The Small

Business

Cyber Security Guy

The Small Business Cyber Security Guy - A man with short gray hair and glasses posing with his hand on his chin against a dark background.

⭐100K+ Monthly Downloads | ⭐Top 20 Apple Management | 🎧>2.5K per episode

Welcome to the blog and podcast, where we share brutally honest views, sharp opinions, and lived experience from four decades in the technology trenches. Whether you're here to read or tune in, expect no corporate fluff and no pulled punches.

Everything here is personal. These are my and the team’s thoughts, not those of our employers, clients, or any poor soul professionally tied to me. If you’re offended, take it up with me, not them.

What you’ll get here (and on the podcast):

  • Straight-talking advice for small businesses that want to stay secure

  • Honest takes on cybersecurity trends, IT malpractice, and vendor nonsense

  • The occasional rant — and yes, the occasional expletive

  • War stories from the frontlines (names changed to protect the spectacularly guilty)

I've been doing this for over 40 years. I’ve seen genius, idiocy, and everything in between. Some of it makes headlines, and most of it should.

This blog and the podcast is where we unpack it all. Pull up a chair.

Prison Time for Directors? Part 2: Building the UK Cybersecurity Accountability Framework

Yes, you read that correctly. Prison time for directors who allow catastrophic cybersecurity failures. Before you close this tab in horror, hear me out. We already send directors to prison for health and safety failures. Workplace fatalities dropped 85% after the Health and Safety Executive got proper enforcement powers. The ICO? They send sternly worded letters whilst breaches affecting millions go unpunished. Today, Mauven and I lay out exactly what a proper UK cybersecurity enforcement regime would look like - one that protects small businesses whilst holding negligent executives accountable. Pull up a chair.

Read More
Podcast, Policy, Accountability Noel Bradford Podcast, Policy, Accountability Noel Bradford

Designing the Corporate Cyber Negligence Act (What Accountability Looks Like)

This week, we established why directors should face criminal prosecution for gross cybersecurity negligence. We examined the Synnovis case where a patient died because free MFA was not enabled. We provided technical analysis, psychological examination, and practical implementation guides. Saturday's opinion piece argued forcefully for criminal liability. Next week, we move from "why" to "how."

What would a Corporate Cyber Negligence Act actually say? What are the thresholds between bad luck and criminal negligence? How do we protect small businesses while targeting genuine negligence? What defences exist? How would enforcement work? We are designing the solution. Join us Monday.

Read More
Opinion & Analysis, Accountability, Policy, Podcast Noel Bradford Opinion & Analysis, Accountability, Policy, Podcast Noel Bradford

Enough. It Is Time to Send Negligent Directors to Prison for Cyber Failures.

I am tired of watching preventable disasters kill people while executives walk away with bonuses intact.

A patient died because Synnovis did not enable free multi-factor authentication. Nobody will face criminal prosecution.

If a construction director failed to provide hard hats and a worker died, that director would go to prison.

Yet when healthcare executives fail to enable free security controls and a patient dies, nothing happens. This is not justice. This is not accountability.

This is a broken system that treats cybersecurity negligence as an acceptable cost of doing business. It needs to stop. Here is why directors should face prison time for gross cyber negligence.

Read More
Case Studies, UK Incidents, Healthcare Security Noel Bradford Case Studies, UK Incidents, Healthcare Security Noel Bradford

The Synnovis Ransomware Disaster: Complete Timeline and Technical Analysis

On 3 June 2024, the Qilin ransomware gang compromised Synnovis, a pathology provider serving NHS hospitals across southeast London. Blood testing collapsed. Over 10,000 appointments were cancelled. More than 1,700 operations were postponed. A patient died waiting for test results that never arrived. The attack succeeded because multi-factor authentication was not enabled. Here is the complete timeline of how a preventable security failure cascaded into catastrophic harm, the technical details of the attack vector, the devastating human and financial cost, and what every UK business must learn from this disaster. This is what happens when free security controls are ignored.

