The Small Business Cyber Security Guy

Hot Takes from the Small Business Cyber Security Guy

Business EN ↓ 20 episodes

Hot Takes Hot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team. This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters: What does this mean for a real small business? Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF. We cove...

Author

The Small Business Cyber Security Guy

Category

Business

Latest episode

Jul 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

FortiBleed, Fortinet, and the Firewall That Became the Failure 10.07.2026

FortiBleed, Fortinet, and the Firewall That Became the Failure Noel Bradford unleashes a withering critique of Fortinet following the FortiBleed vulnerability’s impact on British embassies, the Foreign Office, and the British Council. This is not a balanced analysis; it is a controlled explosion aimed at a vendor that keeps appearing in credential exposure stories despite its market dominance and...

Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week) 03.07.2026

Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week) The Information Commissioner’s Office isn’t hunting your business, but that doesn’t stop small organisations from making the same three avoidable mistakes. Host Noel Bradford examines twelve recent ICO enforcement notices to identify the most common failures: no documented breach response process, insufficient staff trainin...

When Your Security Stack Becomes the Attack Surface 02.07.2026

When Your Security Stack Becomes the Attack Surface Microsoft’s security tools are supposed to protect small businesses, but recent vulnerabilities have turned that premise on its head. GreatXML exploits weaknesses in BitLocker and the Windows Recovery Environment, allowing attackers with physical access to bypass disk encryption protections. RoguePlanet, meanwhile, leverages a race condition in M...

Your Business Is an Open Book 06.06.2026

Your Business Is an Open Book Most small businesses have been building a public intelligence profile for years without realising it. Every LinkedIn update, team photo, and website contact page adds detail to a picture that anyone can view, including those with malicious intent. This episode examines open source intelligence (OSINT) and how publicly available information becomes the foundation for...

Cyber Essentials Platform Transition: What the July Deadline Means for You 05.06.2026

Cyber Essentials Platform Transition: What the July Deadline Means for You The Cyber Essentials scheme is transitioning from its Willow platform to the new Danzell version, with a go-live date now set for 6 July. Noel Bradford cuts through the noise to explain what this extension actually means for small businesses holding or pursuing certification. If you are mid-assessment, you need to check wit...

Passkeys Are Not Magic, But They Are Better Than Passwords 04.06.2026

Passkeys Are Not Magic, But They Are Better Than Passwords Noel Bradford examines passkeys, a rare security improvement that reduces phishing risk and removes the burden of password memorisation. Drawing on NCSC guidance, he explains why passkeys are resistant to credential theft, how they use cryptography tied to the service you’re logging into, and why they can be easier for users than tradition...

MFA Fatigue Is a Management Failure, Not a User Problem 03.06.2026

MFA Fatigue Is a Management Failure, Not a User Problem Multi-factor authentication is essential, but not all MFA is equal. When users receive vague, repeated, or poorly explained prompts, they start treating them like cookie banners: accept, accept, make it go away. Attackers exploit this fatigue by triggering prompts under pressure, impersonating IT support, or using social engineering to bypass...

WiFi Surveillance: When Your Router Becomes a Camera 02.06.2026

WiFi Surveillance: When Your Router Becomes a Camera WiFi feels like plumbing. It’s boring, invisible, and trusted by default. But research from Karlsruhe Institute of Technology shows that ordinary WiFi signals can now identify people with near-perfect accuracy, even when they’re not carrying an active device. This isn’t science fiction or a reason to panic. It’s a signal that infrastructure we c...

When Your SaaS Dashboard Looks Like Times Square 29.05.2026

When Your SaaS Dashboard Looks Like Times Square SaaS dashboards are increasingly cluttered with upsells, AI buttons, trial offers, and partner adverts, turning essential admin portals into noisy digital shopping centres. This creates a serious security problem: when every banner demands attention, users learn to ignore warnings, including genuine security alerts about suspicious logins, new integ...

AI Vulnerability Discovery Will Make Patch Queues Worse 28.05.2026

AI Vulnerability Discovery Will Make Patch Queues Worse AI-assisted vulnerability discovery is accelerating the rate at which security flaws are found and reported. For researchers and vendors, this is progress. For small businesses already struggling with patch management, it means more advisories, more prioritisation pressure, and more noise. Noel Bradford warns that faster discovery will expose...

