The Small Business Cyber Security Guy
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy PodcastPractical cybersecurity advice for small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon. Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between...
Author
The Small Business Cyber Security Guy
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
When Germany's .de Went Missing: A DNSSEC Fable of One Bad Signature 07.05.2026 10:17
How a Broken DNSSEC Signature Knocked Out .de Sites One bad signature. Millions of websites. Gone. On 5 May 2026, Germany's .de domain vanished from the internet for three hours. Amazon.de, Deutsche Bahn, Spiegel, DHL, major banks: all unreachable. Not hacked. Not ransomwared. One broken cryptographic record from the registry that manages 17.9 million domains. The servers were perfectly healthy. N...
Chrome's Hidden AI: The 4GB Surprise Eating Your Disk and Bandwidth 06.05.2026 10:22
Hot Take: Google Chrome, Gemini Nano, and the 4 GB Consent Problem Show Notes Google Chrome has been quietly downloading a roughly 4 GB AI model called Gemini Nano onto user devices in the background. No clear consent prompt. No notification. Just a file called weights.bin turning up in a folder called OptGuideOnDeviceModel like it pays the mortgage. In this Hot Take, Noel breaks down why this is...
Why 43% of UK Businesses Got Hit — and Why the Basics Let Them Down 04.05.2026 29:02
Imagine watching the house next door burn and nodding sympathetically about smoke alarms — then never changing the battery in your own. That image opens our episode as Noel Bradford sits with Mauven MacLeod, Lucy Harper and Graham Falkner to unpack the UK Cybersecurity Breaches Survey 2025–26. This isn’t clickbait panic; it’s a weather report built from 2,112 businesses and 1,085 charities. The he...
Cyber UK 2026: The Front Line Arrives — What Small Businesses Must Do Now 27.04.2026 27:26
When a government minister stood on a podium in Glasgow and said, “the cyber front line is already here,” it did not sound like a warning. It sounded like a cold, unavoidable truth. In this episode, Noel Bradford is joined by Maurven and Graham, who attended Cyber UK 2026, to unpack what was said, what was left unsaid, and what it means for the small businesses quietly sitting inside UK supply cha...
"It's Not DNS" — Until It Is: The Office Mystery That Always Blames the Translator 20.04.2026 23:56
Every office has that moment: the site won’t load, someone whispers “DNS,” and immediately half the room turns into a jury with opinions but no evidence. In this episode of Small Business Cybersecurity Guy, Noel Bradford, Mauven MacLeod, Lucy Harper and Graham Falkner turn that reflexive blame into a story—part detective work, part practical guide—about why DNS so often gets accused, what really b...
167 CVEs and Counting: Patch Tuesday Throws the Kitchen Sink 15.04.2026 9:32
167 vulnerabilities. Two zero-days. One already used in live attacks. Graham Falkner breaks down April's Patch Tuesday and what your business needs to do today — in under 10 minutes. For full show notes etc: see https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-april-2026-sharepoint-zero-day-uk-smb/
From Tokens to Copilot: Fixing the Gaps in Your Microsoft 365 Defenses 13.04.2026 24:49
They said they were secure because they’d turned on Microsoft 365 and MFA. That should have been the end of the conversation — except it wasn’t. In this episode we follow a small-business sagawhere confidence meets complacency: a tidy subscription, a proud admin ticked off in the dashboard, and then a perfectly ordinary Tuesday when the finance inbox receives a believable invoice and the lights go...
When Your Cyber Insurance Says 'No': How One Form Field Can Cost You Millions 06.04.2026 34:53
What if you did everything right — paid the premiums, bought the policy — and on breach day they simply said, "nope"? This episode opens with that cold shock: a tiny answer on a form you filled 18 months ago about MFA, a quiet clause about state-backed operations, and suddenly a million-pound disaster is met with silence. I'm Mauven McLeod, joined by Noel Bradford and the velvet tonsils of Graham...
