Hosted by The Small Business Cyber Security Guy
Listed under Business › Management, News › Tech News
The UK's leading small business cybersecurity podcast, helping SMEs protect against cyber threats without breaking the bank.
105 episodes · publishes weekly · latest 2026-07-27 · ~22 min/episode
Rank
#173
Substance
73.2
/ 100
Breakdown
Scored 2026-08
Updated monthly
General rank
#20 of 91
Across the index
#173 of 1056
Substance
Top 16%
outscores 84% of the index
The Small Business Cyber Security Guy ranks #173 on The B2B Podcast Index with a substance score of 73.2 out of 100, scored across 5 recent episodes. It scores highest on insight density and originality. The episode delivers consistent, substantive claims about OSINT reconnaissance that a small business operator would find genuinely useful: Companies House API rates remain practical for attackers, electoral register opt-outs don't erase historical data brokers hold, job adverts leak technology stacks, DNS records expose email providers, and the critical insight that attackers correlate multiple public sources into a unified profile. The host avoids obvious platitudes and focuses on specific, actionable threat vectors. Minor padding exists in metaphorical language and legal disclaimers, but the core content is dense with concrete intelligence.
Averaged across 5 recently scored episodes, with cited evidence.
The episode delivers consistent, substantive claims about OSINT reconnaissance that a small business operator would find genuinely useful: Companies House API rates remain practical for attackers, electoral register opt-outs don't erase historical data brokers hold, job adverts leak technology stacks, DNS records expose email providers, and the critical insight that attackers correlate multiple public sources into a unified profile. The host avoids obvious platitudes and focuses on specific, actionable threat vectors. Minor padding exists in metaphorical language and legal disclaimers, but the core content is dense with concrete intelligence.
“Before an attacker sends one phishing email, they may already know who runs your business. They may know the company structure, the directors, the registered office, the filing history, and the public contact routes.”
“Once personal data leaves the original source, it becomes digital glitter.”
The episode takes a genuinely underexplored angle - not 'hackers are bad' but 'your own government transparency infrastructure is the attacker's reconnaissance platform' - which is fresher than standard cybersecurity fare. The framing of OSINT as 'information people leak by existing' and the systematic walkthrough of how Companies House, electoral registers, LinkedIn, and DNS records form a joined attacker profile is coherent and contrarian. However, the core OSINT concept itself is not new; the originality lies in making it tangible for SMBs rather than reinventing the wheel.
“The UK has built one of the best open source intelligence databases in the world, and then called it Transparency.”
“Transparency without threat modeling becomes a weaponized phone book.”
Noel Bradford is the primary voice and appears to be a practitioner in UK cybersecurity with hands-on experience advising SMBs, evidenced by his familiarity with specific regulatory frameworks (Companies House, electoral register opt-out mechanics) and his ability to construct realistic attack narratives. However, the transcript provides limited evidence of large-scale operational experience or notable institutional credentials. Corrine Jefferson is introduced but barely speaks (one short hypothetical response about a 20-minute profile build). The episode lacks a second high-caliber guest with contrasting perspective or greater seniority, limiting guest caliber to solid practitioner level rather than standout.
“I'm Noel Bradford, and this is the first episode in a five-part series called The Open Book Problem.”
“A recently appointed director may be a better impersonation target. A newly changed registered office may suggest transition. A late filing may suggest pressure or poor administration.”
The episode anchors claims in named systems (Companies House, electoral register, LinkedIn, Sage, Microsoft 365, Fortinet, Datto, Mimecast, etc.) and specific data points (600 API request limit per five minutes, MX records, SPF/DKIM/DMARC). It references realistic scenarios: a finance assistant posting about payroll, a recruiter listing specific tech stacks, abandoned VPN gateways. The five-step mitigation is concrete. However, the episode lacks dollar figures, specific attack success rates, or real-world case studies with names/outcomes. The depth is sufficient for threat modeling but not maximally granular.
“The register is free to search. It exposes structured information. It also offers an API with a published limit of 600 requests within five minutes.”
“A recruiter advertising for an IT administrator with Microsoft 365, Fortinet, Datto, Sage, and SharePoint experience tells an attacker something.”
Noel Bradford's delivery is clear and engaging, with strong narrative pacing that walks listeners through an attacker's reconnaissance flow. He employs productive metaphors ('digital glitter,' 'weaponized phone book') and self-aware humor ('I bought fingerless gloves specially'). However, conversational craft is limited by structure: this is largely a monologue with Corrine contributing one substantive response. There are no real follow-ups, disagreements, or challenging questions pushed back on. The host doesn't invite pushback on his transparency critique or stress-test his own arguments. The legal disclaimer section is extensive but somewhat disconnects from the main narrative flow.
“That's why we drink tea like it's an incident response tool.”
“Social engineering isn't magic. It's admin with malice. That may be the cleanest definition we've had. No fluff.”
3 periods tracked.
9 scored on substance · 65 tracked in total.
The Open Book Problem 5: Closing it with Practical Defences for Small Businesses
2026-07-27 · 21 min
The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap
2026-06-29 · 20 min
The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency
2026-06-22 · 40 min
Erased from the Web: The Fight Over a Child's Moment
2026-06-15 · 27 min
Birthday Audit: Brutal Lessons for Small Business Cybersecurity
2026-06-08 · 39 min
If Your MSP Says ‘All Good’, Can They Prove It?
2026-06-01 · 36 min
Pop-Ups, Upsells & Risk: Taming the Noisy World of SaaS Admin Dashboards
2026-05-29 · 10 min
AI vs The Patch Queue: When Faster Discovery Breaks Business
2026-05-28 · 10 min
When Cybercrime Stops the Till: Why It's a Business Problem, Not IT's
2026-05-27 · 13 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-small-business-cyber-security-guy-cybersecurity-for-smb-startups" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-small-business-cyber-security-guy-cybersecurity-for-smb-startups/badge.svg" alt="Ranked #20 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Small Business Cyber Security Guy's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
Companies, products and tools that come up most across this show's episodes.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.