Read More

How to Implement MFA Across Your Business in One Afternoon (Complete Guide)

After this week's coverage of the Synnovis death, many of you have asked: "How do I actually implement MFA in my business?" Here is your complete, practical guide. No jargon, no theory, just step-by-step instructions for enabling multi-factor authentication across your entire organisation. This afternoon. Right now. Whether you are running Microsoft 365, Google Workspace, or a mix of different services, this guide walks you through the exact process. I will show you how to configure systems, deploy authenticator apps, train your staff, and create backup plans for when people lose their phones. Let’s prevent another preventable disaster from happening to your business.

Read More
Industry Analysis, Psychology, Corporate Governance Mauven MacLeod Industry Analysis, Psychology, Corporate Governance Mauven MacLeod

The Psychology of Cybersecurity Negligence: Why Smart People Make Fatal Decisions

Nobody wakes up and decides to let patients die through cybersecurity negligence. Yet that is precisely what happened at Synnovis. The executives who failed to enable multi-factor authentication were not cartoon villains.

They were educated professionals running a critical healthcare organisation. So why did they make a decision that, in hindsight, seems obviously catastrophic?

The answer lies in the psychological mechanisms that allow intelligent people to rationalise terrible choices, the organisational structures that insulate decision-makers from consequences, and the systemic failure to connect cybersecurity decisions to real-world harm.

Understanding this psychology is essential to preventing the next preventable death.

Read More

Why Multi-Factor Authentication Could Have Prevented the Synnovis Death

When Beverley Bryant, former Chief Digital Information Officer at Guy's and St Thomas' NHS Foundation Trust, stated that the Synnovis attack "may not have happened" with two-factor authentication enabled, she was not speculating. She was describing technical reality.

The Qilin ransomware gang gained initial access through compromised credentials. Multi-factor authentication completely blocks this attack vector.

A patient died because a free security control was not enabled. This is not hindsight; it is basic cybersecurity hygiene that has been industry standard for over a decade.

Here is the technical explanation of exactly how MFA would have stopped this attack.

Read More
Podcast, Accountability, Healthcare Security Noel Bradford Podcast, Accountability, Healthcare Security Noel Bradford

Should Directors Face Prison Time for Cybersecurity Negligence?

On 3 June 2024, a patient arrived at a London hospital A&E feeling unwell. A blood test was ordered. The patient waited. The medics waited. They all waited some more. The patient died. Why? Ransomware had shut down blood testing at Synnovis, the NHS pathology provider.

The security control that would have stopped it? Multi-factor authentication. Completely free. Built into every platform. The consequences for executives who chose not to enable it?

Nothing. In this episode, we ask the uncomfortable question: what if directors faced prison time for gross cybersecurity negligence, just like they do for health and safety failures?

Read More
Industry Analysis Noel Bradford Industry Analysis Noel Bradford

When Your Biggest Customer Gets Hacked: The £1.9 Billion Lesson No One’s Talking About

Financial Accountant magazine just published my analysis of the £1.9 billion Jaguar Land Rover cyberattack. But here’s what the article couldn’t cover: the small suppliers who died from JLR’s breach. You didn’t get hacked. Your biggest customer did. You still lost everything.

One supplier laid off 40 people because JLR couldn’t place orders for six weeks. Proper security. Good practices. Still went bust. After 40 years in the IT world Intel, Disney, and the BBC, I’ve seen this pattern before. Enterprise companies have bailouts and cash reserves.

Small suppliers have three weeks of runway. Your cybersecurity doesn’t matter if your customer’s fails.

Read More
Patch Tuesday, Podcast, Hot Take Noel Bradford Patch Tuesday, Podcast, Hot Take Noel Bradford

November 2025 Patch Tuesday: A Perfect Storm of Critical Vulnerabilities Demands Immediate Action

Four zero-days. One perfect 10.0 severity score. Hundreds of thousands of sites already compromised.