Digital Sour Milk: When Your Tech's 'Still Turns On' is a GDPR Time Bomb 30.03.2026 22:30
Imagine opening the office fridge and finding a cloudy, unlabeled bottle of milk. You wouldn’t drink it — so why are businesses still running tills, routers and servers on ancient, unsupported software? In this episode Graham, Noel, Lucy and Mauven turn the mic onto the maddening normality of ‘mystery’ machines: the Windows XP till behind the counter, the router older than your youngest employee,...
When Confidence Becomes the Vulnerability: How Ego Opens the Door to Breaches 23.03.2026 21:47
Tonight’s episode opens in an empty studio, a fridge with two bottles of Prosecco and a conspicuously absent Noel — the perfect stage for a conversation that is equal parts wry and urgent. Three hosts trade jokes and a refill, but the real story soon emerges: many cyber disasters don’t begin with cinematic black‑hat brilliance. They begin with everyday confidence, with the quiet sentence, “We’ll r...
Don’t Buy the Badge: The Real SMB 1001 Guide for UK Small Businesses 16.03.2026 32:19
Do small businesses really need another cyber security badge? In this episode, Noel Bradford, Mauven MacLeod and Graham Falkner dig into SMB 1001, a five tier cyber security standard aimed at small and medium sized businesses. They break down what the bronze, silver, gold, platinum and diamond levels actually mean, where the framework came from, and whether it has any real value for UK firms. The...
March 2026 Patch Tuesday — Take It or Stay Vulnerable 11.03.2026 11:53
Listen in as the Small Business Cybersecurity Guy rips through March 2026 Patch Tuesday like a mechanic with a torque wrench: blunt, precise, and impossible to ignore. This episode opens on a single, brutal premise — Windows updates are not a choose‑your‑own‑adventure. They are binary. You either deploy the cumulative payload or you leave every unpatched edge of your estate like a neon target for...
Willow vs Danzel — Navigating Cyber Essentials V3.3 Before the Deadline 09.03.2026 34:43
Imagine your website is a billboard: a shining Cyber Essentials badge promising security and trust. Now imagine a regulator, insurer or large customer asks one awkward question — and that glossy logo turns from an asset into potential evidence against you. In this episode we walk into that exact moment and refuse to let it be a surprise. Join Graham Falkner, Noel Bradford and our resident translat...
They're Not 'Hacking' — They're Logging In: The Dangerous Myth Small Businesses Fall For 06.03.2026 13:13
Imagine an attacker not as a hoodie-wearing wizard wrestling with your firewall, but as someone quietly slipping through an unlocked back door with keys they bought on the dark web. In this episode we sit down with Corrine Jefferson, a former government cyber professional who now helps UK small businesses understand how real attackers operate. Grounded in Palo Alto Networks Unit 42's Global Incide...
Three and a Half Pence: The Currys Breach That Took Nine Years to Matter 02.03.2026 40:22
Picture yourself tapping your card at a bustling store, the till chirps, you walk away thinking that’s the end of the story. For millions of Currys' customers, that ordinary moment in 2017 was the opening scene of a nearly decade-long drama that would ripple through courtrooms, regulator offices and countless inboxes. This episode unpeels that story — malware on thousands of point-of-sale terminal...
Locked In: Palantir, Microsoft and the Hidden Political Risk in Your Cloud 23.02.2026 27:41
Picture this: you’re a minister in Europe and Washington quietly asks for a peek. Your emails, drafts and cabinet notes aren’t in a secret vault — they live on someone else’s servers. This episode opens on that impossible, very real moment and follows the ripple effects: threats of sanctions, a neutral Switzerland walking away from Palantir, and the uncomfortable truth that the UK handed that very...
Edge Devices Under Siege — 393 Days of Unnoticed Access 16.02.2026 22:50
In this episode of Small Business Cybersecurity Guy, host Maurven McLeod and guest Dr Corinne Jefferson (former US government intelligence analyst turned London-based consultant) unpack Google Threat Intelligence’s alarming report on the Defence Industrial Base (DIB) and explain exactly why it matters to small and medium-sized businesses. They move straight from the uncomfortable headline — Chines...
