The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy
46 episodes
16 hours ago
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
All content for The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups is the property of The Small Business Cyber Security Guy and is served directly from their servers
with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.
When Ransomware Kills: Should Directors Face Prison for Cyber Negligence?
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
42 minutes
16 hours ago
When Ransomware Kills: Should Directors Face Prison for Cyber Negligence?
What happens when business negligence causes serious harm to thousands of people? If a faulty ladder injures someone, directors face prison time. If forty million people have their data stolen due to poor security, they receive a strongly worded letter.
In this provocative first episode of our two-part series, Noel and Mauven examine the shocking disparity between health and safety enforcement and cybersecurity regulation in the UK. We compare the HSE's tough approach (prison sentences, director liability, millions in fines) with the ICO's gentle touch (guidance, occasional fines, zero criminal consequences).
With 40 million voter records compromised at the Electoral Commission resulting in just a formal reprimand, whilst construction directors regularly face 18-month prison sentences for single workplace accidents, we ask the uncomfortable question: why is cybersecurity enforcement essentially performative?
This isn't anti-business rhetoric. This is an evidence-based examination of a broken system that fails to protect either businesses or the public, presented through statistics, case studies, and historical precedent, which demonstrates that personal accountability is effective.
What You'll Learn
The Two Regulators: A Tale of Vastly Different Consequences
Why HSE directors face up to 2 years imprisonment, whilst the ICO never imposes criminal penalties
How HSE issued 13,424 enforcement notices and 399 prosecutions in 2023-24
Why the ICO issued just £2.7 million in total UK fines, whilst EU regulators issued over £1 billion
The legal frameworks that create this enforcement gap
The Public-Private Accountability Divide
Electoral Commission breach: 40 million records compromised, 14 months of hostile state access, consequence: formal reprimand
Construction site failures: single injuries lead to prison sentences and director disqualifications
Why do government organisations face minimal consequences for security failures
The message this sends about who matters and who doesn't
Historical Context: How HSE Transformed Workplace Safety
85% reduction in workplace fatalities since the Health and Safety at Work Act 1974
How personal criminal liability changed director behaviour overnight
The construction industry transformation from dangerous to safety-conscious
Evidence that accountability actually works when properly enforced
Arguments Against Director Liability (And Why They Fail)
"Security is too complex for criminal standards" - why doesn't this hold up
"Small businesses can't afford proper security" - HSE already handles proportionate enforcement
"Innovation will suffer" - data showing the opposite effect in the safety sector
"Current system works fine" - statistics proving it demonstrably doesn't
The Current State of Inertia
Why ICO enforcement focuses on "guidance and support" over punishment
Political pressure keeps cybersecurity consequences minimal
Business lobby resistance to accountability measures
The broken incentive structure that rewards negligence
Key Statistics Referenced
HSE Enforcement 2023-24:
13,424 enforcement notices issued
399 prosecutions brought
£73.8 million in fines
Regular prison sentences (average 12-18 months for serious breaches)
ICO Enforcement 2023-24:
£2.7 million total fines across all UK GDPR violations
Zero prison sentences imposed
Zero director disqualifications
Focus on "guidance and support" over punishment
Electoral Commission Breach:
40 million UK voter records compromised
The hostile state actor maintained access for 14 months
Basic security failures: poor patching, weak passwords, inadequate monitoring
Consequence: Formal reprimand only
Impact Statistics:
85% reduction in workplace fatalities since the Health and Safety at Work Act 1974
EU regulators issued over £1 billion in GDPR fines (vs the UK's £2.7 million)
Keymark Construction director: 18 months' prison for fatal fall (2023)
Notable Cases Discussed
Health and Safety Enforcement
Keymark C
The Small Business Cyber Security Guy | Cybersecurity for SMB & Startups
The Small Business Cyber Security Guy Podcast
Practical cybersecurity advice for UK small business owners who need enterprise-level protection without enterprise-level budgets, headaches, or PhD-level jargon.
Join hosts Noel Bradford and Mauven MacLeod as they translate complex cybersecurity threats into actionable solutions that actually work for businesses with 5-50 employees. Noel brings 40+ years of enterprise experience from Intel, Disney, and the BBC, whilst Mauven adds government-level threat intelligence from her time as a UK Government Cyber Analyst. Together, they bridge the gap between knowing you need better security and actually implementing it without breaking the bank.
Why This Podcast Works:
Real experts who’ve chosen to focus on underserved small businesses
Practical advice tested in actual SMB environments
British humour that makes serious topics engaging (not intimidating)
Budget-conscious solutions that acknowledge your real constraints
Perfect For:
Business owners who believe they’re ”too small to be targeted”
Anyone who needs cybersecurity knowledge but lacks time for complex solutions
Those seeking enterprise-quality protection at corner shop prices
UK businesses (though principles apply globally)
Each episode delivers concrete, actionable advice you can implement immediately. No theoretical discussions, no vendor nonsense, no academic waffle. Just two experts who genuinely care about helping small businesses survive and thrive digitally.
Regular Features:
Current threat analysis with real-world context
Implementation guides within realistic budgets
Human factor solutions (because your biggest vulnerability makes excellent tea)
Government framework explanations that actually make sense
New episodes weekly. Subscribe now and join thousands of business owners who’ve discovered that proper cybersecurity isn’t just for Fortune 500 companies.
Like what you hear? Subscribe, leave a review mentioning your biggest cybersecurity concern, and visit our blog for detailed implementation guides on everything we discuss.
Stay secure, stay practical, and remember - if your security wouldn’t survive a curious teenager with too much time, it needs work.