

217K
Downloads
107
Episodes
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.
đŻ WHAT YOU'LL LEARN:
- Cyber Essentials certification guidance
- Protecting against ransomware & phishing attacks
- GDPR compliance for small businesses
- Supply chain & third-party security risks
- Cloud security & remote work protection
- Budget-friendly cybersecurity tools & strategies
đ PERFECT FOR:
- UK small business owners (5-50 employees)
- Startup founders & entrepreneurs
- SME managers responsible for IT security
- Professional services firms
- Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Episodes

7 days ago
7 days ago
26 min
Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyoneâs convinced civilisation ends at lunch. But the truth is never that neat â itâs messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere â assumptions.
First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken â the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. Itâs not a cinematic hack; itâs a mundane, terrifying erosion of the guarantees people thought they had.
Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoftâs genuine login flow and tricked into entering device codes that authorised an attackerâs session â MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings.
These two tales converge on the same point: risk isnât a spreadsheet you update once a year. Itâs the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled âintended.â Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow.
We tell this episode as a story because thatâs how decisions land with people: Lucyâs doom-scrolling, Noelâs exasperation, the nameable exploits and the small, human details â Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes.
Listen for concrete takeaways â what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didnât initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords.
By the end of the episode the panic has become a lesson: passkeys arenât dead, MFA isnât pointless, and TikTok cybersecurity advice can be dangerously loud if itâs not grounded in the research. More importantly, risk is revealed as a human story â assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story.

Aug 3, 2026
Aug 3, 2026
26 min
Three lettersâGâRâCâsound like corporate nonsense until they stand between a business that survives a bad day and one that doesnât.
Pull up a stool: this episode meets Dave, who runs a 14âperson heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. Heâs gasâsafe, insured, and obsessive about paperwork when lives are at stake.
But his cybersecurity? That lives in his head, or a postâit, or a notebook in a top drawerâand thatâs the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster.
We tell Daveâs story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules theyâre given; the business fails when nobody decided what the rules were.
Governance isnât a committee or a legal briefâitâs four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplierâsâand the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday.
This episode uses storytelling to make the abstract vivid: the harmless phrase âweâre too small for thisâ becomes a trap, the notebook of passwords becomes a ticking time bomb, and a oneâpage decision becomes the difference between chaos and calm. Youâll hear practical scenes, not slidesâhow a named human owner, a handful of decisions, and a quarterly 10âminute review turn security into something usable, not terrifying.
By the end youâll have three simple actions you can do this week: name the person who owns your security out loud; start your oneâpage governance sheet; and set a recurring threeâmonth GRC reminder. Small, concrete moves that take minutes and protect years of work. If youâre a small business owner who thinks cyber is someone elseâs problem, this episode is the wakeâup call delivered over a pintâfriendly, practical, and impossible to ignore.

Jul 27, 2026
Jul 27, 2026
21 min
The final episode in the five-part Open Book series delivers a practical action plan for UK small business directors facing public data exposure. Noel Bradford and the SBCSG team rank OSINT risks by real attack potential, from identity compromise to technical targeting.
Graham Falkner provides a 30-day implementation plan covering Companies House corrections, electoral register opt-outs, data broker removal, and process hardening.
Mauven MacLeod examines the policy gaps that leave individuals absorbing systemic risk, while
Lucy Harper summarises outstanding accountability questions for regulators and government. The episode includes a board-level conversation framework, guidance on when to seek help, and a tabletop exercise for testing verification processes. This is not about vanishing from the internet. It is about reducing avoidable harm, prioritising exposure that enables fraud, and turning regulatory frustration into collective pressure for structural reform.

Jul 20, 2026
Jul 20, 2026
18 min
Delete Me and Incogni aren't scams. That's a sensible place to start. But as this episode of The Open Book Problem unfolds, a quieter, sharper scandal emerges: a paid subscription market built on a failure that should never have been dumped on ordinary people.
Meet the protagonist of our story â a UK small-business director who wakes up one morning to discover their home address, director profile and personal history strewn across search results, broker sites and public registers. The immediate villains seem obvious: people-search sites, aggressive broker ecosystems and glossy removal services promising a clean slate. But the real antagonist is a broken system that forces busy people to choose between unpaid, tedious labour and handing their privacy to a subscription.

