『Hot Takes from the Small Business Cyber Security Guy』のカバーアート

Hot Takes from the Small Business Cyber Security Guy

Hot Takes from the Small Business Cyber Security Guy

著者: The Small Business Cyber Security Guy
無料で聴く

Hot Takes

Hot Takes is the sharp, fast moving opinion show from The Small Business Cyber Security Guy team.

This is where we cut through the noise, the vendor nonsense, the breathless headlines, and the cyber doom theatre that small businesses get served far too often. Each episode takes one current cyber security story, claim, breach, statistic, policy change, or industry talking point and asks the question that actually matters:

What does this mean for a real small business?

Expect blunt analysis, practical advice, and a healthy suspicion of anyone trying to sell fear in a shiny PDF.

We cover topics including cyber attacks, data breaches, ransomware, supply chain risk, Microsoft 365 security, compliance, Cyber Essentials, bad MSP behaviour, weak governance, and the many creative ways organisations manage to trip over their own shoelaces.

No hoodies.
No Matrix code.
No corporate fog machine.

Just straight talk, useful context, and clear takeaways for business owners, directors, IT teams, and anyone else trying to keep the lights on without becoming a full time cyber security analyst.

Bold opinions. Practical advice. Made for small businesses.

マネジメント マネジメント・リーダーシップ 経済学
エピソード
  • When Office Printers Join Organised Crime
    2026/07/27
    When Office Printers Join Organised Crime

    Imagine walking into your office to find all systems locked and the printer spewing ransom notes. This episode of SBCSG Hot Take, hosted by Noel Bradford, explores two significant security breaches. The first organisation made classic mistakes: exposed Remote Desktop and disabled endpoint protection. Attackers used BitLocker to encrypt data, demonstrating how tools meant for protection can be turned against the business. The second business fared worse, misconfiguring an SQL server and leaving credentials exposed, allowing intruders to linger for months. Noel emphasises the importance of response over mere alerts and how organisational oversight often contributes more to breaches than sophisticated hacking tools.

    Chapters
    • Cold Open A dramatic opening describes ransomware printed from office printers.
    • They Did Not Hack the Printer First Kaspersky’s investigation reveals exposed Remote Desktop led to the breach.
    • The Protection Had Been Disabled Endpoint protection was disabled due to ‘compatibility issues’, leading to a breach.
    • The Second Business Somehow Did Worse A misconfigured SQL server with public credentials allowed attackers entry.
    • The Alerts Worked Security alerts were raised but ignored, demonstrating response gaps.
    • The Attackers Used Proper IT Tools Attackers used legitimate IT tools instead of custom weapons.
    • Then They Destroyed the Evidence In incident response haste, evidence was destroyed, complicating investigations.
    • The Ransom Was Almost Sensible A modest ransom demand hinted at a pragmatic cybercrime model.
    • The Printer Is Still Guilty Printers, as networked devices, remain security risks despite appearing benign.
    • The Hot Take The breaches highlight organisational security failings, not hacker genius.
    • Close The episode concludes with irony as the printer finally functions faultlessly.
    Links
    • https://www.kaspersky.com
    Links
    • https://www.expressvpn.com/blog/
    • https://techcrunch.com/
    • https://cybernews.com/
    • https://www.scmagazine.com/
    • https://www.bitdefender.com/
    • https://www.securitymagazine.com/
    • https://www.wired.com/
    • https://vpnmentor.com/
    続きを読む 一部表示
    18 分
  • FortiBleed, Fortinet, and the Firewall That Became the Failure
    2026/07/10
    FortiBleed, Fortinet, and the Firewall That Became the Failure Noel Bradford unleashes a withering critique of Fortinet following the FortiBleed vulnerability’s impact on British embassies, the Foreign Office, and the British Council. This is not a balanced analysis; it is a controlled explosion aimed at a vendor that keeps appearing in credential exposure stories despite its market dominance and recurring revenue model. Bradford demands answers: why does one of the world’s largest security companies repeatedly feature in edge device exploitation headlines? Why are customers paying annual licences for products that become the risk conversation? And why, in an era when frontier AI models like Anthropic’s Claude Mythos Preview are being deployed to hunt vulnerabilities in critical software, are we still watching firewalls, the devices sold as the safe bit, turn into national security incidents? He dismantles the familiar cycle of advisory, exploitation, and carefully worded apology, and asks whether recurring revenue comes with recurring responsibility or just recurring anxiety. Public bodies, MSPs, and the industry’s talent for turning failure into beige process language all come under fire. This is a rant, a reckoning, and a refusal to pretend this is fine. Chapters Cold Open Noel opens with cold fury, warning listeners this is a rant. FortiBleed has hit British embassies, the Foreign Office, and the British Council. He refuses to deliver the vendor-friendly version or pretend the complexity excuses the pattern. Fortinet’s ubiquity in critical infrastructure makes its repeated appearance in exploitation headlines unforgivable.The Safe Bit The firewall was sold as the safe bit, the thing with the green dashboard and the procurement-friendly quote. It turns out it was just another internet-exposed computer holding keys and terminating VPN sessions. Noel is tired of the cycle: advisory, exploitation, emergency guidance, carefully worded statement, patch advice, shuffle on.The Fortinet Question The question is not just whether customers patched. Fortinet sells security and confidence. Why does one of the largest security vendors on the planet keep ending up in headlines around exploited edge devices, credential exposure, and large scale customer panic? This is a reputational and governance problem.The Price Of Being Big All vendors have vulnerabilities, but frequency, pattern, and blast radius matter. If your kit is everywhere, your mistakes are everywhere. You do not get giant market share and giant recurring revenue, then act wounded when people expect giant levels of assurance. You wanted the market; now carry the weight.Hard Coded Credentials Noel drags the hard coded credentials issue back into the room, referencing Fortinet’s PSIRT entry for dummy testing data in FortiManager and FortiAnalyzer. Hard coded credentials in security software is a phrase that should make eyebrows leave faces. The optics are appalling when your commercial promise is trust.Mythos And Glasswing Anthropic has deployed Claude Mythos Preview, a frontier AI model, to find and fix vulnerabilities in critical software as part of Project Glasswing. Firewalls are critical software. Noel demands to know whether Fortinet has access to Mythos or an equivalent, because edge security appliances should be attacked internally before criminals get the pleasure.The Licence Model Fortinet’s business model is wrapped in recurring licences. Customers pay annually because threats move daily. But recurring revenue must come with recurring responsibility. If you charge every year, your product security has to move every day. Otherwise, what are customers renewing: protection, or access to the next apology?Subscription To Anxiety Customers were sold maturity, scale, and expertise. FortiBleed makes it feel upside down. The firewall became the risk conversation. The security vendor became the source of anxiety. The recurring licence starts to look like a subscription to anxiety with rack ears.Public Sector Trust British embassies, the British Council, and Foreign Office credentials are reportedly in the mix. People give data to public bodies because they have to. They do not get to inspect the firewall first. They just get the email afterwards, the one about an abundance of caution. Caution is never abundant before the breach.MSPs Do Not Get To Hide If you sold this kit, you own the conversation. If you manage it, you produce evidence. Vanishing behind a ticket note saying awaiting customer instruction is cowardice with a service desk reference. The edge is where the attack starts. If your definition of managed is occasionally aware, stop using the word managed.Why I Am Angry Noel is angry because the same story keeps coming back. A company with Fortinet’s scale should be held to a brutal standard. Customers pay recurring money for security and still wonder whether the security product is the problem. Hard coded credentials should ...
    続きを読む 一部表示
    13 分
  • Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week)
    2026/07/03
    Why Small Businesses Keep Failing ICO Audits (And How to Fix It This Week)

