The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy
42 episodes
1 day ago
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
All content for The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups is the property of The Small Business Cyber Security Guy and is served directly from their servers
with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
Ignored Audits, Ancient Servers, and a Cherry Picker — Inside the Louvre Jewel Robbery
The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
11 minutes
1 day ago
Ignored Audits, Ancient Servers, and a Cherry Picker — Inside the Louvre Jewel Robbery
On October 19th, 2025, four men dressed as construction workers stole €102 million in French crown jewels from the Louvre Museum in just seven minutes. The heist was poorly executed—thieves dropped items and failed to target the most valuable pieces—yet they succeeded spectacularly.
Why? Because the world's most visited museum had been ignoring basic cybersecurity warnings for over a decade.
In this hot take, Noel Bradford examines the shocking details that emerged after the heist: the password to the Louvre's video surveillance system was "LOUVRE." Security software was protected by "THALES" (the vendor's name). Windows 2000 and Server 2003 systems were still in operation years after support ended. And a 2015 security audit with 40 pages of recommendations won't be fully implemented until 2032.
This episode examines the consequences of institutions ignoring expert warnings, the importance of accountability, and what UK small businesses can learn from a €102 million failure. Spoiler: if your security is better than the Louvre's, you're doing something right.
Key Message: Security failures often begin long before the day of the breach. They start years earlier when warnings go unaddressed.
Key Takeaways
The Louvre's password was "LOUVRE." If one of the world's most prestigious institutions used the building's name as its surveillance system password, your organisation probably has similar problems.
Ten years of warnings, zero action - ANSSI identified critical vulnerabilities in 2014. Security upgrades recommended in 2015 won't be completed until 2032. Ignoring expert advice is organisational negligence.
Resources aren't the problem - The Louvre had budget, expertise, and free government audits. They chose to prioritise palace restoration (€60M) over security infrastructure. It's about priorities, not resources.
Hardware authentication solves password problems - FIDO2 security keys can't be guessed, phished, or compromised through weak passwords. At £30-50 per key, they're cheaper than one day of operational disruption.
The accountability gap enables negligence - Government institutions face no consequences for catastrophic security failures, while UK SMBs receive ICO fines and potential closure for less. This double standard undermines security culture.
Your security might be better than that of the Louvre. If you've enabled MFA, run supported operating systems, and have basic password policies, you're already ahead of a museum protecting the Mona Lisa. That's encouraging and concerning.
Security failures often begin years before a breach - The October 2025 heist was made possible by decisions (or non-decisions) that stretched back to 2014. Prevention requires consistent action, not crisis response.
Case Studies Referenced
The Louvre Heist (October 2025)
Incident: €102 million in French crown jewels stolen in 7 minutes
Root causes: Password "LOUVRE" for surveillance, outdated systems (Windows 2000/Server 2003), unmonitored access points
Audit history: 2014 ANSSI audit identified vulnerabilities, 2015 audit provided 40-page recommendations
Accountability: Director retained position, no terminations, Culture Minister initially denied security failure
Timeline: Security upgrades recommended in 2015 won't complete until 2032
KNP Logistics (Referenced)
Industry: East Yorkshire haulage firm
Incident: Ransomware attack, £850,000 ransom demand
Outcome: Couldn't pay, business entered administration, 70 jobs lost
Contrast: Small business faces closure; national institution faces no consequences
Electoral Commission (Referenced)
Incident: Data breach affecting 40 million UK voters
Outcome: No job losses, no significant consequences
Relevance: Government accountability gap vs private sector enforcement
Case Studies Referenced
The Louvre Heist (October 2025)
Incident: €102 million in French crown jewels stolen in 7 minutes
Root causes: Password "LOUVRE" for surveillance, outdated systems (Windows 2000
The Small Business Cyber Security Guy | UK Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.