Fortinet’s track record. Forgotten WordPress backups handing over email and cloud passwords. Microsoft’s Digital Defense Report showing phishing back as the front door. And fake ChatGPT adverts on Google that walk staff straight into installing a remote access tool. Then the conversation turns to the AI in your business that nobody owns. Prompted by John Wernfeldt’s LinkedIn post on AI teams and governance teams talking past each other, the hosts translate the problem for Gary Mott’s twelve-person building firm and land on three conditions that take twenty minutes to agree. Noel also announces GRCBolt, his own AI policy pack for UK small businesses, now taking waitlist sign-ups. What to do this week Email your IT provider and anyone who holds your data. Ask whether they run Citrix NetScaler or Fortinet FortiMail, and whether they’ve patched and checked for signs of compromise. For Citrix, ask whether they’ve applied the second fix released on Sunday 4 October. Find out who looks after your website. Ask them to clear old backup files out of public folders, update WordPress, and change the email password stored in your contact form plugin. Turn on passkeys for the accounts that matter most: whoever runs Microsoft 365 or Google Workspace, and whoever approves payments. Both platforms include passkeys at no extra charge. Forcing everyone to use them needs an extra licence on some Microsoft plans. Tell everyone one rule. No genuine website will ever ask you to press the Windows key and R, then paste something in. Agree three things about AI: which tools are allowed, which data never goes in, and who checks the output before a client sees it. Put a name next to each. Chapters 00:00 Cold open 00:56 Welcome 01:33 The doors you don’t own: Citrix NetScaler and Fortinet FortiMail 10:15 The back door you forgot: WordPress backups leaking passwords 13:36 Borrowed trust: Microsoft’s report and fake ChatGPT adverts 19:13 The AI nobody owns 23:00 Introducing GRCBolt 25:03 Your Monday morning actions 26:57 Close Sources Citrix NetScaler NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Gateway Citrix security bulletin for CVE-2026-88771 to CVE-2026-88778, including indicators of compromise Sophos: Citrix NetScaler vulnerabilities in active exploitation The Hacker News: Mandiant and Google Threat Intelligence on the NetScaler campaign Cyber Security News: NetScaler appliances rebooting after the zero-day patch BleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks Fortinet FortiMail Help Net Security: Critical FortiMail zero-day exploited in the wild watchTowr: FortiMail CVE-2026-104286 FAQ Radical Notion: Fortinet CVE report card (third-party aggregator) MazeHQ: 2025 known exploited vulnerabilities by vendor WordPress backups Cyber Security News: Exposed WordPress backups leaking cloud and email credentials Microsoft Digital Defense Report 2026 Microsoft Digital Defense Report 2026 Microsoft’s figures come from its own customer and incident response data, so treat them as vendor telemetry. Fake ChatGPT adverts and ClickFix Huntress: Attackers abuse ChatGPT Custom GPTs to deliver a RAT via ClickFix Island: How attackers use sponsored search and Custom GPTs in malware delivery Passkeys CoreView: Enabling and enforcing passkeys in Microsoft Entra ID Google Workspace Updates: Passkeys for Workspace users AI and governance The governance discussion was prompted by a LinkedIn post from John Wernfeldt on why AI teams and governance teams need to be in the same room. John writes about data governance, analytics, and AI in his newsletter, Data Governance Field Library. GRCBolt GRCBolt is Noel’s own product, and this episode has no sponsor. It’s an AI policy pack for UK small businesses: four documents written around your business, a one-off price under £100, no subscription, and editable Word files. It’s guidance only, and it doesn’t replace legal advice or certify you against any standard. Join the waitlist and see the partial sample pack at grcbolt.co.uk. Related episodes Mentioned in this episode: The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency When AI Finds the Switch You Forgot: Attacks for Pocket Change When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning Why a 0% Phishing Click Rate Might Be Lying to You When AI Could Make You Speak: Trust, Consent, and Synthetic Voices We Found the Admin Password in the Dark Web: A GRC Wake-Up Call Passkeys Aren’t Dead: What a Week of Panic Taught Us About Risk Further listening: Shadow AI Is Just Shadow IT Wearing a Cape If Your MSP Says ‘All Good’, Can They Prove It? Listen, subscribe, and join in All episodes Join our Skool community Questions or stories: Hello@TheSmallBusinessCyberSecurityGuy.co.uk If this episode was useful, share it with someone who needs to hear it. Especially whoever looks after your website.

