The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups Titelbild

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

Von: The Small Business Cyber Security Guy
Jetzt kostenlos hören, ohne Abo

Saisonale Sparangebote | 0,99 € pro Monat für die ersten 3 Monate

Danach 6,99 €/Monat. Bedingungen gelten. Monatlich kündbar.

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.

Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.

🎯 WHAT YOU'LL LEARN:

  • Cyber Essentials certification guidance
  • Protecting against ransomware & phishing attacks
  • GDPR compliance for small businesses
  • Supply chain & third-party security risks
  • Cloud security & remote work protection
  • Budget-friendly cybersecurity tools & strategies

🏆 PERFECT FOR:

  • UK small business owners (5-50 employees)
  • Startup founders & entrepreneurs
  • SME managers responsible for IT security
  • Professional services firms
  • Anyone wanting practical cyber protection advice

Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

The Small Business Cyber Security Guy Productions
Management & Leadership Politik & Regierungen Ökonomie
  • Your Security Kit Is their Way In
    Oct 5 2026
    Your Security Kit Is the Way In The things you bought to keep attackers out are how they’re getting in. Citrix, Fortinet, forgotten WordPress backups, fake ChatGPT adverts, and the AI in your business that nobody owns. Some time in early September, somebody found a way through a door that thousands of businesses use to let their staff in from home. The owners didn’t know. Then the emergency fix arrived, patched boxes started rebooting, and that turned out to be another hole attackers were already using. This week Noel Bradford, Lucy Harper, and Graham Falkner follow one thread through every story: something was trusted, and nobody was in charge of checking that trust. Citrix NetScaler zero-days exploited for weeks before disclosure. A FortiMail flaw with fixes still pending, and Noel’s long-running grievance with Fortinet’s track record. Forgotten WordPress backups handing over email and cloud passwords. Microsoft’s Digital Defense Report showing phishing back as the front door. And fake ChatGPT adverts on Google that walk staff straight into installing a remote access tool. Then the conversation turns to the AI in your business that nobody owns. Prompted by John Wernfeldt’s LinkedIn post on AI teams and governance teams talking past each other, the hosts translate the problem for Gary Mott’s twelve-person building firm and land on three conditions that take twenty minutes to agree. Noel also announces GRCBolt, his own AI policy pack for UK small businesses, now taking waitlist sign-ups. What to do this week Email your IT provider and anyone who holds your data. Ask whether they run Citrix NetScaler or Fortinet FortiMail, and whether they’ve patched and checked for signs of compromise. For Citrix, ask whether they’ve applied the second fix released on Sunday 4 October.Find out who looks after your website. Ask them to clear old backup files out of public folders, update WordPress, and change the email password stored in your contact form plugin.Turn on passkeys for the accounts that matter most: whoever runs Microsoft 365 or Google Workspace, and whoever approves payments. Both platforms include passkeys at no extra charge. Forcing everyone to use them needs an extra licence on some Microsoft plans.Tell everyone one rule. No genuine website will ever ask you to press the Windows key and R, then paste something in.Agree three things about AI: which tools are allowed, which data never goes in, and who checks the output before a client sees it. Put a name next to each. Chapters 00:00 Cold open00:56 Welcome01:33 The doors you don’t own: Citrix NetScaler and Fortinet FortiMail10:15 The back door you forgot: WordPress backups leaking passwords13:36 Borrowed trust: Microsoft’s report and fake ChatGPT adverts19:13 The AI nobody owns23:00 Introducing GRCBolt25:03 Your Monday morning actions26:57 Close Sources Citrix NetScaler NCSC: Exploitation of vulnerabilities affecting Citrix NetScaler ADC and GatewayCitrix security bulletin for CVE-2026-88771 to CVE-2026-88778, including indicators of compromiseSophos: Citrix NetScaler vulnerabilities in active exploitationThe Hacker News: Mandiant and Google Threat Intelligence on the NetScaler campaignCyber Security News: NetScaler appliances rebooting after the zero-day patchBleepingComputer: Citrix patches NetScaler SAML zero-day exploited in attacks Fortinet FortiMail Help Net Security: Critical FortiMail zero-day exploited in the wildwatchTowr: FortiMail CVE-2026-104286 FAQRadical Notion: Fortinet CVE report card (third-party aggregator)MazeHQ: 2025 known exploited vulnerabilities by vendor WordPress backups Cyber Security News: Exposed WordPress backups leaking cloud and email credentials Microsoft Digital Defense Report 2026 Microsoft Digital Defense Report 2026 Microsoft’s figures come from its own customer and incident response data, so treat them as vendor telemetry. Fake ChatGPT adverts and ClickFix Huntress: Attackers abuse ChatGPT Custom GPTs to deliver a RAT via ClickFixIsland: How attackers use sponsored search and Custom GPTs in malware delivery Passkeys CoreView: Enabling and enforcing passkeys in Microsoft Entra IDGoogle Workspace Updates: Passkeys for Workspace users AI and governance The governance discussion was prompted by a LinkedIn post from John Wernfeldt on why AI teams and governance teams need to be in the same room.John writes about data governance, analytics, and AI in his newsletter, Data Governance Field Library. GRCBolt GRCBolt is Noel’s own product, and this episode has no sponsor. It’s an AI policy pack for UK small businesses: four documents written around your business, a one-off price under £100, no subscription, and editable Word files. It’s guidance only, and it doesn’t replace legal advice or certify you against any standard. Join the waitlist and see the partial sample pack at grcbolt.co.uk. Related episodes Mentioned in this episode: The Firewall Fallacy: Fortinet, KEVs and the Cost of ...
    Mehr anzeigen Weniger anzeigen
    34 Min.
  • When AI Finds the Switch You Forgot: Attacks for Pocket Change
    Sep 28 2026

