The Small Business

Cyber Security Guy

Welcome to my blog and podcast, where I share brutally honest views, sharp opinions, and lived experience from four decades in the technology trenches. Whether you're here to read or tune in, expect no corporate fluff and no pulled punches.

Everything here is personal. These are my thoughts, not those of my employer, clients, or any poor soul professionally tied to me. If you’re offended, take it up with me, not them.

What you’ll get here (and on the podcast):

  • Straight-talking advice for small businesses that want to stay secure

  • Honest takes on cybersecurity trends, IT malpractice, and vendor nonsense

  • The occasional rant — and yes, the occasional expletive

  • War stories from the frontlines (names changed to protect the spectacularly guilty)

I've been doing this for over 40 years. I’ve seen genius, idiocy, and everything in between. Some of it makes headlines, and most of it should.

This blog and the podcast is where I unpack it all. Pull up a chair.

Man wearing glasses and a light gray sweater, smiling
In-House IT vs. MSP: The Real Cost of IT Support for Businesses
SMB IT Operations, MSP Selection Noel Bradford SMB IT Operations, MSP Selection Noel Bradford

In-House IT vs. MSP: The Real Cost of IT Support for Businesses

Should your business handle IT in-house or outsource to a Managed Service Provider (MSP)? On paper, an in-house IT team might sound ideal—until you see the real costs. A single IT manager can set you back £80K+ a year, and that’s before factoring in security tools, compliance, and the inevitable sick days. Meanwhile, a properly managed MSP delivers 24/7 support, robust cybersecurity, and compliance-ready solutions—at a fraction of the price. If your IT plan is to rely on “Dave from accounts” to fix the Wi-Fi, good luck. The smarter choice? Investing in IT before disaster strikes.

Read More
Microsoft Exchange Online: How the Actual F*!# Do You Break Email for a Week?
Microsoft, Outage, Exchange Online Noel Bradford Microsoft, Outage, Exchange Online Noel Bradford

Microsoft Exchange Online: How the Actual F*!# Do You Break Email for a Week?

For seven excruciating days, Microsoft completely broke email transport, crippling businesses worldwide. A botched update turned the simplest, most stable IT function into a flaming dumpster fire, leaving users helpless while Microsoft sat in silence for three days before admitting anything was wrong.

How do you screw up SMTP, MAPI, and basic email delivery in 2025? How does a trillion-dollar company make email less reliable than it was in the 1980s? And more importantly—why should you still trust Microsoft 365 after this catastrophic f*-up? Buckle up, we’re diving in!

Read More
ChatGPT Operator Data Leak – Why Your AI Assistant Can’t Keep a Secret
Noel Bradford Noel Bradford

ChatGPT Operator Data Leak – Why Your AI Assistant Can’t Keep a Secret

ChatGPT Operator, the AI agent with browsing powers, can be hijacked via prompt injection, causing it to leak private data or obey hidden attacker commands. Learn how this exploit works, why AI assistants need serious supervision, and what businesses must do to avoid their AI leaking client data to the internet.

Read More
The StubHub Ticket Heist: When Cybercriminals Outsmarted the Entire Concert Industry with Basic URL Tricks
Noel Bradford Noel Bradford

The StubHub Ticket Heist: When Cybercriminals Outsmarted the Entire Concert Industry with Basic URL Tricks

Two criminals stole £500k worth of Taylor Swift tickets using nothing more than stolen StubHub URLs. This basic security failure exposes a flaw in how digital tickets are secured — and it’s a lesson for every business that relies on magic links. Find out what went wrong and how to protect your own platform from the same fate.

Read More
Silk Typhoon Supply Chain Attack: How Crap MSPs Sell You Out for £20 a Month
Noel Bradford Noel Bradford

Silk Typhoon Supply Chain Attack: How Crap MSPs Sell You Out for £20 a Month

If your MSP isn’t certified to Cyber Essentials Plus (CE+) and charges less than £60 per user per month (excluding productivity licensing), you’re not getting a bargain — you’re buying a front-row seat to the next supply chain breach. China-backed hackers, Silk Typhoon, are targeting crap MSPs who cut corners on security, using their remote management tools to compromise every customer they support.

This isn’t theory — it’s happening right now, and businesses who blindly trust their providers without checking certification, audit history, or internal security are sitting ducks. Find out how cheap MSPs are fuelling the next wave of cyber attacks, and why CE+ should be your absolute minimum requirement for any provider touching your network.

Read More
Jaguar Land Rover Cyber Breach: Hackers Drive Off with Luxury Brand's Secrets!
Noel Bradford Noel Bradford

Jaguar Land Rover Cyber Breach: Hackers Drive Off with Luxury Brand's Secrets!

Jaguar Land Rover—known for luxury, performance, and now, apparently, spectacular cybersecurity fails—has become the latest high-profile victim of a cyberattack. Hackers allegedly snatched critical internal documents, sensitive employee data, and the company's precious source code, then dumped it all online like yesterday's leftovers. As connected cars transform into rolling computers, cybercriminals are clearly buckling up for joyrides through corporate data. Is your business ready, or are you just waiting your turn to become tomorrow’s headline? Time to shift gears and get serious about cybersecurity—before it's too late.

Read More
Eleven11 Botnet: The Newborn Monster That Can DDoS You Into Next Week
Noel Bradford Noel Bradford

Eleven11 Botnet: The Newborn Monster That Can DDoS You Into Next Week

Meet Eleven11, the brand-new botnet responsible for record-shattering DDoS attacks peaking at 3.6 Tbps. This fast-growing menace, built from 30,000 compromised devices, can cripple networks, wipe out online businesses, and expose weak cybersecurity in minutes. Find out how it works, why it’s terrifying, and what every business should do right now to avoid becoming the next victim.