    Your Security Kit Is their Way In
  2. Sep 28

    When AI Finds the Switch You Forgot: Attacks for Pocket Change

    Imagine waking on a Tuesday to discover an invisible army has been testing your doors for six days. It doesn’t need fancy zero-days or cinematic cleverness — just agents that can scan, read, adapt and move on. In this episode, we follow a financially motivated attacker using open-source AI tools to run 105 probing projects in under a week, harvesting card data and compromising organisations while the cost of each reconnaissance run averages just a few dollars. From Gambit Security’s reconstruction of a scaled campaign to New Zealand’s National Cyber Security Centre warning that frontier models accelerate reconnaissance, the story threads together into one uncomfortable observation: the problem isn’t a lack of security technology, it’s the gap between owning features and operating them. A critical TeamCity flaw with a published patch and known exploitation shows how a fixed vulnerability becomes a real ransomware entry when change processes stall and nobody can say for sure what is exposed. We even wind up in the optical spine of fiber broadband, where Quark’s Lab’s deep dive into passive optical networks exposes a familiar theme — standards and features can support strong protections, but optional choices and careless deployments turn capability into illusion. Whether it’s MFA, backups, EDR or encryption, a green tick on a dashboard is not the same as a control that will actually stop an attacker in the middle of the night. AI doesn’t need to be a brilliant mastermind. It just needs to cheaply and persistently test the weak signals you left lying around. That changes the economics: the marginal cost of trying the next company collapses, and opportunistic compromise scales. Small businesses aren’t suddenly interesting; they’re suddenly cheap to probe, and automation can take an exploit much further than old scanners ever could. But this isn’t fatalism — it’s a practical wake-up call. The defence that works is less about buying another product and more about operational discipline: know what your external world can reach, test whether MFA actually prompts for a second factor, restore a backup for real, and rehearse the decision pathways for critical patches. Ask: if someone could attack us cheaply tomorrow, what would make them stop? We tell the story through people and processes — the helpdesk pressured to reset accounts, the admin on leave, the server thought to be internal but quietly facing the internet — and pull tools into the background. The episode walks you through real moments where security features exist but controls don’t, then hands you a simple, evidence-first checklist to start closing those gaps today. By the end you’ll see the same pattern in different disguises: AI makes probing trivial, technology contains the answers, and operations decide whether those answers are actually used. It’s bleak, fixable, and urgent — because the next probe might be the one that finds the switch you forgot to turn on. Find our Skool community here - https://www.skool.com/small-biz-cyber-guy-2008

    When AI Finds the Switch You Forgot: Attacks for Pocket Change
  3. Sep 21

    When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning

    Three headlines—an EU law delay, an AI-accelerated intrusion that went from weeks to hours, and a UK bill about to bring hundreds of IT providers under direct regulation—sound like stories from different podcasts. They aren’t. By the end of this episode, they meet in a single, worrying place: the gap between assumption and evidence. Follow Noel Bradford, Lucy Harper and Corrine Jefferson as they trace that gap through vivid scenes: a quiet lawroom in Brussels that postponed some deadlines but switched major penalties on; a Unit 42 investigation where one attacker, helped by AI, compressed reconnaissance, exploitation and extortion into under ten hours; and Westminster’s Cybersecurity and Resilience Bill that could force managed service providers to register, report incidents quickly, and face heavy fines. Along the way, the podcast lights up small, human details—a heating engineer’s paperwork, a builder’s son who inherited the IT, a host who reads breach reports like gas bills—to show how ordinary businesses get dragged into extraordinary risk. They don’t just explain the problems; they show how the threads tie together. The EU’s AI Act makes clear obligations for providers of large models but only if you can first answer the simple question: what AI do you actually use? The attack demonstrates the lethal value of time—alerts that wait in an inbox are useless when an attacker finishes a campaign before most people have their second cup of coffee. The UK bill exposes who truly owns the decision when an outsourced provider goes dark: legal reporting may hit the MSP, but operational pain lands with the client. Alongside sharp investigations into LG TV privacy claims and a cunning "click-to-fix" browser-cache exploit, the episode turns practical. It hands you three urgent morning-after questions to take to your board: what AI does your business use (and who owns it), could you detect and respond within ten hours, and is your IT provider positioned to be regulated? If you can’t answer those now, this episode will make it impossible to shrug them off. Listen for clear, actionable steps—visibility, speed and ownership—that every small business needs before the clocks of law, crime and regulation collide.

