PODCAST · business
Hot Takes from the Small Business Cyber Security Guy
by The Small Business Cyber Security Guy
Hot TakesHot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team.This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters:What does this mean for a real small business?Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF.We cover topics including cyber attacks, data breaches, ransomware, supply chain risk, Microsoft 365 security, compliance, Cyber Essentials, bad MSP behaviour, weak governance, and the many creative ways organisations manage to trip over their own shoelaces.No hoodies.No Matrix code.No corpora
-
17
Your Business Is an Open Book
Your Business Is an Open Book Most small businesses have been building a public intelligence profile for years without realising it. Every LinkedIn update, team photo, and website contact page adds detail to a picture that anyone can view, including those with malicious intent. This episode examines open source intelligence (OSINT) and how publicly available information becomes the foundation for targeted attacks like spear phishing and invoice fraud. Noel Bradford walks through the reconnaissance process, from Companies House filings to social media posts, demonstrating how an attacker can map your business, identify key staff, and craft convincing impersonation emails in under twenty minutes. The episode provides practical steps for auditing your own digital footprint, including what to check on search engines, how to review your Companies House entry, and why listing every software tool on LinkedIn might not be wise. This is not about disappearing from the internet; it is about making conscious choices about what you publish and understanding who else is reading it. Chapters Welcome Introduction to the concept of OSINT and how small businesses inadvertently publish reconnaissance material about themselves through normal business activities. Body A detailed walkthrough of public information sources including Companies House, LinkedIn, business websites, and social media. Explains how attackers use this data to construct targeted spear phishing campaigns, with practical examples of reconnaissance leading to invoice fraud and credential theft. Concludes with five actionable steps for auditing and managing your business’s public profile. Outro Final reminder that OSINT is simply reading publicly available information with intent, and that small businesses can reduce risk by auditing their own footprint and making conscious publishing decisions. Links https://www.gov.uk/government/organisations/companies-house https://www.linkedin.com https://www.ncsc.gov.uk/guidance/phishing Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
16
Cyber Essentials Platform Transition: What the July Deadline Means for You
Cyber Essentials Platform Transition: What the July Deadline Means for You The Cyber Essentials scheme is transitioning from its Willow platform to the new Danzell version, with a go-live date now set for 6 July. Noel Bradford cuts through the noise to explain what this extension actually means for small businesses holding or pursuing certification. If you are mid-assessment, you need to check with your certification body about completion requirements. If you are planning a new assessment, you will be working under the updated Danzell question set, which brings tightened wording and updated evidence requirements across the five core technical controls. Businesses often hear the word ‘extended’ and relax, but your certificate expiry date has not changed. Contract requirements remain in force. This episode walks through the practical steps you need to take now, whether you are renewing, starting fresh, or supporting clients through the transition. The platform update reflects real shifts in how small businesses operate, from cloud services to remote working. Prepare properly, read the updated guidance, and do not wait for your assessor to chase you. Chapters Welcome Noel Bradford introduces the topic: the Cyber Essentials platform transition, a shifted deadline, and why businesses need to update their plans accordingly. Platform Transition Explained The Cyber Essentials scheme is moving from Willow to Danzell, with a new go-live date of 6 July. Noel explains what each platform is, who runs the scheme, and why the word ‘extended’ does not mean businesses can relax. He covers what the transition means for mid-assessment businesses, those starting fresh, and the practical differences in the Danzell question set. The five core technical controls remain, but wording, scope questions, and evidence requirements have been updated. Noel warns against reusing old templates, stresses the importance of checking your certificate expiry date, and highlights the risk of confusing the platform delay with your personal compliance deadline. He also addresses MSPs and IT support businesses, urging them to communicate the change to clients now rather than waiting for panic calls later. Outro Noel summarises the key actions: talk to your certification body if you are mid-assessment, get the Danzell guidance if you are planning a new assessment, and check your certificate expiry date today. The extension is not a problem; ignoring it is. Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
15
Passkeys Are Not Magic, But They Are Better Than Passwords