    The Information Commissioner’s Office isn’t hunting your business, but that doesn’t stop small organisations from making the same three avoidable mistakes. Host Noel Bradford examines twelve recent ICO enforcement notices to identify the most common failures: no documented breach response process, insufficient staff training on what constitutes personal data, and no record of processing activities. These aren’t exotic compliance gaps requiring expensive consultants or new platforms. They’re basic governance failures that can be fixed with a one-page process document, practical staff training, and a simple spreadsheet. The real exposure isn’t regulatory enforcement, it’s the internal fog that leaves staff unable to recognise or report incidents, managers unclear on ownership, and directors unable to explain what data the business holds. This episode cuts through vendor fear-mongering and compliance theatre to deliver three practical actions any small business can implement immediately, with no budget required.

    Chapters
    • Cold Open The ICO is not actively hunting small businesses, which makes the persistent compliance failures all the more frustrating.
    • Intro Analysis of twelve recent ICO enforcement notices reveals three recurring, avoidable failures that don’t require consultants or expensive tools to fix.
    • Failure One: No Documented Breach Response Process Organisations freeze when incidents occur because nobody knows who to call, what to document, or when the clock starts. The real damage begins with the paralysis, not the breach itself.
    • Failure Two: No Staff Training on Personal Data Employees cannot recognise breaches if they don’t understand that personal data includes names, addresses, payroll information, and customer records, not just obviously sensitive material.
    • Failure Three: No Record of Processing Activities Businesses cannot answer basic questions about what personal data they hold, why they hold it, where it lives, or how long they keep it. This isn’t bureaucracy, it’s stock control for trust.
    • The Vendor Problem None of these three failures required vendor solutions to prevent. Fear-based marketing keeps small businesses terrified rather than informed, selling tools instead of addressing governance gaps.
    • The Real Exposure The true risk isn’t ICO enforcement but internal fog: staff who don’t know what to report, managers unclear on ownership, and directors unable to explain data holdings when complaints arrive.
    • What to Do This Week Three practical actions requiring no budget: write a one-page breach response process, train staff with real examples from your business, and build a basic record of processing activities.
    • The Team Meeting Test Ask your team three questions: who would you tell if you sent personal data to the wrong person, what would you document, and where is our list of personal data holdings. Silence reveals your incident.
    • Close Read three public ICO notices before your next management meeting to understand what small organisations keep getting wrong and why the fixes are boring, free, and available immediately.
    Links
    • https://ico.org.uk/for-organisations/report-a-breach/
    • https://ico.org.uk/for-organisations/accountability-framework/records-of-processing/
    • https://ico.org.uk/action-weve-taken/enforcement/
    Links
    • https://www.expressvpn.com/blog/
    • https://techcrunch.com/
    • https://cybernews.com/
    • https://www.scmagazine.com/
    • https://www.bitdefender.com/
    • https://www.securitymagazine.com/
    • https://www.wired.com/
    • https://vpnmentor.com/
    続きを読む 一部表示
    10 分
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません