Forsidebilde av showet The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

Podkast av The Small Business Cyber Security Guy

engelsk

Business

PrĂžv gratis i 14 dager

99 kr / MÄned etter prÞveperioden.Avslutt nÄr som helst.

  • 20 timer lydbĂžker i mĂ„neden
  • Eksklusive podkaster
  • Gratis podkaster
PrĂžv gratis

Om The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups

The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank. Join cybersecurity veterans Noel Bradford (CIO at Boutique Security First MSP) and Mauven MacLeod (ex-UK Government Cyber Analyst) as they translate enterprise-level security expertise into practical, affordable solutions for UK small businesses.🎯 WHAT YOU'LL LEARN: Cyber Essentials certification guidance Protecting against ransomware & phishing attacks GDPR compliance for small businesses Supply chain & third-party security risks Cloud security & remote work protection Budget-friendly cybersecurity tools & strategies 🏆 PERFECT FOR: UK small business owners (5-50 employees) Startup founders & entrepreneurs SME managers responsible for IT security Professional services firms Anyone wanting practical cyber protection advice Every episode delivers actionable cybersecurity advice that you can implement immediately, featuring real UK case studies

Alle episoder

104 Episoder

episode The Open Book Problem 4: Who's Really Deleting Your Data? cover

The Open Book Problem 4: Who's Really Deleting Your Data?

Delete Me and Incogni aren't scams. That's a sensible place to start. But as this episode of The Open Book Problem unfolds, a quieter, sharper scandal emerges: a paid subscription market built on a failure that should never have been dumped on ordinary people. Meet the protagonist of our story — a UK small-business director who wakes up one morning to discover their home address, director profile and personal history strewn across search results, broker sites and public registers. The immediate villains seem obvious: people-search sites, aggressive broker ecosystems and glossy removal services promising a clean slate. But the real antagonist is a broken system that forces busy people to choose between unpaid, tedious labour and handing their privacy to a subscription.

20. juli 2026 - 18 min
episode The Open Book Problem 2: How Public Records Teach Criminals Your Name cover

The Open Book Problem 2: How Public Records Teach Criminals Your Name

Imagine someone who knows your director's calendar, your payroll provider, the IT stack listed in your job ad, and the name of the accountant who signs your invoices. They don't have to be a genius — they just read what you and the public have already told them. In this episode, Noel Bradford follows that clean, quiet path of reconnaissance from public registers to a phone call that sounds unmistakably legitimate. We open on a simple truth: most social engineering isn’t a cartoon villain guessing passwords in the dark. It’s research, timing and pressure dressed up as plausibility. Noel and Corin map the attacker’s five-step journey — selection, mapping, pretext, delivery and pressure — and show how every ordinary piece of public information becomes a tile in a convincing story. Set against the uniquely open UK landscape of registries, data brokers and oversharing on professional networks, the episode becomes a procedural drama. You’ll hear how a director’s LinkedIn post about a conference can set the stage for an urgent Friday payment request, how job ads can hand an attacker the exact platform to fake, and how a single helpdesk script can be the thin crack through which a whole company falls. Through vivid examples — supplier impersonation, emergency MFA resets, Teams messages that replicate a boss’s tone — the episode explains why static verification checks fail and why ‘because the director said so’ is an invitation to fraud. We discuss Scattered Spider not to sensationalise, but to show how identity support processes become attack surfaces and why attackers treat due diligence like reconnaissance with ill intent. Noel moves from problem to practice: concrete defensive moves you can implement today — map your public exposure, write down verification rules, require independent checks on sensitive requests, train staff on pretext and pressure (not just typos and bad links), and treat your helpdesk as a security control. The advice is practical, procedural and, yes, a little boring — because that’s exactly what prevents crime. By the end you’ll see the small, human moments that make social engineering succeed — a rushed payment, a polite phone call, a culture that prizes speed over verification — and how changing those moments can take away an attacker’s easiest building blocks. Tune in to learn what an attacker would find about your business before lunch, and what you can remove before they get hungry.