Read More
Leuma Stellar: The Malware That Wants Your Crypto and Thinks You’re Dumb Enough to Hand It Over
Noel Bradford Noel Bradford

Leuma Stellar: The Malware That Wants Your Crypto and Thinks You’re Dumb Enough to Hand It Over

Hackers are using fake PDFs disguised as bot detection images to deliver Leuma Stellar, malware designed to steal cryptocurrency wallets, logins, and browser data. Find out how this ridiculously simple scam works, why businesses and crypto holders should care, and how to lock down your assets before your Bitcoin buys someone else’s Lamborghini.

Read More
Rayhunter – The Free Tool That Lets You Spot Stingrays Before They Hoover Up Your Life
Noel Bradford Noel Bradford

Rayhunter – The Free Tool That Lets You Spot Stingrays Before They Hoover Up Your Life

Stingrays are tracking devices disguised as phone towers, used to spy on your location, calls, and messages. The EFF’s free open-source tool Rayhunter lets you detect these covert surveillance devices — putting control of your privacy back in your hands. Find out how Stingrays work, why Rayhunter matters, and why your phone is probably betraying you right now.

Read More
Microsoft Signed a Shit Driver, Now Hackers Have the Keys to Your Entire F’ing Network
Noel Bradford Noel Bradford

Microsoft Signed a Shit Driver, Now Hackers Have the Keys to Your Entire F’ing Network

Microsoft signed a vulnerable driver, and ransomware gangs couldn’t believe their fucking luck. With SYSTEM access gifted on a plate, malware could disable your antivirus, wipe your backups, and redecorate your operating system. This is what happens when you trust Microsoft to check their own homework. Learn how it happened, why BYOVD is back, and what you need to do before your network becomes the next crime scene.

Read More
Artificial Intelligence in Cybersecurity: The Digital Arms Race No One Asked For
Noel Bradford Noel Bradford

Artificial Intelligence in Cybersecurity: The Digital Arms Race No One Asked For

Cybersecurity has become an AI-driven arms race. Attackers now use AI to automate phishing, bypass security, and mimic human behavior to slip past defences. Meanwhile, AI-powered security tools fight back, detecting threats in real-time.

But most businesses are unprepared. If your security relies on outdated defences, you’re already losing. AI isn’t just changing cybersecurity—it’s redefining it.

The only way to stay ahead? Cyber Essentials Plus as your baseline. Anything less, and you’re gambling while cybercriminals use AI to exploit weaknesses.

Read More
Cyber Essentials: Does It Work and Is It Worth the Effort for Small Businesses?
Noel Bradford Noel Bradford

Cyber Essentials: Does It Work and Is It Worth the Effort for Small Businesses?

Cyber Essentials is a government-backed certification that helps small businesses get basic cybersecurity right. But does it actually work, and is it worth the time and money? In this article, we look at what Cyber Essentials involves, how much it costs, and whether it genuinely protects your business from cyber threats. With fresh insights from the UK government’s 2024 evaluation, we uncover the real-world benefits for small businesses.

Read More
Why Small Businesses Are a Hacker’s Favourite Snack (And How Not to Be One)
Noel Bradford Noel Bradford

Why Small Businesses Are a Hacker’s Favourite Snack (And How Not to Be One)

Small businesses love to think they’re “too small” for hackers to bother with. Reality check: that’s exactly why cybercriminals love you. No security team. No proper defences. Just an unlocked digital front door and a password that might as well be ‘password123’. If you’re not taking cybersecurity seriously, you’re practically begging to be hacked.

In this post, we break down why small businesses are an easy target, the biggest security mistakes they make, and how Cyber Essentials can stop your business from becoming a cybercriminal’s next easy payday. Spoiler: it’s easier (and cheaper) than you think.

Read More
Teams & Quick Assist: Microsoft’s New Gift to Cybercriminals Everywhere
Noel Bradford Noel Bradford

Teams & Quick Assist: Microsoft’s New Gift to Cybercriminals Everywhere

In one of the most embarrassing cyber trends of 2025, hackers are using Microsoft Teams to impersonate IT support, then tricking employees into launching Windows Quick Assist, effectively handing remote control of their computers to criminals. Once inside, attackers install malware, steal credentials, and deploy persistent backdoors — all thanks to tools Microsoft built and businesses blindly trust. If your staff still believe every Teams message with ‘IT’ in the name is legitimate, congratulations — you’re already a statistic. Learn how this absurdly preventable scam works and what you need to do right fucking now to avoid becoming the next case study in cybersecurity failure.

Read More
Top Cyber Security Certifications in 2025: Boost Your Career and Your Sanity
Noel Bradford Noel Bradford

Top Cyber Security Certifications in 2025: Boost Your Career and Your Sanity

In the chaotic world of cyber security certifications, 2025 offers more choices than ever; but not all of them are worth your time (or sanity). From the gold-standard CISSP to the controversial CompTIA Security+, this guide cuts through the marketing fluff to reveal which certifications actually boost your career and which ones just boost someone’s profit margins. Whether you’re aiming to become a penetration tester, security manager, or cloud security expert, this brutally honest review will help you pick wisely — and avoid the snake oil.

Read More

⚠️ Full Disclaimer

This is my personal blog. The views, opinions, and content shared here are mine and mine alone. They do not reflect or represent the views, beliefs, or policies of:

  • My employer

  • Any current or past clients, suppliers, or partners

  • Any other organisation I’m affiliated with in any capacity

Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.

Where I mention products, services, or companies, that’s based purely on my own experience and opinions — I’m not being paid to promote anything. If that ever changes, I’ll make it clear.

In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.