February 2026 Patch Tuesday: Six Actively Exploited Flaws — DWM Strikes Twice 11.02.2026 11:40
Host Graham Falkner breaks down Microsoft’s February 2026 Patch Tuesday: more than 50 vulnerabilities across Windows and Microsoft 365, including six that were actively exploited before patches arrived. This episode explains which flaws matter, who’s affected, and the practical steps businesses should take immediately. Coverage includes the six confirmed actively exploited vulnerabilities (triple...
Four Campaigns, One Nightmare: How 2026's Attacks Bypass Every Small-Business Defence 09.02.2026 28:25
In this urgent episode of Small Business Cybersecurity Guy, hosts Mauven MacLeod and Graham Falkner join the notably fed-up Noel Bradford to unpack four simultaneous, high‑impact campaigns that emerged between late January and early February 2026. We walk listeners through detailed research from Trellix, Securonix, Rapid7 and Microsoft and explain why these attacks matter to every small business —...
Security Theatre Exposed — Passkeys, the CISA Leak, and the Hidden Value in Your Cyber Insurance 02.02.2026 43:00
In this urgent episode of The Small Business Cybersecurity Guide, hosts Noel Bradford, Mauven McLeod and Graham Faulkner bring together three experts to answer one question: why you’re doing security wrong and what practical steps will actually protect your business. We cover four pressing, unconnected problems that share the same root cause — a massive gap between perceived and real security. Dr....
Who’s in Charge When Ransomware Hits? Building Your Incident Response Team 19.01.2026 30:57
In this episode of Small Business Cybersecurity Guy, hosts Mauven MacLeod, Noel Bradford and Graham Falkner walk you through Module One of their six-part incident response plan series: building your response team. Through the real-world Katie Roberts case study (name changed), they show why independence matters when a breach hits — and how an unbiased incident manager can quickly uncover the truth...
114 Updates, 1 Active Exploit — January Patch Tuesday: Patch Today or Pay Tomorrow 14.01.2026 10:00
Hosted by Graham Falkner, this episode is a rapid, no‑nonsense January Patch Tuesday breakdown aimed at small businesses and IT owners. Graham walks listeners through Microsoft’s unusually large release of 114 security updates, explains the essential jargon (CVE and CVSS), and highlights why severity scores don’t replace real‑world risk assessments. The show covers the one vulnerability already be...
UK Government Admits Cyber Chaos — 28% of Systems ‘Cannot Be Defended’: What SMBs Need to Know 12.01.2026 27:14
In this episode of the Small Business Cybersecurity Guy, host Noel Bradford is joined by Mauven McLeod and Graham Falkner to unpack the Cabinet Office’s January 2026 Government Cyber Action Plan — a blunt, 100‑page admission that the UK government’s cybersecurity posture is “critically high” risk and that many of its own targets are unachievable. The trio break down the report’s headline findings,...
When MFA Isn’t Enough: Inside Adversary‑in‑the‑Middle Attacks 05.01.2026 38:45
In this episode Mauven McLeod and Graham Faulkner (with Noel Bradford joining partway through) unpack a worrying trend: adversary‑in‑the‑middle (AITM) attacks that steal session tokens and completely bypass conventional multi‑factor authentication (MFA). Using Microsoft’s recent telemetry (a 146% jump in AITM incidents) as a backdrop, they explain how transparent proxy phishing pages relay credent...
3AM Ringtone of Doom? Build Your 6-Module Incident Response Plan 29.12.2025 2:28
What You'll Learn Three in the morning. Your phone's ringing. Someone's encrypted your customer database. What do you do? This trailer launches our most ambitious series yet: a six-module programme running January through March 2026 that transforms panic into a complete, tested incident response plan. Each module drops every two weeks, giving you time to implement before the next one arrives. Be...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.