Passkeys Are Not Magic, But They Are Better Than Passwords Noel Bradford examines passkeys, a rare security improvement that reduces phishing risk and removes the burden of password memorisation. Drawing on NCSC guidance, he explains why passkeys are resistant to credential theft, how they use cryptography tied to the service you’re logging into, and why they can be easier for users than traditional passwords. He then offers practical adoption advice for small businesses: prioritise high-value accounts, choose approved credential managers, plan device recovery carefully, and train users without the hype. Passkeys won’t fix bad governance or unmanaged devices, but they do represent a serious upgrade from password-based authentication. For accounts that touch money, data, or admin access, this is progress worth planning properly. Chapters Welcome Noel opens by framing passkeys as a rare security improvement that may make life safer and less annoying. He notes the NCSC recommends using passkeys over passwords wherever they’re available, and describes passwords as tired after decades of asking normal people to behave like flawless security robots. Why Passkeys Are Better Than Passwords Noel explains that passkeys move the security burden from human memory to devices proving identity properly. They are resistant to phishing because they use cryptography tied to the service, so fake sites cannot trick users into handing over reusable secrets. He offers practical adoption advice: prioritise high-value accounts (admin, finance, email, cloud), choose approved credential managers, plan device recovery, train users in plain English, and avoid half-rolled-out projects. Passkeys do not fix bad governance or unmanaged devices, but they do reduce credential theft risk. Outro Noel closes by saying passkeys are not magic, but they are a serious upgrade from passwords. They reduce phishing risk and password fatigue. Check which key business services already support passkeys, prioritise critical accounts, document recovery, train users, and keep strong passwords and multi-factor authentication where passkeys are not yet available. Links https://www.ncsc.gov.uk/collection/device-security-guidance/authentication-policy/use-passkeys-instead-of-passwords https://www.cisa.gov/secure-our-world/use-strong-passwords Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
14
MFA Fatigue Is a Management Failure, Not a User Problem
MFA Fatigue Is a Management Failure, Not a User Problem Multi-factor authentication is essential, but not all MFA is equal. When users receive vague, repeated, or poorly explained prompts, they start treating them like cookie banners: accept, accept, make it go away. Attackers exploit this fatigue by triggering prompts under pressure, impersonating IT support, or using social engineering to bypass weak helpdesk processes. This is not a user failure; it is a design and management failure. Businesses must reduce unnecessary authentication noise, use phishing-resistant methods like number matching, train staff to recognise unexpected prompts as attack signals, and strengthen identity verification processes. A reported prompt that turns out to be nothing is a working security culture. A prompt nobody reports because everyone fears looking stupid is how expensive conversations with insurers begin. MFA is a control, not a confession booth. If it fails, look at the whole process: the prompt design, the training, the helpdesk, the call-back procedures, and the culture that prioritises speed over verification. Stop blaming users for predictable mistakes in badly designed systems. Chapters Welcome Noel defends MFA while attacking poor MFA design, lazy user blame, and weak verification processes. Not all MFA is equal: some is clear and strong, some is so noisy and vague that users treat prompts like cookie banners. That is design failure, not user failure. Body Noel explains why MFA fatigue happens and how attackers exploit pressure, urgency, and process gaps. Attackers trigger repeated prompts, impersonate IT, and use social engineering. Businesses must ask why users received repeated prompts, why prompts were unclear, why training was absent, and why helpdesk processes were weak. MFA is a decision point, not a magic forcefield. UK SMBs should use number matching, reduce pointless prompts, teach staff what unexpected prompts mean, and strengthen helpdesk verification. MFA fatigue is often a management failure wearing a user blame costume. People are not the weakest link; unsupported people are. Outro Noel closes by stating that MFA is a control, not a confession booth. If it fails, look at the whole process: the prompt, the training, the helpdesk, the call-back process, the culture. Move away from simple push approval, train staff to report unexpected prompts, reduce authentication noise, and strengthen identity checks. Stop blaming users for predictable mistakes in badly designed systems. Links https://www.ncsc.gov.uk/collection/small-business-guide https://www.cisa.gov/ https://www.ftc.gov/business-guidance/small-businesses https://www.fcc.gov/general/cybersecurity-small-business Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
13
WiFi Surveillance: When Your Router Becomes a Camera
WiFi Surveillance: When Your Router Becomes a Camera WiFi feels like plumbing. It’s boring, invisible, and trusted by default. But research from Karlsruhe Institute of Technology shows that ordinary WiFi signals can now identify people with near-perfect accuracy, even when they’re not carrying an active device. This isn’t science fiction or a reason to panic. It’s a signal that infrastructure we consider neutral can become surveillance without looking like it. For small businesses, the challenge isn’t the technology itself. WiFi, sensors, CCTV, door access, and meeting room systems can all be genuinely useful. The problem is treating them as operational kit rather than privacy decisions. Noel Bradford walks through the uncomfortable reality that clever dashboards, vendor promises, and boring boxes on the ceiling can quietly collect more data than anyone has thought through. The solution isn’t to rip access points off the wall. It’s to stop assuming that boring infrastructure is harmless infrastructure, and to ask the awkward governance questions before the router starts behaving like a camera. Chapters Welcome Noel introduces WiFi identification research and frames it as an invisible surveillance problem, not a reason to panic. Body Noel explains the WiFi sensing research in plain English and connects it to privacy, small business infrastructure, CCTV-style thinking, and practical governance. Outro Noel closes by saying WiFi surveillance is not a panic story, but it proves infrastructure can become surveillance and needs governance. Links https://www.sciencedaily.com/releases/2026/05/260522.htm Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
