

214.5K
Downloads
85
Episodes
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.
🎯 WHAT YOU'LL LEARN:
- Cyber Essentials certification guidance
- Protecting against ransomware & phishing attacks
- GDPR compliance for small businesses
- Supply chain & third-party security risks
- Cloud security & remote work protection
- Budget-friendly cybersecurity tools & strategies
🏆 PERFECT FOR:
- UK small business owners (5-50 employees)
- Startup founders & entrepreneurs
- SME managers responsible for IT security
- Professional services firms
- Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.
🎯 WHAT YOU'LL LEARN:
- Cyber Essentials certification guidance
- Protecting against ransomware & phishing attacks
- GDPR compliance for small businesses
- Supply chain & third-party security risks
- Cloud security & remote work protection
- Budget-friendly cybersecurity tools & strategies
🏆 PERFECT FOR:
- UK small business owners (5-50 employees)
- Startup founders & entrepreneurs
- SME managers responsible for IT security
- Professional services firms
- Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Episodes

Thursday Jul 31, 2025
Help Desk MFA Reset Fails: Scattered Spider vs. UK Retail
Thursday Jul 31, 2025
Thursday Jul 31, 2025
Episode Description
Join Noel Bradford and Graham Falkner for another cybersecurity hot take as they dive into the alarming world of help desk social engineering attacks. This episode exposes how the notorious Scattered Spider group has weaponized basic human helpfulness to devastating effect, turning your friendly IT support into the front door for ransomware attacks.
From MGM's $100 million disaster to the recent wave of UK retail breaches (M&S, Co-op, Harrods), discover how teenagers armed with nothing more than convincing accents and sob stories are outsmarting million-pound security systems. Spoiler alert: it's not the tech that's failing us.
Key topics
- The Scattered Spider Phenomenon: Meet the English-speaking teenagers who graduated from Roblox to ransomware
- Help Desk Horror Stories: Why your MFA reset process is probably easier than ordering a dodgy kebab
- The MGM Masterclass: How one phone call led to 10 days of casino chaos
- UK Retail Ransomware Wave: The domino effect that took down half the high street
- Sandra's 3AM Security Failures: Why verification questions like "favourite biscuit" aren't cutting it
- Real Solutions That Actually Work: Beyond useless training modules to proper phishing-resistant MFA
Notable Quotes
"You can get your entire digital life reset with less hassle than ordering a dodgy kebab after the pub."
"The help desk culture these days - it's like the Wild West, but with more hold music and less gunfire."
"If your help desk can be outwitted by someone who sounds like they're late for a Fortnite tournament, you've got bigger problems than patching Windows."
"It's not hacking, it's just really, really good acting."
What You'll Learn
- How Scattered Spider targets help desk processes with surgical precision
- Why traditional security questions are laughably inadequate
- The real-world impact of social engineering attacks on major retailers
- Practical defenses that actually work (hint: it's not more training)
- Why your business might be the stepping stone, not the target
Solutions Discussed
- Video verification for all MFA resets
- Phishing-resistant MFA (FIDO2 keys, smart cards, PKI certificates)
- Proper RMM tool controls with device whitelisting and geographic restrictions
- Zero unauthenticated resets policy
- Monitoring for unusual authentication patterns
Episode Hightlights
- The career trajectory from Minecraft to MGM hacking
- Why "favourite colour" security questions are a disaster waiting to happen
- The proposed "angry Scottish nans verification panel" security policy
- The legendary cat impression MFA reset incident
- How one help desk call can ransomware half the high street
Perfect For
- Small business owners worried about cybersecurity
- IT professionals dealing with help desk security
- Anyone who's ever reset a password over the phone
- Security-conscious listeners who enjoy a good dose of British humor with their cyber threats
#Cybersecurity #ScatteredSpider #Ransomware #SocialEngineering #HelpDesk #MFA #UKRetail #MGM #SmallBusiness #InfoSec #PhishingResistant #SecurityAwareness
Remember: Security isn't about being perfect, it's about being better than the bloke next door. Don't let Sandra near the reset button after midnight!
See - https://www.noelbradford.com/blog/scattered-spider-helpdesk-mfa-reset-attack-warning-uk-2025
No comments yet. Be the first to say something!