The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy

Latest episode
110 episodes
- It begins with a simple, uneasy question: can the system make Graham say something he never said? The hosts ā Lucy, Noel and Graham ā turn a nagging fear into a tense, curious investigation as they lift the curtain on how this podcast is made. What follows is less technical lecture and more confessional roadātest: rehearsal recordings, AI voice models, and the missing line that could break a Mondayāmorning episode. That single scenario becomes a moral pressure test for rules that sound good on paper but buckle the moment a deadline arrives.
From the recorded conference call to the final rendered voice, the episode walks you through every trap: perfect transcriptions that lie by omission, an AI that āhelpsā by inventing clearer phrasing, suppliers who change terms overnight, and the awkward realisation that consent to model a voice is not ownership over the person behind it. The hosts push their own policies until they crack, showing how context ā whoās available, whoās under pressure, what the sponsors want ā determines whether a guardrail holds or fails.
Through punchy examples and studio anecdotes, the conversation pivots to the cornerstones of sensible governance: precise rules not vague aspirations, logging and provenance where decisions matter, incident plans written before disaster, and human authority that can actually say no. Small businesses eavesdropping on this exchange get a practical lesson: donāt pretend AI is brandānew ā apply the governance you already know, but shore it up where AI amplifies risk.
Listeners will feel the tension between convenience and integrity as the hosts debate whether corrected facts, edited context, and lateāminute fixes can ever be rendered in someone elseās voice without permission. The episode doesnāt demonise the technology; instead it teases out the choices that make it trustworthy or dangerous. Identity protection, transparent disclosure, and who gets to approve final wording become the storyās beating heart.
By the end youāre left with a challenge: imagine the moment when following the rule costs you time, money or an episode ā and decide in advance which matters more. With humour, practical steps and a few studio confessions, this episode becomes a toolkit and a cautionary tale: design guardrails that survive a busy Monday morning, then try to break them before someone else does. - It begins like a quiet, ordinary audit: an annual security check, the kind of routine that should leave you reassured. Instead, it ends with a single line of data that changes everything ā the password for a shared Microsoft 365 admin identity appears in a dark web credential dump. What follows is not a thriller about dramatic hacks and midnight ransom notes, but a far more unsettling story about assumptions, convenience and the slow drift from policy to peril.
Lucy, Noel and Graham walk you through the discovery as if you were in the room with them: the initial disbelief, the precise questions, the careful parsing of what the presence of that credential does ā and does not ā prove. It doesnāt prove an active compromise of the tenant. It doesnāt show that funds were stolen or files siphoned off. But it does prove that a secret is no longer secret, and that the one basic thing security is supposed to give you ā accountability ā had been quietly surrendered when a single identity came to stand for many people.
From there the podcast moves from theory into instant reality. Decisions that once felt academic ā whether to stop sharing logins, whether to require stronger authentication, whether to upgrade licensing ā become urgent actions: rotate the credential, remove shared access, review sign-in history, audit privileges and hunt for suspicious activity. The hosts take you through the pragmatic steps of containment and investigation while unpacking why a shared admin account complicates every element of incident response and attribution.
But this episode is more than a checklist. Itās a lesson in governance, risk and compliance told through human voices and wry commentary: who owned the decision to allow shared identities, how risks were underestimated for convenience, and why compliance isnāt a spreadsheet of green boxes but evidence you can show when someone actually looks. The narrative sharpens when the hosts confront the uncomfortable truth ā reality will audit you for free, and often at the worst possible moment.
Technology and nuance weave through the conversation: the protective value of MFA and conditional access only matters if theyāre configured and enforced; for privileged roles, the hosts explain Microsoftās move toward phishing-resistant authentication like passkeys and FIDO2 keys. Practical, bite-sized guidance sits next to the wider cultural point: security work is rarely thrilling, and yet its quiet, boring practices are the very things that stop bad things from happening.
There are human touches too ā the recurring joke about āFred,ā the imaginary multi-person identity that logs in from everywhere, and the admission that the show itself uses AI in all aspects of production under strict guardrails. That revelation becomes a mini-case study about governance again: how consent, editorial control and strict boundaries turn the same technology that can impersonate into a tool for protection and clarity.
The episode ends with a clear, actionable offer ā ten free dark web credential scans and a final provocation: donāt ask whether anything bad has happened to you; ask what evidence you have that nothing bad has happened. Itās an eerie, practical close to a four-part series that began with frameworks and finished by meeting the messy, inconvenient truth of real systems.
Listen for the human conversations, the forensic thinking, and the bitingly honest moment when a routine audit turns a hypothetical risk into a concrete problem. This is a story about small decisions with big consequences ā and about the steady, sometimes boring work that keeps businesses secure. - We start with a number: 94% ā the share of UK business leaders who say theyāre confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require twoāfactor authentication, 31% report boardālevel ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident.
In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isnāt a security control. Saying āweād cope with ransomwareā is not the same as proving youāve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it.
We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change ā rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated.
Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and highāprofile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it?
āComplianceā is rescued from the textbook. It becomes three things: policy (the decision youāve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre ā beautifully formatted fiction where every box is green ā and replaces it with operational tests that matter.
Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same āFred.ā Accountability disappears, and with it the ability to respond credibly to an incident.
There are no magic words or silver bullets: Cyber Essentials isnāt a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline ā a prompt to prove the controls you claim to have.
Before you turn off the show, the hosts hand you an unpretentious toādo list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than oneāoff paperwork.
