⭐100K+ Monthly Downloads

⭐Top 20 Apple Management

⭐100K+ Monthly Downloads ⭐Top 20 Apple Management

The Small

Business

Cyber Security Guy


Welcome to the blog and podcast, where we share brutally honest views, sharp opinions, and lived experience from four decades in the technology trenches. Whether you're here to read or tune in, expect no corporate fluff and no pulled punches.

Everything here is personal. These are my and the team’s thoughts, opinions forged in the heat of battle! And not those of our employers, clients, or any other professional with whom we are associated.

If you’re offended, take it up with us, not them.

What you’ll get here (and on the podcast):

  • Straight-talking advice for small businesses that want to stay secure

  • Honest takes on cybersecurity trends, IT malpractice, and vendor nonsense

  • The occasional rant — and yes, the occasional expletive

  • War stories from the frontlines (names changed to protect the spectacularly guilty)

I've been doing this for over 40 years. I’ve seen genius, idiocy, and everything in between. Some of it makes headlines, and most of it should.

This blog and the podcast are where we break it all down.

Grab a coffee and pull up a chair, you need to see this!

Stop the Security Industry Bullshit. Wear Your Message.
Industry Analysis Corrine Jefferson Industry Analysis Corrine Jefferson

The Bank of England Just Told You Your Financial Sector Can't Do Basic Cybersecurity. Again.

The Bank of England runs live cyberattack simulations on the UK's most critical financial institutions every year. Real attacks, on live systems, designed by intelligence analysts who know exactly how sophisticated threat actors operate.

The 2025 results are in. Weak passwords. Overly permissive access controls. Systems that haven't been patched. Staff who hand over credentials when asked convincingly. Third year running. Same findings. If the institutions that hold your money, process your payroll, and underwrite your insurance can't manage basic cyber hygiene under direct regulatory pressure, you need to ask a harder question: what does your accountant's network look like?

Read More
Small Business Security Noel Bradford Small Business Security Noel Bradford

Your Attacker Already Knows Which Box You Picked

There's a philosophy thought experiment from the 1960s that explains, better than any threat report I've read, exactly why reactive security is a trap. It's called Newcomb's Paradox.

A near-perfect predictor places money in two boxes. Grab both and you walk away with £1,000. Grab just one and you walk away with a million.

Except the decision was made before you walked in the room. Your attackers work the same way. They've already run their reconnaissance.

They've already decided what kind of target you are. The question is: what did they see when they looked? Noel Bradford explains.

Read More
Threat Intelligence Noel Bradford Threat Intelligence Noel Bradford

Your Wi-Fi Guest Network Is a Lie

Last week, researchers proved something that should make every small business owner put down their coffee. Your Wi-Fi guest network, the one you set up so visitors don't touch your business systems, doesn't actually protect you. A new attack called AirSnitch lets anyone already on your network spy on every device connected to the same physical router, regardless of which network name they joined, regardless of whether you're running WPA2 or WPA3. Every single router tested failed. Here's what it means, explained without the jargon, and what you need to do before your next client walks through the door.

Read More
Industry Analysis, Opinion & Analysis Noel Bradford Industry Analysis, Opinion & Analysis Noel Bradford

Europe Is Leaving. The UK Is Sleepwalking. And Nobody in Charge Seems Bothered.

France banned Zoom and Teams from government. Germany is migrating 30,000 workstations to open source and saving €15 million a year. The Dutch Parliament demanded exit strategies from US cloud. Switzerland declared US cloud unsuitable for government data.

The UK has produced no sovereign cloud strategy, no government migration programme, no regulatory enforcement on CLOUD Act exposure, and no explicit guidance for commercial organisations.

Noel Bradford, with 40-odd years of watching the UK IT establishment make the same mistakes on repeat, asks the question nobody in Whitehall wants to answer: when did we decide that digital independence was somebody else's problem?

Read More
Industry Analysis News Desk Industry Analysis News Desk

Switzerland Said No. The UK Said Hold My Beer. The Palantir Case Study Every Business Owner Needs to Read.

Switzerland's military commissioned a 20-page risk assessment of Palantir's software. The findings were blunt: data held by Palantir could be accessed by the American government, leaks could not be technically prevented, and the Army would become dependent on Palantir specialists. The recommendation was unambiguous: consider alternatives. Neutral Switzerland quietly walked away.

The United Kingdom looked at the same company and gave them more than £900 million in contracts across the NHS, Ministry of Defence, policing, nuclear weapons support, and border planning. Same company. Same risks. Opposite conclusions. This is the case study every UK business owner needs to read.

Read More
Small Business Security Mauven MacLeod Small Business Security Mauven MacLeod

Your Cloud Stack Is Not Just Stationery: The Bet Your Business Made Without Realising It

You did not set out to build US-centric infrastructure. You just bought what was on page one of Google. Email, documents, calendars, chat, CRM, help desk, backups, monitoring: all US-owned, all subject to US law, all chosen on price and convenience without a single conversation about jurisdictional risk. Mauven MacLeod explains why your 30-person firm has made exactly the same strategic bet as the NHS and the Ministry of Defence, why "it is just stationery" stopped being true about five years ago, and what one awkward question on your next vendor call can change.