Criminals are exploiting Exchange Servers, Magento shops, and Oracle ERP systems right now - whilst you're reading this. SAP's vulnerability was so bad they deleted the entire component rather than fix it. WordPress sites are falling to a plugin bug that shouldn't exist. And that's just November.

Your patching strategy just became a lot more urgent.

Graham Falkner breaks down what to patch first:

Read More
Podcast, UK Online Safety Act Mauven MacLeod Podcast, UK Online Safety Act Mauven MacLeod

Ofcom's Secret VPN Surveillance: When Britain Embraced the Authoritarian Playbook

Ofcom admits it is monitoring VPN use across Britain with a secret AI tool and unnamed data sources. That should worry any small business that relies on encrypted links for daily work. The tool cannot tell a secure office connection from someone dodging age checks. Section 121 still sits in law, ready to force scanning of encrypted chats. Does that sound like a free internet to you? Document your use. Keep your controls tight. Ask your MP why this is acceptable. Do you want regulators watching your privacy tools without showing their maths? Will you push back today? Act now.

Read More
Technology Risk, Business Security Graham Falkner Technology Risk, Business Security Graham Falkner

Opinion: UK SMBs Are Funding AI's Energy Crisis and Nobody Asked Permission

Here's a question for your weekend: Did anyone ask if UK small businesses wanted to fund Microsoft's nuclear reactor restart?

Because that's what's happening. While Microsoft spends $1.6 billion restarting Three Mile Island, Google partners with Kairos Power for small modular reactors, and Amazon secures nuclear capacity across multiple projects, your cloud bills are climbing to pay for it.

Nobody took a vote. Nobody asked permission. Tech giants made a collective decision that AI is worth unlimited energy consumption, and UK SMBs are involuntary investors in that bet. Let's talk about that.

Read More
Industry Analysis, Business Security Mauven MacLeod Industry Analysis, Business Security Mauven MacLeod

The Nottingham Agency That Spent £47,000 on Cloud Bills They Didn't Need

Twenty-three employees. Eighteen months. Forty-seven thousand pounds wasted on cloud infrastructure they didn't need, SaaS subscriptions nobody used, and auto-scaling rules designed by a consultant who'd never checked back. This isn't a horror story about a massive enterprise with unlimited budget.

This is CloudBridge Digital, a Nottingham digital agency that discovered they'd been hemorrhaging cash while Microsoft, AWS, and a parade of SaaS vendors quietly helped themselves to the company bank account.

Here's what went wrong, how they discovered it, and the six-month recovery plan that clawed back £32,000 of annual waste.

Read More
Business Security, Technology Risks Graham Falkner Business Security, Technology Risks Graham Falkner

7 Actions to Stop Your Cloud Bill Funding AI's Nuclear Ambitions

Microsoft's restarting Three Mile Island. Google's building small modular reactors. Amazon's buying nuclear capacity. And you're getting the bill. While tech giants scramble for gigawatts to power their AI fantasies, your cloud costs are climbing faster than a hyperactive squirrel on espresso.

AWS up 15%, Azure up 12%, SaaS tools adding "AI features" you didn't ask for at 20% premium. But here's what nobody's telling you: you don't need to accept this as inevitable. Seven specific actions you can take today to stop funding Silicon Valley's nuclear renaissance with your operating budget.

Read More

When the Panic Becomes Obvious

Three Mile Island. You remember it, right? The 1979 nuclear accident that terrified an entire generation and effectively killed nuclear power plant construction in America for 40 years?

Microsoft just spent $1.6 billion to restart Unit 1. Not for clean energy virtue signaling. Because they're bloody desperate.

Google committed to 500 megawatts of Small Modular Reactors. Amazon's all-in on multiple nuclear projects. Meta wants up to 4 gigawatts.

Billions in nuclear investment. Timeline: 2028 to 2035 delivery.

Meanwhile, AI's energy demands are immediate and accelerating. And you're paying for every watt through exploding cloud bills.