    When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning
  4. Sep 14

    Why a 0% Phishing Click Rate Might Be Lying to You

    They put a fat green 0% on the slide and everyone nodded like it meant victory. Gary, a builder with plasterboard and vans on his mind, sips his tea and wonders why cyber security suddenly sounds like someone else’s problem — until the hosts pull that cheerful number apart. What looks like perfect protection can be a mirage: a workforce trained to pass one test but not to spot the real, messy tricks criminals use when a delivery is late or an invoice changes. In this episode, Noel and Morvan walk Gary — and you — through the slow unravelling of that comforting 0%. We follow a year of simulated attacks from a vendor’s dataset and watch a story unfold: clicks fall, then spike, and finally settle — not because people got stupider, but because the tests got harder and started catching the vulnerabilities that easier simulations missed. Through vivid examples (the parcel everyone waits for, Dave who closes a window and hopes no one noticed, and a frantic phone call that saves the company money), the hosts tease out the real lessons. Clicks are not binary verdicts; they are one link in a chain that includes credential submission, MFA failures, and the crucial moment when someone chooses to report the suspicious message. Reporting becomes the episode’s hero: a single employee who says “this looks odd” can protect an entire team. The conversation turns practical — one big, easy-to-press button, quick acknowledgement, and a culture that thanks people for coming forward instead of shaming them. The narrative pivots from blaming individuals to building systems that survive human error. By the end you’ll see why insurers and dashboards obsessed with a single percentage get a dangerously incomplete picture, and why better metrics — credential leaks, reporting rates, testing difficulty, and report speed — reveal a healthier story. The episode closes with four concrete steps Gary can take on Monday morning and a rallying cry: don’t chase perfect green ticks; build processes that turn your people into the sensors that actually keep you safe.

  5. Sep 7

    When AI Could Make You Speak: Trust, Consent, and Synthetic Voices

    It begins with a simple, uneasy question: can the system make Graham say something he never said? The hosts — Lucy, Noel and Graham — turn a nagging fear into a tense, curious investigation as they lift the curtain on how this podcast is made. What follows is less technical lecture and more confessional road‑test: rehearsal recordings, AI voice models, and the missing line that could break a Monday‑morning episode. That single scenario becomes a moral pressure test for rules that sound good on paper but buckle the moment a deadline arrives. From the recorded conference call to the final rendered voice, the episode walks you through every trap: perfect transcriptions that lie by omission, an AI that ‘helps’ by inventing clearer phrasing, suppliers who change terms overnight, and the awkward realisation that consent to model a voice is not ownership over the person behind it. The hosts push their own policies until they crack, showing how context — who’s available, who’s under pressure, what the sponsors want — determines whether a guardrail holds or fails. Through punchy examples and studio anecdotes, the conversation pivots to the cornerstones of sensible governance: precise rules not vague aspirations, logging and provenance where decisions matter, incident plans written before disaster, and human authority that can actually say no. Small businesses eavesdropping on this exchange get a practical lesson: don’t pretend AI is brand‑new — apply the governance you already know, but shore it up where AI amplifies risk. Listeners will feel the tension between convenience and integrity as the hosts debate whether corrected facts, edited context, and late‑minute fixes can ever be rendered in someone else’s voice without permission. The episode doesn’t demonise the technology; instead it teases out the choices that make it trustworthy or dangerous. Identity protection, transparent disclosure, and who gets to approve final wording become the story’s beating heart. By the end you’re left with a challenge: imagine the moment when following the rule costs you time, money or an episode — and decide in advance which matters more. With humour, practical steps and a few studio confessions, this episode becomes a toolkit and a cautionary tale: design guardrails that survive a busy Monday morning, then try to break them before someone else does.

