⭐100K+ Monthly Downloads

⭐Top 20 Apple Management

⭐100K+ Monthly Downloads ⭐Top 20 Apple Management

The Small

Business

Cyber Security Guy


Welcome to the blog and podcast, where we share brutally honest views, sharp opinions, and lived experience from four decades in the technology trenches. Whether you're here to read or tune in, expect no corporate fluff and no pulled punches.

Everything here is personal. These are my and the team’s thoughts, opinions forged in the heat of battle! And not those of our employers, clients, or any other professional with whom we are associated.

If you’re offended, take it up with us, not them.

What you’ll get here (and on the podcast):

  • Straight-talking advice for small businesses that want to stay secure

  • Honest takes on cybersecurity trends, IT malpractice, and vendor nonsense

  • The occasional rant — and yes, the occasional expletive

  • War stories from the frontlines (names changed to protect the spectacularly guilty)

I've been doing this for over 40 years. I’ve seen genius, idiocy, and everything in between. Some of it makes headlines, and most of it should.

This blog and the podcast are where we break it all down.

Grab a coffee and pull up a chair, you need to see this!

Stop the Security Industry Bullshit. Wear Your Message.
Threat Intelligence Graham Falkner Threat Intelligence Graham Falkner

March Patch Tuesday 2026: No Zero-Days, No Excuses

Microsoft shipped March 2026 Patch Tuesday on 10 March with no actively exploited zero-days. And I can already hear the conversation in the finance department: "Quiet month, push it to next quarter." Wrong.

This month's release covers six Windows elevation-of-privilege flaws that Microsoft itself rates as Exploitation More Likely, a critical Excel bug that can hijack Copilot Agent to exfiltrate data with near zero user interaction, and two Office remote code execution issues that fire through the Preview Pane. Quiet months are when attackers catch you napping. Get the cumulative update applied. This week.

Read More
Threat Intelligence, Patch Tuesday Graham Falkner Threat Intelligence, Patch Tuesday Graham Falkner

Six Zero-Days, One Tuesday, and Your Approval Process Is Still Broken

Graham here. Microsoft dropped six actively exploited zero-days on us yesterday, three of them publicly disclosed before the patch even landed. That means attackers had working exploits before you had fixes.

Three bypass your security warnings entirely. One gives SYSTEM access through Remote Desktop Services. CrowdStrike confirmed active abuse in the wild. Meanwhile, SAP shipped a CVSS 9.9 code injection flaw and Adobe patched 44 vulnerabilities across nine products.

If your patching approval process takes longer than 48 hours, you are giving attackers a documented, step-by-step guide to your network. Here is what to patch first.

Read More
Technical Analysis, Patch Tuesday, Podcast Graham Falkner Technical Analysis, Patch Tuesday, Podcast Graham Falkner

January 2026 Patch Tuesday: New Year, New Nightmares for SMB Security

Microsoft’s January 2026 Patch Tuesday delivered 114 updates and 3 zero-days – with SharePoint Toolshell, Fortinet VPN bypass, and HPE OneView RCE leading the charge. This isn’t theoretical. Attackers are already exploiting these in the wild. From Adobe Acrobat to Apple’s WebKit spyware holes, no vendor was spared. SMB IT teams, you’re on the clock. Here’s your no-fluff, brutally honest patching guide.

Read More
News Desk News Desk

Monday's Cyber Carnage: Instagram Chaos, Nissan Breach, and Why Tomorrow's Patch Tuesday Can't Come Soon Enough

Monday, 12th January 2026. Instagram denies a breach while millions get password reset emails. Nissan admits attackers stole employee data. A UK school in Nuneaton faces "serious" cyber attack. Three London councils still recovering from November breach affecting 100,000 households. India's entire mobile security infrastructure looks dodgy as hell. BreachForums, the criminal marketplace itself, gets its database leaked. And the US withdraws from global cyber coordination bodies right when we need cooperation most. Eight incidents. One common thread: credentials, governance failures, and shared infrastructure vulnerabilities. Tomorrow is Patch Tuesday, but you can't patch stupid.

Read More
Noel Bradford Noel Bradford

Patch Tuesday July 2025: When Shadow IT Makes Security Updates a Nightmare

Microsoft's July 2025 Patch Tuesday just dropped 130 security fixes while most UK SMBs remain blind to 42% of applications running on their networks. From my NCSC experience, this represents a systematic organizational failure: you cannot patch what you cannot see.

Critical vulnerabilities in Windows Kernel, BitLocker, and authentication systems require immediate deployment, but Shadow IT applications will break unpredictably.

Worse, the buried Secure Boot certificate expiration warning affects every Windows system since 2012 and could cause boot failures by June 2026. Patch management with unauthorized applications is like performing surgery blindfolded while the patient keeps moving.

Read More
Technology Risks Noel Bradford Technology Risks Noel Bradford

The Hidden Apps Undermining Your Business Security

Yesterday's Episode 6 dropped the bombshell: 42% of business applications are unauthorized. Today we're diving deeper into the hidden app epidemic destroying UK SMB security.

Karen's Dropbox backup strategy with password "Password" shared via email. Marketing teams feeding confidential data to AI platforms. Customer service operations running through WhatsApp Business storing financial information in chat logs.

DNS monitoring revealing 200+ cloud connections in a single week. This isn't isolated incidents, it's systematic security failure hiding in plain sight. The digital squatters have moved in, and most businesses have no idea they're paying rent to criminals.

Read More
Threat Intelligence Noel Bradford Threat Intelligence Noel Bradford

Week Ahead Preview: Microsoft's Monthly Security Roulette

This week we explored compliance theatre vs real security. Next week, we're diving into the monthly war zone that every IT team knows: Microsoft's Patch Tuesday roulette where one wrong decision can sink your business.

Monday's podcast takes you inside the 6 PM chaos when UK teams scramble with late-breaking updates, and Tuesday's deep-dive exposes why traditional patch management advice is built for enterprises that don't exist.

Plus, practical survival strategies for when you're fighting attackers who reverse-engineer fixes faster than you can deploy them.

Read More

⚠️ Full Disclaimer

This is my personal blog. The views, opinions, and content shared here are mine and any contributors and ours alone. They do not reflect or represent the views, beliefs, or policies of:

  • Our Day Job employers

  • Any current or past clients, suppliers, or partners

  • Any other organisation We affiliated with in any capacity

Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.

Where we mention products, services, or companies, that’s based purely on our own experiences and opinions — We are not being paid to promote anything. If that ever changes, we’ll make it clear.

In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.