The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy

Latest episode
107 episodes
- Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyone’s convinced civilisation ends at lunch. But the truth is never that neat — it’s messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere — assumptions.
First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken — the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. It’s not a cinematic hack; it’s a mundane, terrifying erosion of the guarantees people thought they had.
Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoft’s genuine login flow and tricked into entering device codes that authorised an attacker’s session — MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings.
These two tales converge on the same point: risk isn’t a spreadsheet you update once a year. It’s the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled “intended.” Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow.
We tell this episode as a story because that’s how decisions land with people: Lucy’s doom-scrolling, Noel’s exasperation, the nameable exploits and the small, human details — Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes.
Listen for concrete takeaways — what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didn’t initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords.
By the end of the episode the panic has become a lesson: passkeys aren’t dead, MFA isn’t pointless, and TikTok cybersecurity advice can be dangerously loud if it’s not grounded in the research. More importantly, risk is revealed as a human story — assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story. Meet Dave: From Gas‑Safe to Cyber‑Safe — A Small Business Survival Story (Part1)
03/08/2026 | 26 mins.Three letters—G‑R‑C—sound like corporate nonsense until they stand between a business that survives a bad day and one that doesn’t.
Pull up a stool: this episode meets Dave, who runs a 14‑person heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. He’s gas‑safe, insured, and obsessive about paperwork when lives are at stake.
But his cybersecurity? That lives in his head, or a post‑it, or a notebook in a top drawer—and that’s the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster.
We tell Dave’s story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules they’re given; the business fails when nobody decided what the rules were.
Governance isn’t a committee or a legal brief—it’s four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplier’s—and the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday.
This episode uses storytelling to make the abstract vivid: the harmless phrase “we’re too small for this” becomes a trap, the notebook of passwords becomes a ticking time bomb, and a one‑page decision becomes the difference between chaos and calm. You’ll hear practical scenes, not slides—how a named human owner, a handful of decisions, and a quarterly 10‑minute review turn security into something usable, not terrifying.
By the end you’ll have three simple actions you can do this week: name the person who owns your security out loud; start your one‑page governance sheet; and set a recurring three‑month GRC reminder. Small, concrete moves that take minutes and protect years of work. If you’re a small business owner who thinks cyber is someone else’s problem, this episode is the wake‑up call delivered over a pint—friendly, practical, and impossible to ignore.The Open Book Problem 5: Closing it with Practical Defences for Small Businesses
27/07/2026 | 21 mins.The final episode in the five-part Open Book series delivers a practical action plan for UK small business directors facing public data exposure. Noel Bradford and the SBCSG team rank OSINT risks by real attack potential, from identity compromise to technical targeting.
Graham Falkner provides a 30-day implementation plan covering Companies House corrections, electoral register opt-outs, data broker removal, and process hardening.
Mauven MacLeod examines the policy gaps that leave individuals absorbing systemic risk, while
Lucy Harper summarises outstanding accountability questions for regulators and government. The episode includes a board-level conversation framework, guidance on when to seek help, and a tabletop exercise for testing verification processes. This is not about vanishing from the internet. It is about reducing avoidable harm, prioritising exposure that enables fraud, and turning regulatory frustration into collective pressure for structural reform.- Delete Me and Incogni aren't scams. That's a sensible place to start. But as this episode of The Open Book Problem unfolds, a quieter, sharper scandal emerges: a paid subscription market built on a failure that should never have been dumped on ordinary people.
Meet the protagonist of our story — a UK small-business director who wakes up one morning to discover their home address, director profile and personal history strewn across search results, broker sites and public registers. The immediate villains seem obvious: people-search sites, aggressive broker ecosystems and glossy removal services promising a clean slate. But the real antagonist is a broken system that forces busy people to choose between unpaid, tedious labour and handing their privacy to a subscription. - GDPR promised control: erasure, access, objection, transparency. In this episode, Noel Bradford and Lucy Harper walk us into the yawning gap between those beautiful legal words and the grinding reality where data brokers collect, enrich and re‑sell people’s lives at scale. The narrative opens with a simple scene — a small business director, a home address, a labrador, a ring doorbell — and slowly reveals how that ordinary detail becomes a powerful asset when combined with brokered profiles.
More Business podcasts
Trending Business podcasts
About The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.🎯 WHAT YOU'LL LEARN:
Cyber Essentials certification guidance
Protecting against ransomware & phishing attacks
GDPR compliance for small businesses
Supply chain & third-party security risks
Cloud security & remote work protection
Budget-friendly cybersecurity tools & strategies
🏆 PERFECT FOR:
UK small business owners (5-50 employees)
Startup founders & entrepreneurs
SME managers responsible for IT security
Professional services firms
Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Podcast websiteListen to The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups, Better With Money and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
Scan code,
download the app,
start listening.
download the app,
start listening.
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups: Podcasts in Family

































