Network Security
DNS Security Threats Are Not Theoretical: Cache Poisoning, Rogue Resolvers, and the 706,000 Servers Nobody Patched Noel Bradford · 21 April 2026
DNS security is not an enterprise problem. Cache poisoning and rogue resolvers are actively targeting small businesses right now.
Read more → Threats & Attacks
Fourth-Party Supply Chain Exposure: The Threat Vector UK Businesses Are Not Monitoring Corrine Jefferson · 20 April 2026
61% of organisations were breached through their supply chain last year. Just 7% monitor beyond immediate suppliers. That is a structural failure, not bad luck.
Read more → Podcast
It Is Always DNS, Except When It Isn't: Why Your Office Blames the Wrong Suspect Every Single Time Noel Bradford · 20 April 2026
Every IT person alive has said it is DNS. Half the time it is nonsense. Here is how to stop wasting hours chasing ghosts.
Read more → Case Study
The Invoice That Wasn't: A UK BEC Case Study Built From Documented Real-World Patterns Lucy Harper · 19 April 2026
Learn from a UK BEC case study where a property firm lost £12,100. Discover the one free policy that could have stopped it.
Read more → Threats & Attacks
Preparing for the Next Wave of Cyber Threats: Insights for UK SMBs Mauven MacLeod · 18 April 2026
63% of UK SMBs faced cyber incidents in 2023. Learn how to prepare and protect your business assets effectively.
Read more → Opinion
When McDonald's Gives Better Cybersecurity Advice Than Your IT Department Noel Bradford · 18 April 2026
When McDonald's Netherlands embarrassed the entire security industry with one ad, your password policy became the problem. Here is how to fix it.
Read more → News & Analysis
April 2026 Patch Tuesday: 167 CVEs, Two Zero-Days, and a Deadline You Cannot Afford to Miss Graham Falkner · 15 April 2026
167 CVEs. Two zero-days. One SharePoint flaw needs no password to exploit. April 2026 Patch Tuesday demands your attention today, not next week.
Read more → Case Study
A Fridge Failed. The Complaint Went Nowhere. The Data Request Became the Next Dispute. Lucy Harper · 13 April 2026
A household with refrigerated medication says the paid route delivered a worse practical outcome than the free one, and that the later data request became a dispute of its own.
Read more → Podcast
Week Ahead: What's Coming on The Small Business Cyber Security Guy Noel Bradford · 12 April 2026
The cyber insurance series is complete. Six posts, one episode. Next week: the Microsoft 365 threat landscape as it actually stands in 2026.
Read more → Opinion
Your Insurer Isn't Betting On Your Security. They're Betting You Can't Prove It. Noel Bradford · 11 April 2026
Over 40% of UK cyber claims are denied. Not because businesses are fraudulent: because the real product insurers sell is plausible deniability, not coverage.
Read more → Case Study
MFA on the Firewall, Not the Servers: The Case That Shows How UK Cyber Claims Really Die Lucy Harper · 10 April 2026
A UK business said yes to MFA on their proposal form. The attack came through servers with no MFA. The policy was voided. Lucy Harper investigates.
Read more → Practical Advice
Six Controls That Stand Between You and a Denied Cyber Claim Graham Falkner · 9 April 2026
UK insurers check six specific technical controls after a breach. If they're not in place and documented, your claim is at risk. Here's the practical checklist for UK SMBs.
Read more → News & Analysis
Red Canary's March 2026 Threat Report: What UK Small Businesses Need to Do This Week Graham Falkner · 8 April 2026
Paste-and-run is now the dominant attack method. Mac is not safe. Vidar is back. Red Canary's March data, translated into steps you can actually take.
Read more → Threats & Attacks
Your IT Support Tool Is Now a Burglary Kit: How STAC6405 Is Weaponising Legitimate RMM Software Corrine Jefferson · 8 April 2026
Attackers are weaponising the same remote access tools your IT team uses. Sophos has the receipts. Here is what happened and what you need to do.
Read more → Opinion
Dave Is Your Biggest Security Vulnerability and He Does Not Even Know It Noel Bradford · 8 April 2026
Dave configured the servers in 2014 and only Dave knows how they work. Dave is not a solution. Dave is a liability.
Read more → Threats & Attacks
The War Exclusion in Your Cyber Policy: Why Being Collateral Damage Might Not Be Covered Mauven MacLeod · 8 April 2026
Your cyber policy probably excludes losses from state-backed attacks. You may not have read that clause. If a nation-state campaign sweeps through your sector, it could void your cover entirely.
Read more → Opinion
WordPress Isn't a Website. It's a Patch Management Emergency With a Blog Attached. Noel Bradford · 7 April 2026
50,000 WordPress sites exposed by one contact form plugin. CVSS 9.8. No login required. This is not bad luck. This is the WordPress business model.
Read more → Case Study
The Package Your Developer Trusted: How the Axios Supply Chain Attack Put 100 Million Downloads at Risk Lucy Harper · 7 April 2026
One compromised npm account. Two poisoned packages. 100 million weekly downloads at risk. Who is accountable when open-source governance fails?
Read more → Threats & Attacks
Two Zero-Days, Zero Patches, Zero Excuses: Windows and Fortinet Are on Fire This Week Corrine Jefferson · 7 April 2026
Two working exploits in one week. One public, one confirmed in the wild. Neither fully patched. Here is what UK SMBs need to do right now.
Read more → UK Compliance & Regulation
The Proposal Form That's Building a Landmine Under Your Business Graham Falkner · 7 April 2026
Every answer on your cyber insurance proposal form will be checked against your network logs if you ever claim. Most SMBs answer how they'd like things to be, not how they actually are.
Read more →