6. juli 2026 - 21 min
episode The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap cover

The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap

They didn’t break in. They didn’t plant malware. They opened tabs, clicked links and joined the dots. In this episode we follow the quiet, methodical work of an attacker who builds a usable portrait of a UK small business director from nothing more than public records and a search box. It begins like a detective story and ends like a cautionary tale: Companies House entries, electoral data, LinkedIn posts, DNS records and job adverts become the clues that make fraud feel personal — because it is. Through the voices of Noel Bradford and Corrine Jefferson, the episode walks you through the attacker’s timeline: the first flick through Companies House to find directors and filing rhythms, the enrichment of that picture with open-register addresses and marketing data, the human-mapping on LinkedIn, and the technical fingerprint left in DNS, MX and certificate logs. Each step is ordinary, lawful and, crucially, assembled without a single hack. We make it concrete. In twenty minutes an attacker can produce a director profile, infer email providers, spot hiring signals that leak technology stacks, and spot behavioral seams to exploit. The lure is tailored; the language is familiar; the victim feels the email is meant for them. Social engineering stops being magic and becomes efficient administration with malicious intent — a repeatable, industrialized craft that preys on transparency. But this episode isn’t just alarmism. It frames the tension between public accountability and personal risk, showing why transparency designed for credit checks and journalism also creates a joined profile attackers love. We tell the story of how digital glitter — once data leaves its source — glints everywhere, and why suppression or removal is never instant or total. By the end you’ll feel that uncomfortable nudge: search your company on Companies House, check service addresses, review LinkedIn and job adverts, and audit your domain’s email records. The narrative closes by setting the scene for the next chapter in the series and challenging every listener to ask: what did I find about myself that an attacker could use first?

29. juni 2026 - 20 min
episode The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency cover

The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency

A firewall cannot save you from being badly run. For years, small businesses have been sold the idea that a perimeter box equals protection. When Fortinet disclosed exploited authentication bypass vulnerabilities, added to CISA's Known Exploited Vulnerabilities catalogue, the uncomfortable truth surfaced again: the firewall is not a wall. It is a computer at the edge of your network that runs software, has management access, and can be compromised. Defence in Depth means using multiple security layers so that when one fails, another slows the attacker, limits damage, or helps you spot the problem. The NCSC describes this as reducing single points of failure. Yet many small businesses still operate flat networks with exposed management, weak identity, old firmware, missing logs, and untested backups. This episode unpacks the Fortinet advisory, challenges the green dashboard culture, and delivers a practical checklist for the twenty-person firm. The panel argues about MSP accountability, board responsibility, and the difference between buying comfort and buying outcomes. No vendor worship. No reassurance fog. Just evidence, ownership, and the hard questions businesses should ask before the next advisory drops.

22. juni 2026 - 39 min
Enkelt Ă„ finne frem nye favoritter og lett Ă„ navigere seg gjennom innholdet i appen
Enkelt Ă„ finne frem nye favoritter og lett Ă„ navigere seg gjennom innholdet i appen
Liker at det er bÄde Podcaster (godt utvalg) og lydbÞker i samme app, pluss at man kan holde Podcaster og lydbÞker atskilt i biblioteket.
Bra app. Oversiktlig og ryddig. MYE bra innhold⭐⭐⭐

Velg abonnementet ditt

Mest populĂŠr

Premium

20 timer lydbĂžker

  • Eksklusive podkaster

  • Ingen annonser i Podimo shows

  • Avslutt nĂ„r som helst

PrĂžv gratis i 14 dager
Deretter 99 kr / mÄned

PrĂžv gratis

Premium Plus

100 timer lydbĂžker

  • Eksklusive podkaster

  • Ingen annonser i Podimo shows

  • Avslutt nĂ„r som helst

PrĂžv gratis i 30 dager
Deretter 169 kr / mÄned

PrĂžv gratis

Bare pÄ Podimo

PopulĂŠre lydbĂžker

Ofte stilte spÞrsmÄl

Flere spÞrsmÄl og svar
PrĂžv gratis

PrÞv gratis i 14 dager. 99 kr / MÄned etter prÞveperioden. Avslutt nÄr som helst.