    Imagine waking on a Tuesday to discover an invisible army has been testing your doors for six days. It doesn’t need fancy zero-days or cinematic cleverness — just agents that can scan, read, adapt and move on. In this episode, we follow a financially motivated attacker using open-source AI tools to run 105 probing projects in under a week, harvesting card data and compromising organisations while the cost of each reconnaissance run averages just a few dollars.

    From Gambit Security’s reconstruction of a scaled campaign to New Zealand’s National Cyber Security Centre warning that frontier models accelerate reconnaissance, the story threads together into one uncomfortable observation: the problem isn’t a lack of security technology, it’s the gap between owning features and operating them. A critical TeamCity flaw with a published patch and known exploitation shows how a fixed vulnerability becomes a real ransomware entry when change processes stall and nobody can say for sure what is exposed.

    We even wind up in the optical spine of fiber broadband, where Quark’s Lab’s deep dive into passive optical networks exposes a familiar theme — standards and features can support strong protections, but optional choices and careless deployments turn capability into illusion. Whether it’s MFA, backups, EDR or encryption, a green tick on a dashboard is not the same as a control that will actually stop an attacker in the middle of the night.

    AI doesn’t need to be a brilliant mastermind. It just needs to cheaply and persistently test the weak signals you left lying around. That changes the economics: the marginal cost of trying the next company collapses, and opportunistic compromise scales. Small businesses aren’t suddenly interesting; they’re suddenly cheap to probe, and automation can take an exploit much further than old scanners ever could.

    But this isn’t fatalism — it’s a practical wake-up call. The defence that works is less about buying another product and more about operational discipline: know what your external world can reach, test whether MFA actually prompts for a second factor, restore a backup for real, and rehearse the decision pathways for critical patches. Ask: if someone could attack us cheaply tomorrow, what would make them stop?

    We tell the story through people and processes — the helpdesk pressured to reset accounts, the admin on leave, the server thought to be internal but quietly facing the internet — and pull tools into the background. The episode walks you through real moments where security features exist but controls don’t, then hands you a simple, evidence-first checklist to start closing those gaps today.

    By the end you’ll see the same pattern in different disguises: AI makes probing trivial, technology contains the answers, and operations decide whether those answers are actually used. It’s bleak, fixable, and urgent — because the next probe might be the one that finds the switch you forgot to turn on.

    Find our Skool community here - https://www.skool.com/small-biz-cyber-guy-2008

    Mehr anzeigen Weniger anzeigen
    28 Min.
  • When Laws Lag and Attacks Sprint: The 10-Hour Cyber Reckoning
    Sep 21 2026

    Three headlines—an EU law delay, an AI-accelerated intrusion that went from weeks to hours, and a UK bill about to bring hundreds of IT providers under direct regulation—sound like stories from different podcasts. They aren’t. By the end of this episode, they meet in a single, worrying place: the gap between assumption and evidence.

    Follow Noel Bradford, Lucy Harper and Corrine Jefferson as they trace that gap through vivid scenes: a quiet lawroom in Brussels that postponed some deadlines but switched major penalties on; a Unit 42 investigation where one attacker, helped by AI, compressed reconnaissance, exploitation and extortion into under ten hours; and Westminster’s Cybersecurity and Resilience Bill that could force managed service providers to register, report incidents quickly, and face heavy fines. Along the way, the podcast lights up small, human details—a heating engineer’s paperwork, a builder’s son who inherited the IT, a host who reads breach reports like gas bills—to show how ordinary businesses get dragged into extraordinary risk.

    They don’t just explain the problems; they show how the threads tie together. The EU’s AI Act makes clear obligations for providers of large models but only if you can first answer the simple question: what AI do you actually use? The attack demonstrates the lethal value of time—alerts that wait in an inbox are useless when an attacker finishes a campaign before most people have their second cup of coffee. The UK bill exposes who truly owns the decision when an outsourced provider goes dark: legal reporting may hit the MSP, but operational pain lands with the client.

    Alongside sharp investigations into LG TV privacy claims and a cunning "click-to-fix" browser-cache exploit, the episode turns practical. It hands you three urgent morning-after questions to take to your board: what AI does your business use (and who owns it), could you detect and respond within ten hours, and is your IT provider positioned to be regulated? If you can’t answer those now, this episode will make it impossible to shrug them off.

    Listen for clear, actionable steps—visibility, speed and ownership—that every small business needs before the clocks of law, crime and regulation collide.

    Mehr anzeigen Weniger anzeigen
    37 Min.
adbl_web_anon_alc_button_suppression_t1
Noch keine Rezensionen vorhanden