12
When Your SaaS Dashboard Looks Like Times Square
When Your SaaS Dashboard Looks Like Times Square SaaS dashboards are increasingly cluttered with upsells, AI buttons, trial offers, and partner adverts, turning essential admin portals into noisy digital shopping centres. This creates a serious security problem: when every banner demands attention, users learn to ignore warnings, including genuine security alerts about suspicious logins, new integrations, or privilege changes. For small businesses managing limited admin resources, this clutter destroys the attention needed to spot real threats. The NCSC cloud security principles remind us that shared responsibility means businesses still own access, configuration, and data decisions, even in SaaS environments. SaaS sprawl compounds the issue: too many tools, too many integrations, too many admin accounts, and not enough people asking what each service can actually see. This is not just a usability complaint; it is a governance, supplier risk, and data protection concern. Vendors must stop treating admin portals like marketing real estate and give administrators clarity, exportable logs, and usable security signals. Small businesses, meanwhile, must review their SaaS estate, assign ownership, remove dormant integrations, enforce MFA, and route security alerts to monitored channels. Attention is a finite control, and SaaS clutter is selling it back to businesses one popup at a time. Chapters Welcome Noel opens by attacking the way SaaS dashboards now mix work, adverts, upsells, alerts, and AI clutter, arguing that when every button screams for attention, nobody hears the one that matters. Body Noel explains how cluttered SaaS dashboards create warning fatigue, hide security signals, increase integration risk, and make small businesses worse at managing cloud services. He covers shared responsibility under NCSC cloud security principles, the governance risks of SaaS sprawl, and practical steps for reviewing the SaaS estate, reducing noise, and demanding better vendor transparency. Outro Noel closes by arguing that SaaS clutter destroys attention and that small businesses need ownership, review, and better vendor questions. He provides a checklist: create a SaaS tool list, assign owners, remove unused integrations, route security alerts properly, and ask vendors how they separate security signals from marketing noise. Links https://www.ncsc.gov.uk/collection/cloud/the-cloud-security-principles https://www.cisa.gov/resources-tools/resources/secure-by-demand Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
11
AI Vulnerability Discovery Will Make Patch Queues Worse
AI Vulnerability Discovery Will Make Patch Queues Worse AI-assisted vulnerability discovery is accelerating the rate at which security flaws are found and reported. For researchers and vendors, this is progress. For small businesses already struggling with patch management, it means more advisories, more prioritisation pressure, and more noise. Noel Bradford warns that faster discovery will expose weak processes, not fix them. Without a proper asset inventory, clear ownership, agreed maintenance windows, and documented exceptions, businesses risk drowning in patch queues they cannot manage. This episode cuts through the hype to explain why AI-driven vulnerability intelligence demands better fundamentals, not heroic firefighting. UK businesses can start with Cyber Essentials as a baseline for supported software and security updates. US organisations can map similar thinking through CISA’s Secure by Demand guidance. The message is consistent: faster threat intelligence only helps if your business can make faster, informed decisions. Speed without process is just louder failure. Chapters Welcome Noel opens by warning that AI-assisted vulnerability discovery may help defenders, but it will also increase patch pressure for small businesses. Body Noel explains that faster vulnerability discovery means more patch noise, more prioritisation pressure, and a greater need for asset inventory, supported software, and maintenance windows. Outro Noel closes by warning that AI will expose weak patch processes and gives practical SMB actions. Links https://www.ncsc.gov.uk/ https://www.gov.uk/ https://www.ncsc.gov.uk/cyberessentials/overview https://www.cisa.gov/ Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
10
Cyber Crime Is a Business Risk, Not Just an IT Budget Line
Cyber Crime Is a Business Risk, Not Just an IT Budget Line Cyber crime has become a mainstream business risk, yet many UK SMBs still treat it as an IT problem to be quietly managed between printer issues and password resets. In this Hot Take, Noel Bradford argues that scams, fraud, ransomware, and account compromise belong on the risk register alongside cashflow, supplier risk, and customer retention. Drawing on recent British Chambers of Commerce data showing that 21% of firms experienced cyber attacks and 20% reported fraud or scams in the past year, Noel challenges the notion that security is an optional grudge purchase. He makes the case that cyber incidents ultimately land in the business, not just the server cupboard, affecting finance, operations, sales, HR, legal, and leadership. The episode reframes security spending as growth protection and resilience, not compliance theatre, and offers practical questions business owners should ask before an incident forces them to learn the hard way. For UK SMBs and US listeners alike, the message is clear: if cyber only lives in your IT budget, leadership has already failed the first test. Chapters Welcome Noel opens by framing cyber crime as a business problem with IT consequences, not just a server cupboard issue. He highlights the real costs: time lost, money lost, trust lost, growth delayed, and staff pulled into incidents they didn’t cause. Cyber Crime as Business Risk Noel unpacks recent British Chambers of Commerce data showing that 21% of UK firms experienced cyber attacks and 20% reported fraud or scams. He argues that cyber incidents, whether ransomware, invoice fraud, or account takeover, all land in the business, affecting finance, operations, sales, HR, legal, and leadership. He challenges the habit of treating cyber as a grudge purchase and calls for it to be budgeted alongside cashflow, supplier risk, and customer retention. The section includes US parallels via FTC and CISA guidance, and closes with practical questions business owners should ask to map risk, assign decision ownership, and plan resilience before an incident strikes. Outro Noel delivers the Hot Take: cyber crime is now a cost of doing business and must be treated as such. He urges leaders to add cyber and fraud to the risk register, review payment controls, assign incident decision owners, map critical systems, and budget for resilience. He warns that firewalls won’t fix weak governance or rebuild trust, and leadership must act before an incident, not during a panicked Teams call. Links https://www.britishchambers.org.uk/ https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024 https://www.ftc.gov/business-guidance/small-businesses https://www.cisa.gov/resources-tools/resources/small-business-resources Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
9
The Backup Lie: Why Green Ticks Won't Save Your Business
The Backup Lie: Why Green Ticks Won’t Save Your Business Most small businesses have backups. Few have tested recovery plans. In this uncompromising episode, Noel Bradford dismantles the dangerous assumption that backup equals recovery readiness. Drawing on NCSC and ICO guidance, he explains why green dashboard ticks, successful job reports, and monthly invoices create false confidence. Businesses fail not from encryption alone, but from downtime, confusion, missing credentials, and broken assumptions. Noel walks through the uncomfortable questions every UK small business must answer: what can you actually restore, by when, from where, and who knows how? He covers the cloud backup gap, the difference between platform availability and data recovery, and why testing turns backup from belief system into evidence. This is not about technology. It is about knowing what happens at 9am on a Monday when your main systems go down. Stop worshipping green ticks. Start proving you can get back to work. Chapters Welcome Noel opens by attacking the comforting myth that having backups is the same as being able to recover. He argues that many small businesses have green ticks, dashboards, and reports, but lack a genuine recovery plan. Body Noel explains why backup success does not prove recovery readiness. He references NCSC ransomware guidance and ICO data protection obligations, then walks through the uncomfortable questions businesses avoid: what can you restore, by when, from where, and who knows how? He covers common failure modes, the cloud backup gap, credential management, and the difference between platform availability and data recovery. Testing, he argues, turns backup from belief into evidence. Outro Noel closes by stating that an untested backup is a rumour and a green tick is false confidence. He gives practical recovery questions for small businesses: what do we restore first, how long will it take, who does the restore, and what happens if the backup system itself is affected? Backups are not the finish line. Recovery is. Links https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks https://ico.org.uk/for-organisations/guidance-on-ransomware/ https://www.cisa.gov/stopransomware Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
8
Shadow AI Is Just Shadow IT Wearing a Cape
Shadow AI Is Just Shadow IT Wearing a Cape Shadow AI has already arrived in most UK small businesses, often through browser tabs, SaaS tool sidebars, and helpful buttons that promise to improve text. Staff are using AI to rewrite emails, summarise meetings, polish proposals, and speed up admin tasks, frequently without approval, policy, or controls. This is shadow IT all over again, but faster and with better branding. The problem is not the technology itself, but unmanaged data movement into systems nobody has reviewed. Noel Bradford explains why banning AI without offering safe approved routes will fail, why hope is not an AI governance model, and why businesses need practical data controls that give staff clear lanes: low-risk generic tasks, controlled handling of customer data, and hard stops for sensitive material. UK Government guidance and NCSC advice make clear that AI changes the threat landscape, but the basics still matter. This episode cuts through the hype to deliver straightforward guidance on approved tools, supplier checks, human review, and early mistake reporting. AI policy is not about stopping progress; it is about stopping progress from leaking your business into someone else’s platform. Chapters Welcome Noel opens by calling shadow AI the new shadow IT, warning that most businesses already have unmanaged AI use happening through browsers, SaaS tools, and helpful buttons, even when leadership believes it has been avoided or controlled. Body Noel explains why unmanaged AI creates data governance, supplier risk, and access control problems. He argues that banning AI without offering safe approved routes will fail, and that businesses must give staff clear lanes for low-risk tasks, controlled customer data handling, and hard stops for sensitive material. He emphasises supplier checks, human review, accuracy risks, and early mistake reporting. Outro Noel closes by stating that shadow AI is already in the building and the question is whether businesses manage it properly or discover it during a customer complaint, DSAR, or regulator call. AI policy is not about stopping progress, but about preventing unmanaged workflows from leaking business data into unapproved platforms. Links https://www.gov.uk/government/publications/uk-government-open-letter-on-ai-cyber-threats https://www.ncsc.gov.uk/report/impact-of-ai-on-cyber-threat https://www.ftc.gov/business-guidance/small-businesses/cybersecurity https://www.cisa.gov/securebydemand Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
7
Curiosity as a Control: Why Asking Questions Beats Buying Tools
Curiosity as a Control: Why Asking Questions Beats Buying Tools Noel Bradford argues that curiosity is one of the cheapest and most overlooked security controls in small business cyber defence. Many organisations inadvertently train staff to suppress suspicion in favour of speed, creating environments where invoice fraud, phishing, and social engineering thrive. Drawing on NCSC guidance for UK businesses and parallel FTC and CISA frameworks for US audiences, Noel examines why reporting culture matters, how business pressure undermines vigilance, and what practical steps leaders can take to make curiosity socially safe. The episode reframes people not as the weakest link, but as a critical defensive layer when properly supported. Noel challenges businesses to praise false alarms, enforce verification processes for senior staff, and create frictionless reporting routes. This is not soft advice. It is operational security for organisations that cannot afford to reward silence. Chapters Welcome Noel introduces curiosity as the cheapest cyber security control most small businesses actively suppress, setting up the argument that organisational culture often trains people not to notice warning signs. Body Noel examines how UK NCSC guidance encourages reporting suspicious activity, yet many businesses reward speed over judgement. He explores invoice fraud, phishing, and social engineering scenarios where curiosity would prevent losses, and explains why false alarms are evidence of a functioning control. Practical steps include making reporting frictionless, enforcing verification for senior staff, and praising employees who raise concerns. Outro Noel closes by reframing people as a defensive layer when properly supported, not as the weakest link. He challenges businesses to treat curiosity as a control, normalise friction in high-risk processes, and recognise that attackers exploit culture as readily as they exploit technology. Links https://www.ncsc.gov.uk/collection/small-business-guide https://www.ncsc.gov.uk/information/report-scam-email https://www.ftc.gov/business-guidance/small-businesses https://www.cisa.gov/topics/cybersecurity-best-practices Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
6
CCTV Is a Networked Computer System with Cameras (and Possibly Microphones)
CCTV Is a Networked Computer System with Cameras (and Possibly Microphones) Noel Bradford challenges the persistent misconception that CCTV sits outside the cyber security estate. Many small businesses still treat cameras, recorders, door access systems and similar connected devices as facilities kit rather than networked computer systems requiring proper ownership, patching, segmentation and access controls. Modern CCTV often ships with audio capability, adding privacy and governance questions that many organisations have never considered. This Hot Take walks through the practical steps UK small businesses should take to inventory connected devices, control remote access, segment networks, disable unnecessary features like audio recording, and assign clear ownership. The episode references UK guidance from NCSC, ICO and DSIT, with parallel observations for US listeners drawing on CISA and FCC frameworks. If a device has an IP address or a microphone, it counts. Bolted to a wall doesn’t mean exempt from reality. Chapters Welcome Noel reframes CCTV as part of the cyber security estate, not just facilities kit, and highlights that many modern cameras ship with audio capability that often goes unmanaged. Body Noel explains why CCTV, NVRs, door access systems, smart screens and similar connected devices need ownership, segmentation, patching and proper remote access controls, with particular attention to audio recording as a privacy and governance question. Outro Noel closes with the core line that connected facilities systems are management problems with network cables and microphones, urging small businesses to treat any device with an IP address or microphone as part of the estate. References Source notes for production review covering NCSC, ICO and DSIT guidance for UK listeners, with parallel observations for US audiences drawing on CISA and FCC frameworks. Links https://www.ncsc.gov.uk/collection/smart-devices https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/cctv-and-video-surveillance/ https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology https://www.cisa.gov/ https://www.fcc.gov/ Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
5
Cyber Security Is Not Broadband
Cyber Security Is Not Broadband Noel Bradford unpacks a vendor meeting that went sideways and exposes a wider problem in the small business cyber market. As the UK’s cyber security sector grows to 2,603 firms generating £14.7 billion in annual revenue, more suppliers are packaging cyber protection like broadband bundles: one monthly fee, one portal, one reassuring product name. But when light services hide behind heavy language, small businesses get packages instead of protection. Drawing on the UK Government’s Cyber Security Sectoral Analysis 2026 and real-world incident management experience, Noel explains the difference between genuine incident response and signposting with a login. He challenges the gap between what vendors promise and what customers actually receive when something goes wrong. This episode asks awkward questions about dark web monitoring, phishing simulation, insurance wrappers, and who really owns the incident when the clock is ticking. If you are a small business owner evaluating a cyber bundle, or a vendor selling one, this is essential listening. Cyber security is not a utility. It is not broadband. And when we sell it like broadband, we make ‘do nothing’ the stronger competitor. Chapters Welcome Noel introduces the episode after being pulled into a vendor meeting cold. He explains that cyber security is being bundled, packaged, and sold like broadband, but the analogy breaks when small businesses need real protection instead of tidy portals. The Cyber Sector Is Booming Noel cites the UK Government’s Cyber Security Sectoral Analysis 2026, which reports 2,603 active UK cyber firms, 69,600 full-time equivalent employees, and £14.7 billion in annual revenue. A bigger sector does not automatically mean better security for small businesses. Dragged Into The Call Noel describes joining a vendor call without context and immediately spotting a small business cyber bundle featuring dark web scanning. He explains when dark web monitoring can be useful and when it becomes a scare lever without follow-through. The Bundle Noel breaks down the bundle components: dark web monitoring, phishing simulation, privacy tools, cyber insurance, and incident response. He explains that none are inherently bad, but stacking five useful-sounding things together does not create a strategy without honest scoping and clear ownership. Incident Response Or Signposting With A Headset Noel explains the difference between real incident management and light advice. Proper incident response involves containment, evidence handling, insurer engagement, legal coordination, and recovery planning. At low five figures, it is not a £25 add-on, and signposting is not the same as ownership. Midroll Bumper Noel resets before moving into the insurance and channel problem. He reminds listeners that cyber security does not have to be expensive, but ignoring it always is. The Insurance Comfort Blanket Noel examines the bundle’s £25 per month price point and limited insurance cover: GDPR breach costs and fines capped at £25,000 per incident. He explains that the fine is often not the expensive part. The response is, and a small insurance wrapper is a sticky plaster, not a strategy. The Pitch Breaks Noel describes how the vendor disengaged when he asked what the service actually did. When a cyber product cannot survive basic questions from an MSP, it is not ready for small business customers. The Wider Channel Problem Noel connects the incident to the wider issue of telcos, insurers, software vendors, and MSPs moving into small business cyber. If sector growth turns into a land grab with light bundles and heavy language, the real competitor, ‘do nothing’, becomes stronger. Outro Noel offers practical advice. Small business owners should ask who owns the incident, who speaks to the insurer, and what the service does at two in the morning. Vendors should stop hiding light services behind heavy language. Cyber security is not broadband. Links https://www.gov.uk/government/organisations/department-for-science-innovation-and-technology https://www.gov.uk/government/publications/cyber-security-sectoral-analysis-2026 Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
4
Microsoft Authenticator Isn't Magic: The Token Leak Nobody Wants to Talk About
Microsoft Authenticator Isn’t Magic: The Token Leak Nobody Wants to Talk About Microsoft Authenticator has become the identity gatekeeper for millions of Microsoft 365 users, but CVE-2025-41615 exposes a critical flaw that can leak work account access tokens after user interaction. Noel Bradford unpacks why this ‘information disclosure’ vulnerability is really an identity compromise risk, why the CVSS score debate misses the point, and why treating MFA apps as sacred cows instead of managed software creates dangerous blind spots. This episode challenges IT providers to move beyond tick-box security, explains what access tokens actually do, and delivers a practical seven-step response plan for UK small businesses and MSPs. If your defence relies on assuming automatic updates will save you, you’re not managing risk—you’re outsourcing it to hope. MFA is essential, but the app protecting it needs governance, patching, and accountability. Chapters Intro Noel introduces CVE-2025-41615, a vulnerability in Microsoft Authenticator that can expose work account access tokens. He frames the real issue: businesses treat MFA apps as magic instead of managed software that sits inside critical identity infrastructure. What a Token Actually Means An explanation of how access tokens work as temporary proof of authentication, why token theft enables attackers to act as signed-in users, and why ‘information disclosure’ labels hide serious identity compromise risks. Stop Worshipping the Score Noel addresses the CVSS scoring split between Microsoft (9.6 Critical) and NIST (7.4 High), arguing that business risk assessment matters more than score theatre when the affected control is your identity gatekeeper. The Sacred Cow Problem A challenge to IT providers who treat MFA as a magic shield. Noel asks who actually knows what versions users are running, whether admin accounts depend on unmanaged personal devices, and whether providers can prove their users are patched. The User Interaction Excuse Needs to Die Why ‘user interaction required’ is not reassuring when attackers only need busy, distracted humans to approve one malicious request. Includes guidance on denying unexpected Authenticator prompts. What to Do Today Seven practical steps for UK SMBs and MSPs: update Authenticator to safe versions (Android 6.2605.2973+, iOS 6.8.47+), prioritise privileged accounts, verify updates via MDM, review sign-in logs, consider session revocation, tighten Conditional Access, and move towards phishing-resistant authentication. Outro Noel closes with reassurance that MFA remains essential but must be treated as managed software, not magic. He urges businesses to demand evidence and accountability from IT providers instead of accepting assumption as assurance. Links https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-41615 https://nvd.nist.gov/vuln/detail/CVE-2025-41615 https://www.heise.de/news/Kritische-Luecke-Microsoft-Authenticator-koennte-Firmen-Tokens-leaken-10380757.html Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
3
Europol Just Admitted Cybercrime Is an Industry
Europol Just Admitted Cybercrime Is an Industry Europol’s IOCTA 2026 report, published on 28 April 2025, describes cybercrime not as isolated attacks but as a connected industrial economy. More than 120 active ransomware brands operated in 2025, with affiliate programmes offering margins of 80 to 85 per cent. Modern extortion has shifted from encryption to data leak threats, making backups necessary but insufficient. Industrial-scale SIM farms, such as the Latvian operation involving seven nationals, 1,200 devices, 40,000 SIM cards, and more than 49 million fraudulent accounts, now underpin the majority of online fraud. The report highlights enablers including residential proxies, bulletproof hosting, and crypto payment rails. Europol identifies a velocity gap: criminals move faster than law enforcement can respond. For UK small businesses, this matters because too much of the security industry still sells compliance theatre rather than defence against an industrial threat. This episode examines what the report actually says, what ransomware now looks like, why SMS authentication is dangerously weak, and three practical actions any small business can take this week. Chapters Intro Noel introduces Europol’s IOCTA 2026 report and argues that cybercrime has industrialised into a market with suppliers, customers, and margins, while too much of the security industry sells comfort rather than defence. What the report actually says Europol describes a connected criminal economy where the same infrastructure supports multiple crimes. Key enablers include residential proxies, bulletproof hosting, and SIM farms. The velocity gap means criminals move faster than law enforcement can respond. Ransomware now has brands More than 120 active ransomware brands operated in 2025. Qilin offered affiliates 80 to 85 per cent of ransom payments. Modern extortion has shifted towards threatening to publish stolen data, making backups necessary but insufficient. The industry response problem Noel argues that the security industry too often sells compliance theatre rather than defence matched to an industrial threat. Cyber Essentials is a necessary baseline, but a certificate is not a security posture. Exhibit A: seven Latvians, forty nine million accounts A Latvian SIM farm case involved seven nationals, 1,200 devices, 40,000 SIM cards, and more than 49 million fraudulent accounts. Industrial-scale SIM farms underpin the majority of online fraud, exposing the weakness of SMS as proof of identity. What to do this week Three practical actions: email your IT supplier to ask if they have read IOCTA 2026 and what they have changed, audit SMS authentication in dangerous workflows, and review your ransomware plan for data leak scenarios. Outro Noel directs listeners to the full write-up on the blog and previews Friday’s long-form investigation into the SIM farm case. Links https://www.europol.europa.eu/publications-events/main-reports/iocta-2026 https://www.europol.europa.eu/media-press/newsroom/news/latvian-sim-farm-operation-busted Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
2
The Celebrity Stalkerware Leak: Not Encryption, Endpoint Compromise
The Celebrity Stalkerware Leak: Not Encryption, Endpoint Compromise In late April 2026, headlines screamed about 86,000 private screenshots leaked from a prominent European celebrity’s phone. The story dominated tech press coverage, but crucial context went missing. This was not hackers breaking encryption or sophisticated cyber warfare. It was endpoint compromise: stalkerware capturing screenshots directly from a device after messages had already been decrypted on screen. The database, allegedly linked to the collapsed Cocospy spyware ecosystem, contained WhatsApp chats, Instagram activity, invoices, intimate images and more. Whilst the core reporting appears sound, the framing obscured important truths. A VPN would not have stopped this attack. Encrypted messaging apps could not protect against malware already installed locally. And beneath the sensational headlines lies a grim pattern: commercial spyware marketed as parental monitoring or employee oversight, repeatedly exposed in breaches that reveal its real use in coercive control and domestic abuse. This episode unpacks what actually happened, why the technical details matter, and why we need to stop calling this surveillance software anything other than what it is. Chapters Intro Noel introduces the celebrity stalkerware