By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered ā convinced that good security can be practical and affordable, but only if leaders stop saying theyāre secure and start showing it. - Right before our episode even starts, Lucy fires off eleven frantic links and a small panic spreads across the internet. By link six the certainty that passkeys and MFA have been obliterated is trending, and by link eleven everyoneās convinced civilisation ends at lunch. But the truth is never that neat ā itās messier, quieter and far more instructive. This episode unpicks the chaos: two separate technical stories, one social-media meltdown, and the same underlying culprit everywhere ā assumptions.
First: the dramatic-sounding Pass2Key research. On paper, no cryptography was broken ā the maths behind passkeys still holds. The real problem was the plumbing: synced passkeys, how browsers and operating systems handle master secrets, and how malware running as the user can abuse legitimate system calls to register keys or read secrets. That means an attacker who already has code on your machine can escalate in ways that look like magic but are really just human error, misplaced trust and sloppy implementation. Itās not a cinematic hack; itās a mundane, terrifying erosion of the guarantees people thought they had.
Second: a phishing-as-a-service campaign that rents out a tiny piece of surveillance-and-relay infrastructure for the price of an office chair. Victims were sent to Microsoftās genuine login flow and tricked into entering device codes that authorised an attackerās session ā MFA worked exactly as designed, but for the wrong person. Elegant, low-tech and brutal in its effectiveness. Again, no zero-day, just attackers exploiting human workflows and long-forgotten trust settings.
These two tales converge on the same point: risk isnāt a spreadsheet you update once a year. Itās the gap between what you believe your controls do and what they actually do in the wild. Someone chose to accept behaviour labelled āintended.ā Someone else left a trusted sender in place because it once solved a problem. Months or years later those choices become the breadcrumbs attackers follow.
We tell this episode as a story because thatās how decisions land with people: Lucyās doom-scrolling, Noelās exasperation, the nameable exploits and the small, human details ā Dave at his desk blissfully unaware, the enrolment process left half-finished, an organisation that never questioned an old mail rule. Those moments are where governance, risk and compliance actually live, and where small businesses can make practical, immediate changes.
Listen for concrete takeaways ā what to do today, this month, and for high-risk accounts. Move people off SMS, audit trusted senders, check registered devices and sessions, train staff not to enter device codes they didnāt initiate, and consider hardware keys for admin and finance roles. These steps are boring and effective: better than panicking, and far better than reverting to passwords.
By the end of the episode the panic has become a lesson: passkeys arenāt dead, MFA isnāt pointless, and TikTok cybersecurity advice can be dangerously loud if itās not grounded in the research. More importantly, risk is revealed as a human story ā assumptions, decisions, and the uncomfortable question of who owned the trade-off. If you want a framework for fixing that, stick around: our next instalment on compliance will chase the policy side of the same story. Meet Dave: From GasāSafe to CyberāSafe ā A Small Business Survival Story (Part1)
08/03/2026 | 26 mins.Three lettersāGāRāCāsound like corporate nonsense until they stand between a business that survives a bad day and one that doesnāt.
Pull up a stool: this episode meets Dave, who runs a 14āperson heating firm and would sooner let an unqualified person near a boiler than admit his office could be a target. Heās gasāsafe, insured, and obsessive about paperwork when lives are at stake.
But his cybersecurity? That lives in his head, or a postāit, or a notebook in a top drawerāand thatās the exact thing that turns a sprained ankle on the ski slopes into a potential business disaster.
We tell Daveās story as a practical, human drama: a boss who is used to owning everything, who breaks a leg in the French Alps, and a normal Friday where invoices are due and systems wobble. The computers obey the rules theyāre given; the business fails when nobody decided what the rules were.
Governance isnāt a committee or a legal briefāitās four lines on a page: who owns security, who decides spending, who we ring when it all goes wrong, and where the passwords live. That simple sheet saves the day when Priya at the front desk gets an email that looks exactly like a supplierāsāand the rule written on a calm Tuesday avoids four grand of invoice fraud on a frantic Friday.
This episode uses storytelling to make the abstract vivid: the harmless phrase āweāre too small for thisā becomes a trap, the notebook of passwords becomes a ticking time bomb, and a oneāpage decision becomes the difference between chaos and calm. Youāll hear practical scenes, not slidesāhow a named human owner, a handful of decisions, and a quarterly 10āminute review turn security into something usable, not terrifying.
By the end youāll have three simple actions you can do this week: name the person who owns your security out loud; start your oneāpage governance sheet; and set a recurring threeāmonth GRC reminder. Small, concrete moves that take minutes and protect years of work. If youāre a small business owner who thinks cyber is someone elseās problem, this episode is the wakeāup call delivered over a pintāfriendly, practical, and impossible to ignore.
More Business podcasts
Trending Business podcasts
About The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.šÆ WHAT YOU'LL LEARN:
Cyber Essentials certification guidance
Protecting against ransomware & phishing attacks
GDPR compliance for small businesses
Supply chain & third-party security risks
Cloud security & remote work protection
Budget-friendly cybersecurity tools & strategies
š PERFECT FOR:
UK small business owners (5-50 employees)
Startup founders & entrepreneurs
SME managers responsible for IT security
Professional services firms
Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Podcast websiteListen to The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups, The Learning Leader Show With Ryan Hawk and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
Scan code,
download the app,
start listening.
download the app,
start listening.
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups: Podcasts in Family


