  6. Aug 31

    We Found the Admin Password in the Dark Web: A GRC Wake-Up Call

    It begins like a quiet, ordinary audit: an annual security check, the kind of routine that should leave you reassured. Instead, it ends with a single line of data that changes everything — the password for a shared Microsoft 365 admin identity appears in a dark web credential dump. What follows is not a thriller about dramatic hacks and midnight ransom notes, but a far more unsettling story about assumptions, convenience and the slow drift from policy to peril. Lucy, Noel and Graham walk you through the discovery as if you were in the room with them: the initial disbelief, the precise questions, the careful parsing of what the presence of that credential does — and does not — prove. It doesn’t prove an active compromise of the tenant. It doesn’t show that funds were stolen or files siphoned off. But it does prove that a secret is no longer secret, and that the one basic thing security is supposed to give you — accountability — had been quietly surrendered when a single identity came to stand for many people. From there the podcast moves from theory into instant reality. Decisions that once felt academic — whether to stop sharing logins, whether to require stronger authentication, whether to upgrade licensing — become urgent actions: rotate the credential, remove shared access, review sign-in history, audit privileges and hunt for suspicious activity. The hosts take you through the pragmatic steps of containment and investigation while unpacking why a shared admin account complicates every element of incident response and attribution. But this episode is more than a checklist. It’s a lesson in governance, risk and compliance told through human voices and wry commentary: who owned the decision to allow shared identities, how risks were underestimated for convenience, and why compliance isn’t a spreadsheet of green boxes but evidence you can show when someone actually looks. The narrative sharpens when the hosts confront the uncomfortable truth — reality will audit you for free, and often at the worst possible moment. Technology and nuance weave through the conversation: the protective value of MFA and conditional access only matters if they’re configured and enforced; for privileged roles, the hosts explain Microsoft’s move toward phishing-resistant authentication like passkeys and FIDO2 keys. Practical, bite-sized guidance sits next to the wider cultural point: security work is rarely thrilling, and yet its quiet, boring practices are the very things that stop bad things from happening. There are human touches too — the recurring joke about ‘Fred,’ the imaginary multi-person identity that logs in from everywhere, and the admission that the show itself uses AI in all aspects of production under strict guardrails. That revelation becomes a mini-case study about governance again: how consent, editorial control and strict boundaries turn the same technology that can impersonate into a tool for protection and clarity. The episode ends with a clear, actionable offer — ten free dark web credential scans and a final provocation: don’t ask whether anything bad has happened to you; ask what evidence you have that nothing bad has happened. It’s an eerie, practical close to a four-part series that began with frameworks and finished by meeting the messy, inconvenient truth of real systems. Listen for the human conversations, the forensic thinking, and the bitingly honest moment when a routine audit turns a hypothetical risk into a concrete problem. This is a story about small decisions with big consequences — and about the steady, sometimes boring work that keeps businesses secure.

  7. Aug 24

    Prove It — When Boardroom Confidence Meets Real-World Controls

    We start with a number: 94% — the share of UK business leaders who say they’re confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require two‑factor authentication, 31% report board‑level ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident. In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isn’t a security control. Saying “we’d cope with ransomware” is not the same as proving you’ve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it. We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change — rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated. Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and high‑profile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it? ‘Compliance’ is rescued from the textbook. It becomes three things: policy (the decision you’ve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre — beautifully formatted fiction where every box is green — and replaces it with operational tests that matter. Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same ‘Fred.’ Accountability disappears, and with it the ability to respond credibly to an incident. There are no magic words or silver bullets: Cyber Essentials isn’t a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline — a prompt to prove the controls you claim to have. Before you turn off the show, the hosts hand you an unpretentious to‑do list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than one‑off paperwork. By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered — convinced that good security can be practical and affordable, but only if leaders stop saying they’re secure and start showing it.

  8. Aug 11

    Passkeys Aren't Dead — What a Week of Panic Taught Us About Risk

    Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions. First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had. Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings. These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow. We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes. Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords. By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.

Trailers

About

The UK’s leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses. 🎯 WHAT YOU’LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

You Might Also Like