Cyber Crime Is a Business Risk, Not Just an IT Budget Line 27.05.2026

Cyber Crime Is a Business Risk, Not Just an IT Budget Line Cyber crime has become a mainstream business risk, yet many UK SMBs still treat it as an IT problem to be quietly managed between printer issues and password resets. In this Hot Take, Noel Bradford argues that scams, fraud, ransomware, and account compromise belong on the risk register alongside cashflow, supplier risk, and customer retent...

The Backup Lie: Why Green Ticks Won't Save Your Business 26.05.2026

The Backup Lie: Why Green Ticks Won’t Save Your Business Most small businesses have backups. Few have tested recovery plans. In this uncompromising episode, Noel Bradford dismantles the dangerous assumption that backup equals recovery readiness. Drawing on NCSC and ICO guidance, he explains why green dashboard ticks, successful job reports, and monthly invoices create false confidence. Businesses...

Shadow AI Is Just Shadow IT Wearing a Cape 25.05.2026

Shadow AI Is Just Shadow IT Wearing a Cape Shadow AI has already arrived in most UK small businesses, often through browser tabs, SaaS tool sidebars, and helpful buttons that promise to improve text. Staff are using AI to rewrite emails, summarise meetings, polish proposals, and speed up admin tasks, frequently without approval, policy, or controls. This is shadow IT all over again, but faster and...

Curiosity as a Control: Why Asking Questions Beats Buying Tools 24.05.2026

Curiosity as a Control: Why Asking Questions Beats Buying Tools Noel Bradford argues that curiosity is one of the cheapest and most overlooked security controls in small business cyber defence. Many organisations inadvertently train staff to suppress suspicion in favour of speed, creating environments where invoice fraud, phishing, and social engineering thrive. Drawing on NCSC guidance for UK bus...

CCTV Is a Networked Computer System with Cameras (and Possibly Microphones) 23.05.2026

CCTV Is a Networked Computer System with Cameras (and Possibly Microphones) Noel Bradford challenges the persistent misconception that CCTV sits outside the cyber security estate. Many small businesses still treat cameras, recorders, door access systems and similar connected devices as facilities kit rather than networked computer systems requiring proper ownership, patching, segmentation and acce...

Cyber Security Is Not Broadband 22.05.2026

Cyber Security Is Not Broadband Noel Bradford unpacks a vendor meeting that went sideways and exposes a wider problem in the small business cyber market. As the UK’s cyber security sector grows to 2,603 firms generating £14.7 billion in annual revenue, more suppliers are packaging cyber protection like broadband bundles: one monthly fee, one portal, one reassuring product name. But when light serv...

Microsoft Authenticator Isn't Magic: The Token Leak Nobody Wants to Talk About 21.05.2026

Microsoft Authenticator Isn’t Magic: The Token Leak Nobody Wants to Talk About Microsoft Authenticator has become the identity gatekeeper for millions of Microsoft 365 users, but CVE-2025-41615 exposes a critical flaw that can leak work account access tokens after user interaction. Noel Bradford unpacks why this ‘information disclosure’ vulnerability is really an identity compromise risk, why the...

Europol Just Admitted Cybercrime Is an Industry 19.05.2026

Europol Just Admitted Cybercrime Is an Industry Europol’s IOCTA 2026 report, published on 28 April 2025, describes cybercrime not as isolated attacks but as a connected industrial economy. More than 120 active ransomware brands operated in 2025, with affiliate programmes offering margins of 80 to 85 per cent. Modern extortion has shifted from encryption to data leak threats, making backups necessa...

The Celebrity Stalkerware Leak: Not Encryption, Endpoint Compromise 17.05.2026

The Celebrity Stalkerware Leak: Not Encryption, Endpoint Compromise In late April 2026, headlines screamed about 86,000 private screenshots leaked from a prominent European celebrity’s phone. The story dominated tech press coverage, but crucial context went missing. This was not hackers breaking encryption or sophisticated cyber warfare. It was endpoint compromise: stalkerware capturing screenshot...

YellowKey and the BitLocker Assurance Problem 16.05.2026

YellowKey and the BitLocker Assurance Problem Noel Bradford delivers a direct examination of YellowKey, the reported BitLocker bypass that exploits the Windows Recovery Environment on TPM-only configurations. This episode strips away vendor comfort narratives and green-tick dashboards to focus on what default encryption settings actually protect against when a laptop is stolen or accessed physical...

Listen to the Hot Takes from the Small Business Cyber Security Guy podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.