The Small Business

Cyber Security Guy

Welcome to my blog and podcast, where I share brutally honest views, sharp opinions, and lived experience from four decades in the technology trenches. Whether you're here to read or tune in, expect no corporate fluff and no pulled punches.

Everything here is personal. These are my thoughts, not those of my employer, clients, or any poor soul professionally tied to me. If you’re offended, take it up with me, not them.

What you’ll get here (and on the podcast):

  • Straight-talking advice for small businesses that want to stay secure

  • Honest takes on cybersecurity trends, IT malpractice, and vendor nonsense

  • The occasional rant — and yes, the occasional expletive

  • War stories from the frontlines (names changed to protect the spectacularly guilty)

I've been doing this for over 40 years. I’ve seen genius, idiocy, and everything in between. Some of it makes headlines, and most of it should.

This blog and the podcast is where I unpack it all. Pull up a chair.

Man wearing glasses and a light gray sweater, smiling
Cyber Essentials: Does It Work and Is It Worth the Effort for Small Businesses?
Noel Bradford Noel Bradford

Cyber Essentials: Does It Work and Is It Worth the Effort for Small Businesses?

Cyber Essentials is a government-backed certification that helps small businesses get basic cybersecurity right. But does it actually work, and is it worth the time and money? In this article, we look at what Cyber Essentials involves, how much it costs, and whether it genuinely protects your business from cyber threats. With fresh insights from the UK government’s 2024 evaluation, we uncover the real-world benefits for small businesses.

Read More
Why Small Businesses Are a Hacker’s Favourite Snack (And How Not to Be One)
Noel Bradford Noel Bradford

Why Small Businesses Are a Hacker’s Favourite Snack (And How Not to Be One)

Small businesses love to think they’re “too small” for hackers to bother with. Reality check: that’s exactly why cybercriminals love you. No security team. No proper defences. Just an unlocked digital front door and a password that might as well be ‘password123’. If you’re not taking cybersecurity seriously, you’re practically begging to be hacked.

In this post, we break down why small businesses are an easy target, the biggest security mistakes they make, and how Cyber Essentials can stop your business from becoming a cybercriminal’s next easy payday. Spoiler: it’s easier (and cheaper) than you think.

Read More
Teams & Quick Assist: Microsoft’s New Gift to Cybercriminals Everywhere
Noel Bradford Noel Bradford

Teams & Quick Assist: Microsoft’s New Gift to Cybercriminals Everywhere

In one of the most embarrassing cyber trends of 2025, hackers are using Microsoft Teams to impersonate IT support, then tricking employees into launching Windows Quick Assist, effectively handing remote control of their computers to criminals. Once inside, attackers install malware, steal credentials, and deploy persistent backdoors — all thanks to tools Microsoft built and businesses blindly trust. If your staff still believe every Teams message with ‘IT’ in the name is legitimate, congratulations — you’re already a statistic. Learn how this absurdly preventable scam works and what you need to do right fucking now to avoid becoming the next case study in cybersecurity failure.

Read More
Top Cyber Security Certifications in 2025: Boost Your Career and Your Sanity
Noel Bradford Noel Bradford

Top Cyber Security Certifications in 2025: Boost Your Career and Your Sanity

In the chaotic world of cyber security certifications, 2025 offers more choices than ever; but not all of them are worth your time (or sanity). From the gold-standard CISSP to the controversial CompTIA Security+, this guide cuts through the marketing fluff to reveal which certifications actually boost your career and which ones just boost someone’s profit margins. Whether you’re aiming to become a penetration tester, security manager, or cloud security expert, this brutally honest review will help you pick wisely — and avoid the snake oil.

Read More
Over 4,000 ISP Networks Hacked Because People Still Use ‘admin123’ as a Password — WTF?
Noel Bradford Noel Bradford

Over 4,000 ISP Networks Hacked Because People Still Use ‘admin123’ as a Password — WTF?

More than 4,000 ISP networks got hacked because they left their admin passwords set to 'password123' — and shockingly, that didn’t work out well. Cybercriminals brute-forced their way into routers, servers, and management systems, planting infostealers, cryptominers, and enough malware to make an antivirus cry. This wasn’t some elite state-sponsored operation; it was basic-level script kiddie shit that worked because ISPs still treat security like a hobby. Find out how it happened, why your broadband might be slower than a fax machine, and how these companies left the front door wide open for hackers.

Read More
The Impact of 5G on Cyber Security: What Small Businesses Need to Know
Noel Bradford Noel Bradford

The Impact of 5G on Cyber Security: What Small Businesses Need to Know

5G promises faster speeds and endless connectivity, but for small businesses, it’s also a cyber security minefield. More connected devices means more targets for hackers, and 5G’s speed amplifies every attack. This article explores how 5G is rewriting the cyber risk playbook — and what small businesses need to do to avoid becoming easy prey.