Read More
Compliance & Risk Management, Guest Blog Kathryn Renaud Compliance & Risk Management, Guest Blog Kathryn Renaud

DUAA: The "Keep Calm and Build a Workflow" Act 

The Data (Use and Access) Act just went live on 5 February, and if you're only hearing about it now, you're not alone. The commencement regulations were published two days before the provisions kicked in. That's the government's idea of adequate notice. Guest contributor Kathryn Renaud cuts through the panic with something actually useful: four repeatable workflows for DSARs, complaints, cookies, and automated decisions that any UK SMB can build this week with tools they already own. No expensive software. No consultant fees. Just structure, ownership, and documented processes. Read this before the ICO comes knocking.

Read More
PodCast, Opinion & Analysis Noel Bradford PodCast, Opinion & Analysis Noel Bradford

Weekend Reflection - Efficiency Theatre and the Tyranny of the Measurable

Why do smart people keep making the same catastrophic mistake? Cut security spending, congratulate themselves on efficiency, watch everything fall apart, spend vastly more recovering. It's not ignorance. It's psychology. Measurable costs are visible, politically defensible, easy to justify cutting. Invisible value is theoretical until it disappears. CFOs get promoted for cutting £50,000 from budgets. Nobody gets promoted for preventing breaches that don't happen. This asymmetry creates systematic bias toward destroying things that actually matter. Weekend reflection on why efficiency theatre keeps winning despite catastrophic costs.

Read More
PodCast, Case Studies Noel Bradford PodCast, Case Studies Noel Bradford

UK Case Study - The Manchester Marketing Agency That Cut Training and Lost Everything

Manchester marketing agency, 28 staff, £2.4M revenue. CFO proposed cutting security training: "£12,000 annually for slides nobody watches." Board agreed. Six months later, junior account manager clicked phishing link in fake client brief. No training meant she didn't recognise warning signs. Credentials stolen, ransomware deployed, three weeks offline. Recovery costs: £190,000. ICO investigation: inadequate training documented.

They saved £12,000 and spent £190,000 learning what training actually prevented. This is a real case, anonymized details, taught me never to treat training as optional expense. Names changed. Mistakes real. Costs actual.

Read More
PodCast, Practical Guides Noel Bradford PodCast, Practical Guides Noel Bradford

Practical Guide - Evaluating Security Cost Cuts Without Destroying Your Business (Copy)

Stop cutting security costs based on gut feel and budget pressure. Start using actual frameworks that calculate downside risk. This practical guide walks you through evaluating any security spending decision: What's the notional function versus actual value? What's the cost of being wrong? What's the expected cost multiplied by probability? What invisible value disappears when you cut this? Includes checklists, decision trees, and real cost calculations for training, MFA, insurance, IT staff, and vendor relationships. Because the British Library's £7 million lesson shouldn't need to be learned individually by every UK business.

They saved £12,000 and spent £190,000 learning what training actually prevented. This is a real case, anonymized details, taught me never to treat training as optional expense. Names changed. Mistakes real. Costs actual.

Read More
Threat Intelligence Mauven MacLeod Threat Intelligence Mauven MacLeod

The British Library's £7 Million MFA Decision

The British Library decided not to implement MFA on administrator accounts. Their reasoning: "practicality, cost and impact on ongoing programmes." That decision cost them £7 million in recovery, 600GB of staff data dumped on the dark web, and over a year of service disruption. This is Mauven's Take on one of the clearest examples of the doorman fallacy in UK history. When cost-cutting decisions focus narrowly on immediate expense whilst ignoring catastrophic downside risk, you get exactly this result. And before you say "but we're not a major institution," remember: the attack vector works identically on your systems.

Read More
PodCast, Cyber Security for Small Businesses Noel Bradford PodCast, Cyber Security for Small Businesses Noel Bradford

The Doorman Fallacy - Complete Framework for UK Businesses

I've watched businesses make the same catastrophic mistake for 40 years. They look at security costs through a narrow efficiency lens, define roles by their obvious function, cut them to save money, and completely miss the invisible value. Until it's gone. Then they spend 10 times more fixing what they broke. The doorman fallacy explains every stupid IT decision I've ever seen: training cuts that cost millions in breaches, MFA removal that gifts credentials to attackers, insurance cancellation that leaves businesses exposed, IT staff replacement that destroys institutional knowledge. Stop optimising for obvious functions. Start understanding actual value.

Read More
PodCast Noel Bradford PodCast Noel Bradford

The Doorman Fallacy - Podcast Episode Launch

What's the most expensive cost-saving decision you can make? Firing your hotel doorman and replacing him with an automatic door. Saves you £35,000 a year in salary, costs you £200,000 in lost revenue because your hotel just became ordinary. This isn't about hotels. It's about every IT budget cut I've seen in the last 40 years. New episode drops today: The Doorman Fallacy, or How to Accidentally Destroy Your Business Whilst Congratulating Yourself on Efficiency Gains. Featuring examples that will make you uncomfortably aware of past decisions.

Read More

⚠️ Full Disclaimer

This is my personal blog. The views, opinions, and content shared here are mine and any contributors and ours alone. They do not reflect or represent the views, beliefs, or policies of:

  • Our Day Job employers

  • Any current or past clients, suppliers, or partners

  • Any other organisation We affiliated with in any capacity

Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.

Where we mention products, services, or companies, that’s based purely on our own experiences and opinions — We are not being paid to promote anything. If that ever changes, we’ll make it clear.

In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.