The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy
42 episodes
1 day ago
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
All content for The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups is the property of The Small Business Cyber Security Guy and is served directly from their servers
with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
Discord's Data Breach and the UK's Digital ID Debacle
The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
11 minutes
3 weeks ago
Discord's Data Breach and the UK's Digital ID Debacle
Noel and Mauven unpack Discord’s third-party breach that exposed government-ID checks from age-appeal cases, then weigh it against Westminster’s push for a nationwide digital ID. It’s a frank look at how outsourcing, age-verification mandates and data-hungry processes collide with real-world security on the ground. Expect straight talk and practical fixes for UK SMBs.
What we cover
What actually happened at Discord: a contractor compromise affecting support/Trust & Safety workflows, not Discord’s core systems; notifications issued; vendor relationship severed; law-enforcement engaged.
Why age-verification data is dynamite: passports and licences used for “prove your age” are a high-value, high-liability dataset for any platform or vendor.
The UK digital ID plan, clarified: free digital ID, phased rollout this Parliament, and mandatory for Right to Work checks rather than everyone by default. What that means for employers, suppliers and software choices.
Public sentiment vs promised safety: Britons broadly back “age checks” in principle but expect more data compromise and censorship risk, and doubt effectiveness.
Why it matters to UK SMBs
You can’t outsource accountability. If a payroll, KYC, helpdesk or verification vendor mishandles data, your customers still see your name on the breach notice.
Age and identity checks creep into ordinary business flows. HR onboarding, ticketing, and customer support can accumulate sensitive documents if you let them.
Centralising identity increases the jackpot for attackers. Your job is to minimise what you collect and partition what you must keep.
Key takeaways
Do not collect what you can’t protect. Prefer attribute proofs over document uploads.
Limit blast radius. Separate systems, short retention, hard deletion, and vendor access that is time-boxed and device-checked.
Contract like you mean it. Specify MFA, device compliance, immutable logging, breach SLAs, and verifiable deletion in vendor agreements.
Prepare your Right-to-Work path now. Choose flows that avoid copying and storing underlying documents.
Action checklist for SMB owners
Map every place you’re collecting ID or age proof today. Kill non-essential collection.
Where age is required, adopt attribute-based verification that proves “over 18” without revealing full identity.
Move any remaining uploads behind automatic redaction, strict retention, and encryption with keys you control.
Enforce vendor MFA via your IdP, require compliant devices, and review access logs weekly.
Run DPIAs for onboarding, support and HR flows that touch identity documents.
Rehearse your breach comms. Aim to say: “only an age token was exposed, not source documents.”
Chapter outline
Setting the scene: a breach born in the support queue
Why ID uploads are a liability multiplier
The UK’s digital ID plan, without the spin
Vendor risk is your risk
Practical fixes you can implement before lunch
Q&A and what to do if you uploaded ID to Discord
If you think you’re affected
Treat notices as real; monitor credit; be alert to targeted phishing; don’t re-upload documents to unsolicited “verification” links.
Support the show
Subscribe, rate and review. Share this episode with a business owner who still stores passport scans in their helpdesk.
Send questions or topic requests for future episodes.
The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.