

213.1K
Downloads
69
Episodes
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.
đŻ WHAT YOU'LL LEARN:
- Cyber Essentials certification guidance
- Protecting against ransomware & phishing attacks
- GDPR compliance for small businesses
- Supply chain & third-party security risks
- Cloud security & remote work protection
- Budget-friendly cybersecurity tools & strategies
đ PERFECT FOR:
- UK small business owners (5-50 employees)
- Startup founders & entrepreneurs
- SME managers responsible for IT security
- Professional services firms
- Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.
đŻ WHAT YOU'LL LEARN:
- Cyber Essentials certification guidance
- Protecting against ransomware & phishing attacks
- GDPR compliance for small businesses
- Supply chain & third-party security risks
- Cloud security & remote work protection
- Budget-friendly cybersecurity tools & strategies
đ PERFECT FOR:
- UK small business owners (5-50 employees)
- Startup founders & entrepreneurs
- SME managers responsible for IT security
- Professional services firms
- Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Episodes

43 minutes ago
43 minutes ago
Imagine opening the office fridge and finding a cloudy, unlabeled bottle of milk. You wouldnât drink it â so why are businesses still running tills, routers and servers on ancient, unsupported software? In this episode Graham, Noel, Lucy and Mauven turn the mic onto the maddening normality of âmysteryâ machines: the Windows XP till behind the counter, the router older than your youngest employee, the dusty NAS holding the only copy of customer data. With equal parts humour and hard sense, they map food-safety instincts â âuse byâ, âbest beforeâ, the sniff test â onto the tech that keeps small businesses running.
Through real-world stories (from cafes and dental practices to corner shops and manufacturers) the hosts show how âstill turns onâ is not the same as âstill secureâ. End-of-life and end-of-support dates are the invisible expiry stickers businesses ignore at their peril: when security updates stop, so does your defence. Graeme lays out pragmatic steps for a no-nonsense tech audit â list devices, note what they do, check support windows, then slap âused byâ or âbest beforeâ labels on the kit that matters. For anything internet-facing, handling payments, or storing sensitive data, the rule is simple: if itâs out of support, replace it. For unavoidable legacy kit, segment it, lock it down, and plan its retirement.
Practical, urgent and often funny, this episode is a wake-up call for anyone running a small business: donât let your tech go off the rails just because the lights still come on. Follow the simple 30-minute âmilk checkâ homework, colour-code your inventory by risk, and commit to one concrete fix this month â whether thatâs replacing a router, budgeting for a refresh, or scheduling an audit. Share the episode with that friend still running a mystery Windows box. Your customers â and the regulator â will thank you.

7 days ago
7 days ago
Tonightâs episode opens in an empty studio, a fridge with two bottles of Prosecco and a conspicuously absent Noel â the perfect stage for a conversation that is equal parts wry and urgent. Three hosts trade jokes and a refill, but the real story soon emerges: many cyber disasters donât begin with cinematic blackâhat brilliance. They begin with everyday confidence, with the quiet sentence, âWeâll revisit that next quarter.â
We tell the story through small, human scenes: Davina from IT documenting a firewall hole and being ignored; a busy owner insisting the dashboards look fine; staff pasting customer notes into an AI coâpilot because it saves time. Those moments feel ordinary, even sensible. But together they create an irresistible path for attackers â unpatched servers, excessive permissions, reused credentials, and shadow SaaS tools that no one thought to approve. The breach that looks sophisticated in a postâincident writeup often starts with a password used in the wrong place, or a medium finding waved away until it can be chained with others.
We push back against comforting myths: that a tool equals a process, that your business is too unique to be targeted, or that a theoretical finding can safely wait. Instead, we reframe humility as a security control â a practical habit of updating your view when evidence changes, surfacing awkward truths quickly, and learning without scapegoating. Psychological safety isnât a workshop buzzword here; itâs the difference between catching a problem early and making headlines.
The episode then moves into practical, biteâsize remedies you can use this week. Start by asking: what have we delayed because itâs inconvenient? who has more access than they need? what unsanctioned tools or AI are people using? and where do people raise concerns, and what happens when they do? Make a stopâdoing list: pick one convenienceâled risk and fix or formalize it. Give staff a boring, reliable route to flag risks â a 10âminute slot in an ops call, a simple shared list, or a noâblame MSP review â and reward the person who brings bad news early.
We finish with a quiet but powerful leadership practice: say out loud, âI might be wrong.â That sentence flips the dynamic. It turns performative certainty into honest curiosity, shrinks blast radius by encouraging early action, and makes resilience a habit rather than a purchase order. No giant security teams required â just cleaner permissions, timely patches, governed AI use, and the grit to listen when someone like Davina says, calmly, that something is off.
By the end of the episode the mood is hopeful. The hosts have had their Prosecco, given practical checklists, and reminded listeners that strong organizations donât sound the most certain â they admit uncertainty early, correct course quickly, and make space for truth before convenience becomes a liability.

Monday Mar 16, 2026
Donât Buy the Badge: The Real SMB 1001 Guide for UK Small Businesses
Monday Mar 16, 2026
Monday Mar 16, 2026
Do small businesses really need another cyber security badge?
In this episode, Noel Bradford, Mauven MacLeod and Graham Falkner dig into SMB 1001, a five tier cyber security standard aimed at small and medium sized businesses. They break down what the bronze, silver, gold, platinum and diamond levels actually mean, where the framework came from, and whether it has any real value for UK firms.
The team also looks at how SMB 1001 compares with Cyber Essentials, Cyber Essentials Plus, IASME Cyber Assurance and ISO 27001. More importantly, they ask the question many business owners should be asking already. Do you need another logo for the website, or do you need security controls that actually work?
Expect plain English, practical analysis, and a healthy level of scepticism about cyber theatre, vanity certifications and providers who still cannot get clients to the basics.
In this episode
-
What SMB 1001 is and who it is for
-
How the five certification levels work
-
Why it is not a replacement for Cyber Essentials in the UK
-
Where it aligns with good practice and where it does not
-
Which level is realistic for most UK SMEs
-
Why good security matters more than collecting badges
Why listen?
If you run a UK small business, buy IT support, fill in supplier questionnaires, or keep hearing about standards and certifications, this episode will help you cut through the noise. What should you actually focus on first? And what is just expensive reassurance dressed up as strategy?

Wednesday Mar 11, 2026
March 2026 Patch Tuesday â Take It or Stay Vulnerable
Wednesday Mar 11, 2026
Wednesday Mar 11, 2026
Listen in as the Small Business Cybersecurity Guy rips through March 2026 Patch Tuesday like a mechanic with a torque wrench: blunt, precise, and impossible to ignore. This episode opens on a single, brutal premise â Windows updates are not a chooseâyourâownâadventure. They are binary. You either deploy the cumulative payload or you leave every unpatched edge of your estate like a neon target for attackers. The stakes arenât fireworks; theyâre the slow, quiet escalation chains attackers use after a single phishing click.
We trace the real playbook attackers follow: step one, land as an ordinary user; step two, chain an Elevation of Privilege. This month Microsoft shipped six EOP fixes â graphics, kernel twice, accessibility, SMB, and WinLogon â and slapped them with "exploitation more likely." In plain English, these are the exact plumbing pieces an intruder needs to turn a compromised laptop or RDS session into full environment control. Youâll hear why delaying the patch is an active, informed choice to leave those doors open.
Then the narrative sharpens into a thriller: Copilot in Excel. A critical CVE that reads like a very small script with an outsized punch â a nearâzeroâclick XSSâstyle flaw that can make Copilot agent mode obediently hand over internal secrets. Picture your finance lead or CEO, spreadsheets and Copilot live, and a crafted workbook quietly acting as an insider. No macros, no drama â just a nudge that sends data where it shouldnât. The episode makes the risk vivid and personal, not academic.
We also unpack two more critical Office RCEs via the preview pane â the sort of everyday behavior (previewing mail, browsing SharePoint) that real people do all day. Microsoft says exploitation is less likely, but only if youâre patched. The episode forces you to confront the gap between marketing calm and the real-world tradeoffs IT teams make when budgets and reboot windows collide with executive convenience.
Finally, the show gives you a short, brutal checklist â what to do this week if you run a small business or juggle multiple clients: verify actual build numbers, identify who has Copilot agent mode, sanityâcheck DLP and egress for AI tools, and roll in thirdâparty updates like Acrobat alongside Office and Windows. Itâs not a sixâmonth project; itâs triage and discipline. The narration is urgent but practical, a call to action delivered with the weary authority of someone whoâs patched one too many servers at 2 a.m.
Tune in for a tight, noâfluff ride through what looks quiet on the surface but is dangerously loud under it â because the difference between a quiet month and a disaster is how long you choose to stay vulnerable. Hit the blog for scripts, guides, and the deeper dive promised at the end of the episode.

Monday Mar 09, 2026
Willow vs Danzel â Navigating Cyber Essentials V3.3 Before the Deadline
Monday Mar 09, 2026
Monday Mar 09, 2026
Imagine your website is a billboard: a shining Cyber Essentials badge promising security and trust. Now imagine a regulator, insurer or large customer asks one awkward question â and that glossy logo turns from an asset into potential evidence against you. In this episode we walk into that exact moment and refuse to let it be a surprise.
Join Graham Falkner, Noel Bradford and our resident translator of tech, Lucy Harper as they pull apart the new Cyber Essentials changes and stitch the pieces back together into something a small business can actually use.
We start with the simple truth: the requirements document (V3.2, V3.3 and whatever comes next) is the standard you must meet, and the Willow and Danzel question sets are the forms you fill in when you buy certification. Get the wrong combination, or try to recycle last yearâs answers, and assessors will fail you â quietly at first, then painfully when a tender or a claim comes along.
From there we map the conflict: scope, cloud and asset management. V3.3 pulls the rug on the old âthatâs someone elseâs problemâ attitude â cloud services, BYOD devices that touch organisational data, and remote workers are in the frame. If your asset list is a half-dead spreadsheet and some post-it notes, you cannot honestly answer whether you are compliant. The drama here is avoidable, but only if you stop pretending the messy bits arenât part of your estate.
We decode the five controls â firewalls, secure configuration, security update management, user access control and malware protection â and translate them into Monday-morning tasks: lock down admin interfaces, remove default accounts, document inbound firewall rules, treat vendor configuration changes as security fixes, and make sure anti-malware actually blocks things rather than sitting in the tray.
Authentication gets a starring role. V3.3 clarifies passwordless (hello FIDO2 and passkeys) and treats modern approaches as valid multi-factor methods. SMS is grudgingly still acceptable, but itâs the floor, not the ceiling. If your tenant runs on Microsoft 365 or Google Workspace, we give concrete examples of what âgood enoughâ looks like for normal users and admins.
We donât stop at problems â we hand you a plan. Nail your scope and inventory; map assets to the five controls; enable MFA everywhere; clean up admin accounts; ensure critical vendor fixes are applied within the 14âday window; and prepare evidence in a spreadsheet before you pay for the portal. Treat certification as a living process, not a sticker you won once.
For the procrastinators, we lay out a rapid action plan: days 1â10 define scope and update your asset list; days 11â30 enable MFA, tidy accounts and prove you can hit 14âday patches; days 31â60 tighten firewall rules, confirm anti-malware and run a dry self-assessment against Willow or Danzel depending on your purchase date.
This episode is equal parts wake-up call and field guide â built for business owners who donât have a security department but do have customers, contracts and reputations to protect. Listen for the practical checklist, the red flags that bite in tenders and post-breach enquiries, and the honest reassurance that Cyber Essentials will help you â if you stop gaming the edges and start being truthful about what you actually run.
By the end youâll either feel the pressure to act or youâll be able to explain your scope in 30 seconds. Either way, we give you the first steps: patch your systems, turn on MFA, and stop pretending the cloud is somebody elseâs problem.

Friday Mar 06, 2026
Friday Mar 06, 2026
Imagine an attacker not as a hoodie-wearing wizard wrestling with your firewall, but as someone quietly slipping through an unlocked back door with keys they bought on the dark web. In this episode we sit down with Corrine Jefferson, a former government cyber professional who now helps UK small businesses understand how real attackers operate.
Grounded in Palo Alto Networks Unit 42's Global Incident Response Report 2026, our conversation is built on more than 750 serious, real-world investigations from October 2024 to September 2025. Not theory. Not vendor marketing. Actual cases. The numbers are stark: identity weaknesses featured in nearly 90% of incidents, and 65% of all initial access was identity-driven.
We start by setting the scene: your people live in the browser. Outlook, payroll, Teams, your CRM, and a pile of SaaS tools. That ordinary click is the battleground. Attackers buy credentials, harvest session tokens, and exploit OAuth grants. Once they have a valid login, they blend into normal traffic and move silently. Corrine brings these statistics to life with vivid examples of reused passwords, push-MFA fatigue, shared admin accounts, and contractors who still have permanent access three years after leaving.
The stakes are immediate. Unit 42 found that the fastest quarter of intrusions reached data theft in just 72 minutes, down from 285 minutes the previous year. A simulated AI-assisted attack did it in 25 minutes. That means from one careless click to your customer data being packaged for extortion can happen faster than a cup of tea.
This episode guides you away from romantic myths about firewalls and sophisticated exploits and toward the uncomfortable truth: most breaches are enabled by preventable exposure and excessive identity trust.
We walk through the failure modes that make small businesses attractive targets: recycled passwords, MFA that's easy to social-engineer, standing global admin accounts, and forgotten integrations that act like zombie doors. Corrine explains why these aren't technical puzzles for nation-states. They are human, operational, and fixable. She also lays out how attackers exploit browser-based OAuth flows and session cookies to live off long-lived access without ever triggering an alert.
This is not just a lecture. It is a plan.
If you do one thing this quarter, make it identity. If you do one thing this week, do these three: deploy phishing-resistant MFA for admins and finance roles; remove or disable all ex-employee and contractor accounts across Microsoft 365, your VPN, and remote support tools; and cut standing admin rights while shortening session lifetimes on sensitive applications.
By the end of the episode you will see the difference between spending on another perimeter box and actually locking the doors that matter. This is a call to action for small businesses: stop hoping you will not be targeted and start hardening the identities attackers are already using.
Three Actions You Can Take This Week
Action 1: Deploy Phishing-Resistant MFA
What: FIDO2 hardware security keys or passkeys. Not SMS codes. Not basic push notifications.
Where to start: Administrators, finance roles, and anyone with access to sensitive data or privileged systems.
Why it matters: Standard push-based MFA is vulnerable to adversary-in-the-middle attacks and push-bombing. FIDO2 provides phishing resistance, guessing resistance, and theft resistance.
NCSC guidance: FIDO2 is recommended by the NCSC as the strongest available MFA type for UK organisations. Hardware options include Authentrend, Keys, Platform options include Windows Hello for Business and Apple Touch ID.
Action 2: Remove Zombie Access
What to audit and disable:
- All accounts belonging to former employees
- All accounts belonging to former contractors
- Unused service accounts
- Dormant OAuth integrations and app permissions
Where to look: Microsoft 365 Admin Centre, your VPN gateway, remote support tools, and any SaaS platform connected to your business.
Why it matters: Unit 42 found that 99% of 680,000 cloud identities had excessive permissions, many unused for 60 days or more. Each one is an unlocked back door.
