The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy

Latest episode
112 episodes
- Three headlinesāan EU law delay, an AI-accelerated intrusion that went from weeks to hours, and a UK bill about to bring hundreds of IT providers under direct regulationāsound like stories from different podcasts. They arenāt. By the end of this episode, they meet in a single, worrying place: the gap between assumption and evidence.
Follow Noel Bradford, Lucy Harper and Corrine Jefferson as they trace that gap through vivid scenes: a quiet lawroom in Brussels that postponed some deadlines but switched major penalties on; a Unit 42 investigation where one attacker, helped by AI, compressed reconnaissance, exploitation and extortion into under ten hours; and Westminsterās Cybersecurity and Resilience Bill that could force managed service providers to register, report incidents quickly, and face heavy fines. Along the way, the podcast lights up small, human detailsāa heating engineerās paperwork, a builderās son who inherited the IT, a host who reads breach reports like gas billsāto show how ordinary businesses get dragged into extraordinary risk.
They donāt just explain the problems; they show how the threads tie together. The EUās AI Act makes clear obligations for providers of large models but only if you can first answer the simple question: what AI do you actually use? The attack demonstrates the lethal value of timeāalerts that wait in an inbox are useless when an attacker finishes a campaign before most people have their second cup of coffee. The UK bill exposes who truly owns the decision when an outsourced provider goes dark: legal reporting may hit the MSP, but operational pain lands with the client.
Alongside sharp investigations into LG TV privacy claims and a cunning "click-to-fix" browser-cache exploit, the episode turns practical. It hands you three urgent morning-after questions to take to your board: what AI does your business use (and who owns it), could you detect and respond within ten hours, and is your IT provider positioned to be regulated? If you canāt answer those now, this episode will make it impossible to shrug them off.
Listen for clear, actionable stepsāvisibility, speed and ownershipāthat every small business needs before the clocks of law, crime and regulation collide. - They put a fat green 0% on the slide and everyone nodded like it meant victory. Gary, a builder with plasterboard and vans on his mind, sips his tea and wonders why cyber security suddenly sounds like someone elseās problem ā until the hosts pull that cheerful number apart. What looks like perfect protection can be a mirage: a workforce trained to pass one test but not to spot the real, messy tricks criminals use when a delivery is late or an invoice changes.
In this episode, Noel and Morvan walk Gary ā and you ā through the slow unravelling of that comforting 0%. We follow a year of simulated attacks from a vendorās dataset and watch a story unfold: clicks fall, then spike, and finally settle ā not because people got stupider, but because the tests got harder and started catching the vulnerabilities that easier simulations missed.
Through vivid examples (the parcel everyone waits for, Dave who closes a window and hopes no one noticed, and a frantic phone call that saves the company money), the hosts tease out the real lessons. Clicks are not binary verdicts; they are one link in a chain that includes credential submission, MFA failures, and the crucial moment when someone chooses to report the suspicious message.
Reporting becomes the episodeās hero: a single employee who says āthis looks oddā can protect an entire team. The conversation turns practical ā one big, easy-to-press button, quick acknowledgement, and a culture that thanks people for coming forward instead of shaming them. The narrative pivots from blaming individuals to building systems that survive human error.
By the end youāll see why insurers and dashboards obsessed with a single percentage get a dangerously incomplete picture, and why better metrics ā credential leaks, reporting rates, testing difficulty, and report speed ā reveal a healthier story. The episode closes with four concrete steps Gary can take on Monday morning and a rallying cry: donāt chase perfect green ticks; build processes that turn your people into the sensors that actually keep you safe. - It begins with a simple, uneasy question: can the system make Graham say something he never said? The hosts ā Lucy, Noel and Graham ā turn a nagging fear into a tense, curious investigation as they lift the curtain on how this podcast is made. What follows is less technical lecture and more confessional roadātest: rehearsal recordings, AI voice models, and the missing line that could break a Mondayāmorning episode. That single scenario becomes a moral pressure test for rules that sound good on paper but buckle the moment a deadline arrives.
From the recorded conference call to the final rendered voice, the episode walks you through every trap: perfect transcriptions that lie by omission, an AI that āhelpsā by inventing clearer phrasing, suppliers who change terms overnight, and the awkward realisation that consent to model a voice is not ownership over the person behind it. The hosts push their own policies until they crack, showing how context ā whoās available, whoās under pressure, what the sponsors want ā determines whether a guardrail holds or fails.
Through punchy examples and studio anecdotes, the conversation pivots to the cornerstones of sensible governance: precise rules not vague aspirations, logging and provenance where decisions matter, incident plans written before disaster, and human authority that can actually say no. Small businesses eavesdropping on this exchange get a practical lesson: donāt pretend AI is brandānew ā apply the governance you already know, but shore it up where AI amplifies risk.
Listeners will feel the tension between convenience and integrity as the hosts debate whether corrected facts, edited context, and lateāminute fixes can ever be rendered in someone elseās voice without permission. The episode doesnāt demonise the technology; instead it teases out the choices that make it trustworthy or dangerous. Identity protection, transparent disclosure, and who gets to approve final wording become the storyās beating heart.
By the end youāre left with a challenge: imagine the moment when following the rule costs you time, money or an episode ā and decide in advance which matters more. With humour, practical steps and a few studio confessions, this episode becomes a toolkit and a cautionary tale: design guardrails that survive a busy Monday morning, then try to break them before someone else does. - It begins like a quiet, ordinary audit: an annual security check, the kind of routine that should leave you reassured. Instead, it ends with a single line of data that changes everything ā the password for a shared Microsoft 365 admin identity appears in a dark web credential dump. What follows is not a thriller about dramatic hacks and midnight ransom notes, but a far more unsettling story about assumptions, convenience and the slow drift from policy to peril.
