News & Analysis
A Black Box with Flashy Lights: The NCSC's SilentGlass and the Question Nobody Is Asking Mauven MacLeod · 28 April 2026
NCSC's SilentGlass is technically sound government kit, now available commercially. But if you're still fighting phishing, it's probably not your next purchase.
Read more → Threats & Attacks
Your Office Router Has 19 Critical Vulnerabilities. Published Yesterday. Exploits Already Public. Corrine Jefferson · 28 April 2026
Nineteen critical flaws. One router model. All exploits published. If your office uses a Totolink A8000RU, you are already exposed.
Read more → Threats & Attacks
Threat Analysis: PyPI and npm Supply Chain Attacks, What UK SMBs Need to Know About the TeamPCP Campaign Mauven MacLeod · 27 April 2026
TeamPCP is back. Three concurrent package compromises in one week. Here is what UK businesses using Python or Node.js tooling need to do right now.
Read more → Threats & Attacks
Threat Analysis: BlackFile Extortion and Supply Chain Poisoning — UK Cyber Threats, 27 Apr 2026 Mauven MacLeod · 27 April 2026
Voice phishing plus credential harvesting. Malicious Python packages with 11 million monthly downloads. This is what active UK cyber threats look like today.
Read more → Podcast
The Government Finally Said It Out Loud: CyberUK 2026 and What It Actually Means for Your Business Noel Bradford · 27 April 2026
The government pledged £90m for SMB cyber resilience. Sounds impressive until you do the maths. That is £5.35 per business per year. Here is what actually matters from CyberUK 2026.
Read more → News & Analysis
How AI Is Changing State-Sponsored Cyber Threats for UK SMBs Kathryn Renaud · 26 April 2026
State-sponsored attackers are reaching small businesses through the systems they already rely on. Here is how to spot it and respond.
Read more → Threats & Attacks
Your MSP's Remote Support Tool Has a Backdoor. CISA Just Confirmed It. Corrine Jefferson · 26 April 2026
CISA just added SimpleHelp remote support vulnerabilities to its actively-exploited list. If your IT provider uses it, attackers may already have a path in.
Read more → Threats & Attacks
Threat Analysis: UK Cyber Threats Roundup, What SMBs Need to Know This Week Mauven MacLeod · 26 April 2026
A quiet day on the KEV and NVD feeds. Mauven explains why that is not the same as a safe day.
Read more → Cyber Security News
Week Ahead: Cyber Essentials v3.3 Goes Live Tomorrow and Your Certification Just Got Harder Noel Bradford · 26 April 2026
Cyber Essentials v3.3 goes live tomorrow. MFA and patching become auto-fail questions. Cloud services cannot be scoped out. Buckle up.
Read more → Opinion
Stop Blaming DNS and Start Understanding Your Own Bloody Network Noel Bradford · 25 April 2026
DNS is the messenger, not the murderer. The real problem is that most UK small businesses do not understand their own networks.
Read more → Case Study
The Accountancy Firm That Blamed DNS for Three Weeks While a Compromised Router Rewrote Their Network Map Lucy Harper · 24 April 2026
Three weeks. Two resolver changes. One compromised router nobody checked. How a UK accountancy firm blamed DNS while the real threat hid.
Read more → Practical Advice
The Five Step DNS Troubleshooting Guide Your Small Business Actually Needs Graham Falkner · 23 April 2026
Website not loading? Before you blame DNS, follow these five steps. A practical guide that saves hours of wasted time.
Read more → Network Security
The NCSC Built Protective DNS for Government. Private Sector SMBs Are Still Guessing. Mauven MacLeod · 22 April 2026
The NCSC has blocked 1.5 million malicious domains with Protective DNS. Private sector SMBs do not qualify. Here is what that gap means and how to close it.
Read more → Network Security
DNS Security Threats Are Not Theoretical: Cache Poisoning, Rogue Resolvers, and the 706,000 Servers Nobody Patched Noel Bradford · 21 April 2026
DNS security is not an enterprise problem. Cache poisoning and rogue resolvers are actively targeting small businesses right now.
Read more → Threats & Attacks
Fourth-Party Supply Chain Exposure: The Threat Vector UK Businesses Are Not Monitoring Corrine Jefferson · 20 April 2026
61% of organisations were breached through their supply chain last year. Just 7% monitor beyond immediate suppliers. That is a structural failure, not bad luck.
Read more → Podcast
It Is Always DNS, Except When It Isn't: Why Your Office Blames the Wrong Suspect Every Single Time Noel Bradford · 20 April 2026
Every IT person alive has said it is DNS. Half the time it is nonsense. Here is how to stop wasting hours chasing ghosts.
Read more → Case Study
The Invoice That Wasn't: A UK BEC Case Study Built From Documented Real-World Patterns Lucy Harper · 19 April 2026
Learn from a UK BEC case study where a property firm lost £12,100. Discover the one free policy that could have stopped it.
Read more → Threats & Attacks
Preparing for the Next Wave of Cyber Threats: Insights for UK SMBs Mauven MacLeod · 18 April 2026
63% of UK SMBs faced cyber incidents in 2023. Learn how to prepare and protect your business assets effectively.
Read more → Opinion
When McDonald's Gives Better Cybersecurity Advice Than Your IT Department Noel Bradford · 18 April 2026
When McDonald's Netherlands embarrassed the entire security industry with one ad, your password policy became the problem. Here is how to fix it.
Read more → News & Analysis
April 2026 Patch Tuesday: 167 CVEs, Two Zero-Days, and a Deadline You Cannot Afford to Miss Graham Falkner · 15 April 2026
167 CVEs. Two zero-days. One SharePoint flaw needs no password to exploit. April 2026 Patch Tuesday demands your attention today, not next week.
Read more →