How to find OAuth zombies: In Microsoft 365, go to Azure Active Directory > Enterprise Applications > All Applications. Sort by last sign-in date. Revoke anything unrecognised or unused.
Action 3: Eliminate Standing Admin Rights
What: Move from permanent administrator accounts to just-in-time (JIT) privilege elevation.
How:
- Remove persistent administrator role grants
- Require time-bound elevation through Microsoft Entra Privileged Identity Management or equivalent
- Shorten session lifetimes on sensitive applications
- Enable strong logging on all privilege escalation events
Why it matters: A compromised account with no standing privileges yields nothing. JIT elevation changes the attacker's calculation from "I have the keys" to "I have nothing."
Sources and References
Â
Â
| Source | Resource |
|---|---|
| Palo Alto Networks Unit 42 | Global Incident Response Report 2026 (Full Report) |
| Palo Alto Networks Unit 42 | Global Incident Response Report 2026 (Executive Edition) |
| Palo Alto Networks | Unit 42 Global IR Report 2026: Blog Summary |
| NCSC | Multi-Factor Authentication for Your Corporate Online Services |
| NCSC | Recommended Types of MFA |
| NCSC | Authentication Methods: Choosing the Right Type |
| NCSC | Cyber Essentials Scheme Overview |
| NCSC | NCSC: Information for Small and Medium-Sized Organisations |
| FIDO Alliance | FIDO2: Web Authentication Standards |
| MITRE ATT&CK | T1219: Remote Access Tools (Referenced in Unit 42 C2 Data) |
Â
#CyberSecurity #SmallBusinessSecurity #IdentitySecurity #MFA #FIDO2 #Passkeys #UKBusiness #CyberEssentials #CyberSecurityPodcast #SecurityAwareness #TechPodcast #NoBS #SmallBizTech #CyberResilience #DirectorAccountability #BusinessRisk #DataProtection #GDPR #ZeroTrust #CloudSecurity #SaaSSecurity #IncidentResponse #ThreatIntelligence #IdentityManagement #SessionSecurity #Unit42 #PaloAltoNetworks #NCSC #CyberAware #UKCyber
Â
Disclaimer
This podcast provides general cybersecurity guidance based on publicly available research and industry best practices. It is not a substitute for professional security assessment or legal advice. Organisations should consult qualified security professionals and legal counsel to address their specific circumstances and regulatory requirements.
All statistics cited from the Unit 42 Global Incident Response Report 2026, published by Palo Alto Networks, covering incident response engagements between 1 October 2024 and 30 September 2025. NCSC guidance referenced is published by the UK National Cyber Security Centre. All URLs verified at time of publication.

Monday Mar 02, 2026
Three and a Half Pence: The Currys Breach That Took Nine Years to Matter
Monday Mar 02, 2026
Monday Mar 02, 2026
Picture yourself tapping your card at a bustling store, the till chirps, you walk away thinking thatâs the end of the story. For millions of Currys' customers, that ordinary moment in 2017 was the opening scene of a nearly decade-long drama that would ripple through courtrooms, regulator offices and countless inboxes. This episode unpeels that story â malware on thousands of point-of-sale terminals, 14 million people exposed, and a legal fight that turned a monumental failure into what worked out as roughly three and a half pence per person under the old law.
We set the scene as a crime thriller: silent malware skimming payment data across 5,390 tills for nine months, basic security absent where it mattered most, and a regulator reaching for the only enforcement tool it had under an older statute. Then the plot thickens. DSG fights back, tribunals slice and dice the ICOâs case, and years of appeals stretch this into a slow-motion moral fable about who the system really protects.
But this isnât just legal theatre â itâs human fallout. We follow the people on the receiving end: anxious customers, stalled group claims, and a lone litigant whose attempt at compensation is bounced between courts and stays. By the time the Court of Appeal finally says the obvious â a retailer that can link card numbers to people must treat them as personal data â most victims are already out of time to sue. The episode shows how the machinery of justice can leave ordinary people stranded.