Lucy, Noel and Graham walk you through the discovery as if you were in the room with them: the initial disbelief, the precise questions, the careful parsing of what the presence of that credential does ā and does not ā prove. It doesnāt prove an active compromise of the tenant. It doesnāt show that funds were stolen or files siphoned off. But it does prove that a secret is no longer secret, and that the one basic thing security is supposed to give you ā accountability ā had been quietly surrendered when a single identity came to stand for many people.
From there the podcast moves from theory into instant reality. Decisions that once felt academic ā whether to stop sharing logins, whether to require stronger authentication, whether to upgrade licensing ā become urgent actions: rotate the credential, remove shared access, review sign-in history, audit privileges and hunt for suspicious activity. The hosts take you through the pragmatic steps of containment and investigation while unpacking why a shared admin account complicates every element of incident response and attribution.
But this episode is more than a checklist. Itās a lesson in governance, risk and compliance told through human voices and wry commentary: who owned the decision to allow shared identities, how risks were underestimated for convenience, and why compliance isnāt a spreadsheet of green boxes but evidence you can show when someone actually looks. The narrative sharpens when the hosts confront the uncomfortable truth ā reality will audit you for free, and often at the worst possible moment.
Technology and nuance weave through the conversation: the protective value of MFA and conditional access only matters if theyāre configured and enforced; for privileged roles, the hosts explain Microsoftās move toward phishing-resistant authentication like passkeys and FIDO2 keys. Practical, bite-sized guidance sits next to the wider cultural point: security work is rarely thrilling, and yet its quiet, boring practices are the very things that stop bad things from happening.
There are human touches too ā the recurring joke about āFred,ā the imaginary multi-person identity that logs in from everywhere, and the admission that the show itself uses AI in all aspects of production under strict guardrails. That revelation becomes a mini-case study about governance again: how consent, editorial control and strict boundaries turn the same technology that can impersonate into a tool for protection and clarity.
The episode ends with a clear, actionable offer ā ten free dark web credential scans and a final provocation: donāt ask whether anything bad has happened to you; ask what evidence you have that nothing bad has happened. Itās an eerie, practical close to a four-part series that began with frameworks and finished by meeting the messy, inconvenient truth of real systems.
Listen for the human conversations, the forensic thinking, and the bitingly honest moment when a routine audit turns a hypothetical risk into a concrete problem. This is a story about small decisions with big consequences ā and about the steady, sometimes boring work that keeps businesses secure. - We start with a number: 94% ā the share of UK business leaders who say theyāre confident they could detect and respond to a cyber attack. Then we add the counterpunch: 47% require twoāfactor authentication, 31% report boardālevel ownership of cyber, and just 5% hold Cyber Essentials. That mismatch is the spark for a story about confidence, evidence, and what really happens when theory meets a real incident.
In this episode two hosts trade barbed banter and hard questions, peeling back the myths that make organisations feel safe. Confidence, they argue, isnāt a security control. Saying āweād cope with ransomwareā is not the same as proving youāve tested a restore at two in the morning. The narrative pivots on a single, simple demand: prove it.
We follow two small business case studies that bring the stakes into sharp relief. One firm clings to shared identities, ancient laptops and convenient workarounds; the other quietly accepts practical change ā rolling out managed devices, conditional access and enforced MFA. Both started imperfect. One accepted reality and fixed it. The other negotiated around controls until accountability evaporated.
Along the way the episode lands hard facts: the National Cyber Security Centre handles an average of four nationally significant incidents each week, and highāprofile victims are not immune. The hosts use these data points not to terrify but to sharpen the question every board should ask: where does our confidence come from, and can we show it?
āComplianceā is rescued from the textbook. It becomes three things: policy (the decision youāve made), control (the technical enforcement) and evidence (the logs, tests and restores that prove it actually works). The show dismantles compliance theatre ā beautifully formatted fiction where every box is green ā and replaces it with operational tests that matter.
Listeners get practical storytelling: imagine being audited six months from now and asked who accessed a client file. In one business the audit trail names individuals and shows MFA enforced. In the other, five people all log in as the same āFred.ā Accountability disappears, and with it the ability to respond credibly to an incident.
There are no magic words or silver bullets: Cyber Essentials isnāt a forcefield, but it forces an organisation to answer specific questions at a point in time. The episode argues passionately that certification matters less as a guarantee and more as a discipline ā a prompt to prove the controls you claim to have.
Before you turn off the show, the hosts hand you an unpretentious toādo list: name the person who owns cyber risk, enforce strong authentication everywhere it matters, actually restore backups, reduce admin counts, and store emergency contacts where they can be reached if your cloud goes dark. Small steps, repeatedly tested, win far more than oneāoff paperwork.
By the end the narrative comes full circle: confidence without demonstrable controls is denial in a suit. The episode leaves listeners both chastened and empowered ā convinced that good security can be practical and affordable, but only if leaders stop saying theyāre secure and start showing it.
More Business podcasts
Trending Business podcasts
About The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.šÆ WHAT YOU'LL LEARN:
Cyber Essentials certification guidance
Protecting against ransomware & phishing attacks
GDPR compliance for small businesses
Supply chain & third-party security risks
Cloud security & remote work protection
Budget-friendly cybersecurity tools & strategies
š PERFECT FOR:
UK small business owners (5-50 employees)
Startup founders & entrepreneurs
SME managers responsible for IT security
Professional services firms
Anyone wanting practical cyber protection advice
Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies
Podcast websiteListen to The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups, the bossbabe podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
Scan code,
download the app,
start listening.
download the app,
start listening.
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups: Podcasts in Family


