Jul 13, 2026
Jul 13, 2026
20 min
GDPR promised control: erasure, access, objection, transparency. In this episode, Noel Bradford and Lucy Harper walk us into the yawning gap between those beautiful legal words and the grinding reality where data brokers collect, enrich and reâsell peopleâs lives at scale. The narrative opens with a simple scene â a small business director, a home address, a labrador, a ring doorbell â and slowly reveals how that ordinary detail becomes a powerful asset when combined with brokered profiles.
Â

Jul 6, 2026
Jul 6, 2026
21 min
Imagine someone who knows your director's calendar, your payroll provider, the IT stack listed in your job ad, and the name of the accountant who signs your invoices. They don't have to be a genius â they just read what you and the public have already told them. In this episode, Noel Bradford follows that clean, quiet path of reconnaissance from public registers to a phone call that sounds unmistakably legitimate.
We open on a simple truth: most social engineering isnât a cartoon villain guessing passwords in the dark. Itâs research, timing and pressure dressed up as plausibility. Noel and Corin map the attackerâs five-step journey â selection, mapping, pretext, delivery and pressure â and show how every ordinary piece of public information becomes a tile in a convincing story.
Set against the uniquely open UK landscape of registries, data brokers and oversharing on professional networks, the episode becomes a procedural drama. Youâll hear how a directorâs LinkedIn post about a conference can set the stage for an urgent Friday payment request, how job ads can hand an attacker the exact platform to fake, and how a single helpdesk script can be the thin crack through which a whole company falls.
Through vivid examples â supplier impersonation, emergency MFA resets, Teams messages that replicate a bossâs tone â the episode explains why static verification checks fail and why âbecause the director said soâ is an invitation to fraud. We discuss Scattered Spider not to sensationalise, but to show how identity support processes become attack surfaces and why attackers treat due diligence like reconnaissance with ill intent.
Noel moves from problem to practice: concrete defensive moves you can implement today â map your public exposure, write down verification rules, require independent checks on sensitive requests, train staff on pretext and pressure (not just typos and bad links), and treat your helpdesk as a security control. The advice is practical, procedural and, yes, a little boring â because thatâs exactly what prevents crime.
By the end youâll see the small, human moments that make social engineering succeed â a rushed payment, a polite phone call, a culture that prizes speed over verification â and how changing those moments can take away an attackerâs easiest building blocks. Tune in to learn what an attacker would find about your business before lunch, and what you can remove before they get hungry.

Jun 29, 2026
Jun 29, 2026
20 min
They didnât break in. They didnât plant malware. They opened tabs, clicked links and joined the dots. In this episode we follow the quiet, methodical work of an attacker who builds a usable portrait of a UK small business director from nothing more than public records and a search box. It begins like a detective story and ends like a cautionary tale: Companies House entries, electoral data, LinkedIn posts, DNS records and job adverts become the clues that make fraud feel personal â because it is.
Through the voices of Noel Bradford and Corrine Jefferson, the episode walks you through the attackerâs timeline: the first flick through Companies House to find directors and filing rhythms, the enrichment of that picture with open-register addresses and marketing data, the human-mapping on LinkedIn, and the technical fingerprint left in DNS, MX and certificate logs. Each step is ordinary, lawful and, crucially, assembled without a single hack.
We make it concrete. In twenty minutes an attacker can produce a director profile, infer email providers, spot hiring signals that leak technology stacks, and spot behavioral seams to exploit. The lure is tailored; the language is familiar; the victim feels the email is meant for them. Social engineering stops being magic and becomes efficient administration with malicious intent â a repeatable, industrialized craft that preys on transparency.
But this episode isnât just alarmism. It frames the tension between public accountability and personal risk, showing why transparency designed for credit checks and journalism also creates a joined profile attackers love. We tell the story of how digital glitter â once data leaves its source â glints everywhere, and why suppression or removal is never instant or total.
By the end youâll feel that uncomfortable nudge: search your company on Companies House, check service addresses, review LinkedIn and job adverts, and audit your domainâs email records. The narrative closes by setting the scene for the next chapter in the series and challenging every listener to ask: what did I find about myself that an attacker could use first?

Jun 22, 2026
Jun 22, 2026
39 min
A firewall cannot save you from being badly run. For years, small businesses have been sold the idea that a perimeter box equals protection. When Fortinet disclosed exploited authentication bypass vulnerabilities, added to CISA's Known Exploited Vulnerabilities catalogue, the uncomfortable truth surfaced again: the firewall is not a wall. It is a computer at the edge of your network that runs software, has management access, and can be compromised. Defence in Depth means using multiple security layers so that when one fails, another slows the attacker, limits damage, or helps you spot the problem. The NCSC describes this as reducing single points of failure.
Yet many small businesses still operate flat networks with exposed management, weak identity, old firmware, missing logs, and untested backups. This episode unpacks the Fortinet advisory, challenges the green dashboard culture, and delivers a practical checklist for the twenty-person firm. The panel argues about MSP accountability, board responsibility, and the difference between buying comfort and buying outcomes. No vendor worship. No reassurance fog. Just evidence, ownership, and the hard questions businesses should ask before the next advisory drops.
Â