Alongside the outrage, we pull apart the courtroom arguments that nearly let a multinational off the hook: the dangerous idea of judging identifiability from a hackerâs viewpoint, and the peril of treating data fragments as harmless. The Court of Appealâs eventual clarity is legally important, but the delay exposes a chilling truth â if youâve got deep pockets, you can litigate and wait out consequences while victims go uncompensated.
This is also a playbook episode for anyone who runs a small or mid-sized business. We translate the Court of Appealâs ruling into a simple controllerâs-eye test you can run on Monday morning: if you, as the organisation, can link data to a person, itâs personal and worth protecting. From that test we give concrete, low-cost actions: map your data, cut unnecessary access, name who watches your logs, patch and MFA the essentials, and keep a one-page accountability pack that proves you took reasonable steps.
We donât just point fingers â we hand you a route out. The Currys' saga becomes the cautionary tale that makes the normal business case for basics suddenly urgent: monitoring that notices intrusions, access reviews that kill zombie accounts, and documentation that shows youâre not winging it. Do these things and you move from case study risk to trusted steward of customer data.
Finally, the episode is a story of how law, business and people collide â a vivid reminder that prevention matters more than litigation, and that the protections for customers are only as strong as the choices organisations make before the breach. Tune in to feel the outrage, understand the legal twists, and walk away with practical steps to stop your business from becoming headline fodder nine years from now.

Monday Feb 23, 2026
Locked In: Palantir, Microsoft and the Hidden Political Risk in Your Cloud
Monday Feb 23, 2026
Monday Feb 23, 2026
Picture this: youâre a minister in Europe and Washington quietly asks for a peek. Your emails, drafts and cabinet notes arenât in a secret vault â they live on someone elseâs servers. This episode opens on that impossible, very real moment and follows the ripple effects: threats of sanctions, a neutral Switzerland walking away from Palantir, and the uncomfortable truth that the UK handed that very company the keys to its health, defence and policing systems.
We meet the players: Noel Bradford, the Small Business Cybersecurity Guy, whoâs spent four decades turning tape backups into survival tactics; Corinne Jefferson, an ex-US intelligence officer who refuses to say âtold you soâ; Mauven MacLeod, the ex-UK government cyber analyst with biscuits and sarcasm; and Graham Falkner, whose voice narrates the creeping, bureaucratic apocalypse with unnerving charm. Together they pull the camera tight on Palantir â a firm born with CIA-connected funding, hardened in intelligence use, repackaged for civilian life â and show how its DNA matters for everyone from governments to your local charity.
The episode walks you through the high-stakes decisions: Switzerlandâs 2024 risk assessment that warned data could be reached by American authorities and that leaks from Palantir are architecturally unavoidable; the UKâs contrasting embrace of the same tools across NHS, the MOD and border planning; and how this divergence should set off alarms for every organization that has leaned on US SaaS as neutral plumbing.
We translate the legal jargon into a human story. Think of the Cloud Act like an American landlord who can be ordered to open a warehouse â even if your files are stored in London. Encryption doesnât save you unless you control the keys. UK and EU data rules complicate the picture but donât yet provide a clean escape. That legal murk leaves businesses and charities sitting on unquantified exposures â not because theyâre spies, but because convenience and market share created choke points that politics or courts can exploit.
This isnât fearmongering; itâs a practical wake-up call. Noel guides you through what to do next: a simple Cloud Act exposure audit, naming your crown-jewel data, and deciding which systems deserve extra protection or customer-managed keys. The episode offers concrete, manageable steps â split sensitive fields, demand clear vendor answers, build exit plans â so your small firm isnât left exposed if geopolitics changes the rules.
By the end youâll see the world differently: your email and CRM arenât just tools, theyâre legal and geopolitical choices. The narrative closes on an urgent but solvable note â map your dependencies, protect what matters, and start asking the awkward questions. The story lands as both a warning and a roadmap: serious, fixable, and essential for anyone who cares where their data really lives.