Read More
YouTube Phishing Scam – Deepfake CEO Videos Hijacking Creators’ Accounts
Noel Bradford Noel Bradford

YouTube Phishing Scam – Deepfake CEO Videos Hijacking Creators’ Accounts

Hackers are using deepfake videos of YouTube’s CEO to phish creators into handing over their accounts. In this absurd cybercrime twist, scammers send fake YouTube monetization emails featuring a realistic AI-generated video of Neal Mohan, urging creators to “confirm policy updates” via a phishing link disguised as YouTube Studio. The result? Stolen credentials, hijacked channels, and another WTF moment in cybersecurity. This scam is shockingly effective because it uses YouTube’s own private video sharing to appear legitimate. Find out how the scam works, how YouTube is responding, and what every creator (and business) must do to avoid getting scammed by a CEO who doesn’t even know he’s in the video.

Read More
Cyber Essentials Is Changing in April 2025 — Here’s What You Need to Know (Before It Bites You)
Noel Bradford Noel Bradford

Cyber Essentials Is Changing in April 2025 — Here’s What You Need to Know (Before It Bites You)

Big changes are coming to Cyber Essentials from April 2025, and they are not just cosmetic. From embracing passwordless logins to treating remote workers' devices like company kit, the new rules mean businesses need to sharpen up their security game — fast. Whether you are managing firewalls, updating browser extensions, or figuring out how to patch a vulnerability with no patch, this update raises the bar. Ignore it at your peril.

Read More
Implementing Zero Trust Security: A Step-by-Step Guide for Small Businesses
Noel Bradford Noel Bradford

Implementing Zero Trust Security: A Step-by-Step Guide for Small Businesses

Trust no one — not even your own staff. That’s the heart of Zero Trust security, the modern approach that treats every device, user, and login as suspicious until proven safe. This guide walks small businesses through the why, what, and how of Zero Trust, helping you lock down your network before cyber criminals stroll right in.

Read More
The US Just Bent Over for Putin — And They’ve Left Every UK SMB Holding Its Own Arse in the Wind
Noel Bradford Noel Bradford

The US Just Bent Over for Putin — And They’ve Left Every UK SMB Holding Its Own Arse in the Wind

In a move that defies logic, common sense, and basic self-preservation, the US just ordered its cyber defenders to stop investigating Russian attacks. Why should UK businesses care? Because when the world's cyber watchdog leaves the door wide open, every UK SMB becomes an easier target. This isn’t politics — this is your business continuity on the line.

Read More
Gmail Scams 2025: Nutty Cyber Squirrel Survival Guide
Noel Bradford Noel Bradford

Gmail Scams 2025: Nutty Cyber Squirrel Survival Guide

Gmail users face a fresh wave of scams in 2025. Cybercriminals now use artificial intelligence, Google Calendar invites, and fake shared Docs to trick you. Learn how to spot the latest tricks and protect your inbox in this tongue-in-cheek survival guide.

Read More
Data Theft: Why Hackers Don’t Bother Locking Your Files Anymore – They Just Steal Them
Noel Bradford Noel Bradford

Data Theft: Why Hackers Don’t Bother Locking Your Files Anymore – They Just Steal Them

Ransomware attacks have changed — and the price for protecting your stolen data now averages £475,000. Hackers are skipping the hassle of file encryption and instead stealing data directly, then demanding payment to keep it private. This shift makes it even clearer that prevention, through schemes like Cyber Essentials, is far cheaper than paying criminals after the fact. In this article, we explore why data theft is the new normal, why small businesses are at risk, and what every company should be doing to stay out of the hackers’ crosshairs.

Read More
Apple vs. The UK Government: A Petty Breakup Over Encryption
Noel Bradford Noel Bradford

Apple vs. The UK Government: A Petty Breakup Over Encryption

The UK government and Apple are in a messy breakup, and—spoiler alert—it’s not mutual. Apple has yanked Advanced Data Protection (ADP) from the UK faster than a politician dodging accountability, all because the government wants a sneaky backdoor into everyone’s iCloud. Apple’s response? “Yeah, no.”

The Investigatory Powers Act (IPA) 2016—affectionately nicknamed the Snooper’s Charter—gives the UK authorities the power to demand weaker encryption, which, as every cybersecurity expert knows, is about as smart as setting your password to “password123.” Apple, not one to be bullied, packed up and left, meaning UK users are now stuck with less protection and more vulnerability.

So, who wins? Not the everyday user, who now gets to live in constant fear that their private data is an all-you-can-eat buffet for cybercriminals. But hey, at least the UK government can pat itself on the back for really sticking it to privacy. Welcome to 2025—where security is optional, surveillance is mandatory, and Apple just swiped left on Britain.

Read More

⚠️ Full Disclaimer

This is my personal blog. The views, opinions, and content shared here are mine and mine alone. They do not reflect or represent the views, beliefs, or policies of:

  • My employer

  • Any current or past clients, suppliers, or partners

  • Any other organisation I’m affiliated with in any capacity

Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.

Where I mention products, services, or companies, that’s based purely on my own experience and opinions — I’m not being paid to promote anything. If that ever changes, I’ll make it clear.

In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.