leak story from April 2026, cutting through sensational headlines to frame what this incident actually was: endpoint compromise, not encryption failure. What The Story Claimed Breaking down the original ExpressVPN report by researcher Jeremiah Fowler, which detailed 86,859 screenshots from a celebrity’s device, including encrypted app content, intimate images and personal data. This Was Not Breaking Encryption Clarifying the critical technical misunderstanding: the spyware did not crack WhatsApp or Signal encryption. It simply captured screenshots after messages were already decrypted and displayed on screen. The Cocospy Bit Unpacking the Cocospy connection. The spyware ecosystem collapsed in 2025 after a massive breach, but leftover infrastructure appears linked to this incident, which targeted one victim rather than millions. The VPN Problem Addressing the uncomfortable commercial context: the story appeared on ExpressVPN’s blog, yet a VPN would not have prevented this attack. Transparency and vendor-owned media ecosystems matter in security reporting. The Bigger Issue Nobody Talks About The depressing normalisation of stalkerware. Marketed as parental monitoring, these tools repeatedly surface in breaches exposing their use in coercive control and domestic abuse, not legitimate oversight. Outro Final verdict: the core story appears accurate, but framing matters. This was endpoint compromise, not encryption failure. And the industry should stop euphemising commercial spyware designed for abuse. Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
-
1
YellowKey and the BitLocker Assurance Problem
YellowKey and the BitLocker Assurance Problem Noel Bradford delivers a direct examination of YellowKey, the reported BitLocker bypass that exploits the Windows Recovery Environment on TPM-only configurations. This episode strips away vendor comfort narratives and green-tick dashboards to focus on what default encryption settings actually protect against when a laptop is stolen or accessed physically. Bradford explains how YellowKey targets trusted recovery paths rather than breaking encryption mathematics, why TPM-only BitLocker represents a convenience trade-off rather than maximum assurance, and how businesses confuse enabled controls with proven protection. The episode provides practical guidance on identifying high-risk devices, reviewing BitLocker protectors, implementing TPM plus PIN where appropriate, locking firmware settings, restricting USB storage, and properly escrowing recovery keys. Bradford argues that physical access remains a normal business risk through stolen laptops, lost devices, and compromised bags, not merely a theoretical attack scenario. The episode challenges boards and decision-makers to move beyond checkbox assurance and ask what their laptop security actually proves under adversarial conditions. Chapters Stop Treating BitLocker Like Magic Bradford opens with a direct challenge to businesses that rely on default BitLocker settings and dashboard indicators as proof of security, arguing that enabled encryption is not the same as proven assurance. This Is About Recovery Explanation of how YellowKey exploits the Windows Recovery Environment rather than breaking encryption mathematics, targeting trusted recovery paths that systems use for legitimate repair operations. TPM Only: The Convenience We Pretended Was a Fortress Bradford examines TPM-only BitLocker as a usability trade-off that protects against some risks but may permit systems to unlock themselves in recovery contexts that attackers can exploit. Physical Access Is Still a Real Business Risk Reframing physical access as normal business risk through stolen laptops, lost devices in taxis, and bags taken from cars or hotels, not merely theoretical attack scenarios. Backdoor Claims and Evidence Bradford addresses the researcher’s reported claim that YellowKey appears deliberate whilst maintaining focus on operational risk management rather than speculation about intent. The Part That Should Make Boards Uncomfortable Examination of shallow security assurance in boardrooms, where checkbox answers to encryption questions fail to address configuration details, recovery key protection, and evidential requirements for regulators and insurers. What You Actually Do Now Practical guidance including identifying high-risk devices, reviewing BitLocker protectors, considering TPM plus PIN for sensitive roles, locking firmware, restricting USB storage, and properly escrowing recovery keys. Substack and Blog: The Safe Receipts Bradford directs listeners to companion materials on the blog and Substack for business impact analysis, mitigation checklists, and ongoing updates without exploit details. The Bigger Lesson: Assurance Is Not a Checkbox Closing argument that configuration, recovery paths, and physical access all matter, and that businesses must prove rather than assume what their laptop security protects against. Links https://www.expressvpn.com/blog/ https://techcrunch.com/ https://cybernews.com/ https://www.scmagazine.com/ https://www.bitdefender.com/ https://www.securitymagazine.com/ https://www.wired.com/ https://vpnmentor.com/
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Hot TakesHot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team.This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters:What does this mean for a real small business?Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF.We cover topics including cyber attacks, data breaches, ransomware, supply chain risk, Microsoft 365 security, compliance, Cyber Essentials, bad MSP behaviour, weak governance, and the many creative ways organisations manage to trip over their own shoelaces.No hoodies.No Matrix code.No corpora
HOSTED BY
The Small Business Cyber Security Guy
CATEGORIES
Loading similar podcasts...