Read More
Technology Risks, Threat Intelligence Noel Bradford Technology Risks, Threat Intelligence Noel Bradford

When Two Swiss Scientists Decided Silicon Wasn't Good Enough

They're growing brain tissue in Swiss laboratories and using it to process information. Not simulations. Actual living human neurons, derived from skin cells, housed in specialized chambers, connected to electrodes, computing.

FinalSpark's Neuroplatform has 16 brain organoids containing roughly 160,000 neurons total. Each organoid interfaces with 8 electrodes sampling at 30 kHz. The system has operated continuously for four years, testing over 1,000 organoids, collecting 18 terabytes of data.

The peer-reviewed research is published. Nine universities have free access. You can watch neurons computing in real-time on their website.

This is happening right now. Not science fiction. Science fact.

Read More

No MFA? No Certification. The Cyber Essentials Rule That Changes Everything

The April 2026 Cyber Essentials update introduces a game-changing rule: multi-factor authentication is now mandatory. Not recommended. Not "nice to have." Mandatory. If your cloud service offers MFA (free or paid) and you're not using it, you automatically fail. No exceptions.

This single change will expose how many UK businesses have been skating by with terrible security. With potentially 30,000+ certified companies lacking proper MFA configuration, the fallout will be significant.

You've got six months to prepare. I can tell you this is overdue and absolutely necessary. Here's what you need to do now.

Read More
Threat Intelligence, Technology Risks Noel Bradford Threat Intelligence, Technology Risks Noel Bradford

The Frankenstein Computer That's Actually Real

There's a lab in Switzerland where they're building computers out of living human neurons. Sounds completely barking mad, right?

Here's the thing: these brain cells compute using one million times less energy than silicon. Meanwhile, training a single AI model now produces the carbon emissions of 500 cars over their entire lifetimes. Microsoft, Google, and Amazon just committed billions to restart nuclear power plants because they can't keep the lights on.

And your business? You're paying for every watt through exploding cloud bills. Listen to this week's episode. It's properly mental.

Read More
PodCast, Opinion & Analysis Noel Bradford PodCast, Opinion & Analysis Noel Bradford

Weekend Reflection - Efficiency Theatre and the Tyranny of the Measurable

Why do smart people keep making the same catastrophic mistake? Cut security spending, congratulate themselves on efficiency, watch everything fall apart, spend vastly more recovering. It's not ignorance. It's psychology. Measurable costs are visible, politically defensible, easy to justify cutting. Invisible value is theoretical until it disappears. CFOs get promoted for cutting £50,000 from budgets. Nobody gets promoted for preventing breaches that don't happen. This asymmetry creates systematic bias toward destroying things that actually matter. Weekend reflection on why efficiency theatre keeps winning despite catastrophic costs.

Read More
PodCast, Case Studies Noel Bradford PodCast, Case Studies Noel Bradford

UK Case Study - The Manchester Marketing Agency That Cut Training and Lost Everything

Manchester marketing agency, 28 staff, £2.4M revenue. CFO proposed cutting security training: "£12,000 annually for slides nobody watches." Board agreed. Six months later, junior account manager clicked phishing link in fake client brief. No training meant she didn't recognise warning signs. Credentials stolen, ransomware deployed, three weeks offline. Recovery costs: £190,000. ICO investigation: inadequate training documented.

They saved £12,000 and spent £190,000 learning what training actually prevented. This is a real case, anonymized details, taught me never to treat training as optional expense. Names changed. Mistakes real. Costs actual.

Read More

⚠️ Full Disclaimer

This is my personal blog. The views, opinions, and content shared here are mine and mine alone. They do not reflect or represent the views, beliefs, or policies of:

  • My employer

  • Any current or past clients, suppliers, or partners

  • Any other organisation I’m affiliated with in any capacity

Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.

Where I mention products, services, or companies, that’s based purely on my own experience and opinions — I’m not being paid to promote anything. If that ever changes, I’ll make it clear.

In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.