<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Graham Falkner — The Small Business Cybersecurity Guy</title><description>Every article by Graham Falkner. Straight-talking cybersecurity advice for UK small businesses.</description><link>https://thesmallbusinesscybersecurityguy.co.uk/</link><language>en-gb</language><item><title>How to Write Your One-Page Governance Sheet This Afternoon</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/one-page-governance-sheet-howto-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/one-page-governance-sheet-howto-uk-smb-2026/</guid><description>Four headings, forty-five minutes, one sheet of paper. Here&apos;s exactly how to build it.</description><pubDate>Thu, 06 Aug 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>executive-security</category><category>business-risk</category><category>compliance-failure</category><author>Graham Falkner</author></item><item><title>The Two-Hour Test: What to Check Before Paying for Data Removal</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/two-hour-test-data-removal-service-uk-directors-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/two-hour-test-data-removal-service-uk-directors-2026/</guid><description>Before paying for a data removal subscription, two hours of free work tells you exactly whether it will solve your actual problem. Here is the full process.</description><pubDate>Thu, 23 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>vendor-risk</category><category>business-risk</category><category>executive-security</category><category>compliance-failure</category><author>Graham Falkner</author></item><item><title>The Privacy Dashboard That Made You Feel Safe While Your Home Address Stayed Online</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/data-removal-service-false-confidence-risk-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/data-removal-service-false-confidence-risk-uk-2026/</guid><description>A removal service dashboard showing successful removals can mask the fact that your most important exposures were never in scope. Here is how to spot the gap.</description><pubDate>Wed, 22 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>vendor-risk</category><category>business-risk</category><category>compliance-failure</category><category>executive-security</category><author>Graham Falkner</author></item><item><title>DeleteMe and Incogni: Are Data Removal Services Worth It for UK Users?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/deleteme-incogni-uk-review-worth-it-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/deleteme-incogni-uk-review-worth-it-2026/</guid><description>DeleteMe and Incogni are not scams. But UK users pay monthly for rights they own free, against a broker list built for the wrong country.</description><pubDate>Mon, 20 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>compliance-failure</category><category>executive-security</category><category>business-risk</category><category>vendor-risk</category><author>Graham Falkner</author></item><item><title>How to Submit a UK GDPR Erasure Request to a Data Broker That Actually Works</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-gdpr-erasure-request-data-broker-guide-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-gdpr-erasure-request-data-broker-guide-2026/</guid><description>Most UK GDPR erasure requests to data brokers fail because they are vague, undocumented, or not followed up. Here is the process that produces results.</description><pubDate>Thu, 16 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>compliance-failure</category><category>executive-security</category><category>business-risk</category><category>incident-response</category><author>Graham Falkner</author></item><item><title>How to Audit Your Own OSINT Exposure: A Step-by-Step Guide for UK Directors</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/osint-exposure-audit-uk-director-guide-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/osint-exposure-audit-uk-director-guide-2026/</guid><description>A practical sequenced guide to audit and reduce your public data exposure as a UK SMB director. No tools required. No budget needed. One afternoon.</description><pubDate>Fri, 10 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>executive-security</category><category>data-protection</category><category>business-risk</category><category>social-engineering</category><category>compliance-failure</category><author>Graham Falkner</author></item><item><title>Ten Questions to Ask Your IT Provider This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ten-questions-it-provider-edge-security-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ten-questions-it-provider-edge-security-uk-smb-2026/</guid><description>You do not need to understand SAML or KEV. You need to ask grown-up questions and expect plain-English answers. Here are ten of them.</description><pubDate>Thu, 25 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>incident-response</category><category>business-risk</category><author>Graham Falkner</author></item><item><title>Set Up Security Logging for Your Small Business in 60 Minutes: A Step-by-Step Guide</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/security-logging-setup-guide-smb-60-minutes-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/security-logging-setup-guide-smb-60-minutes-2026/</guid><description>Fifteen minutes for Microsoft 365. Fifteen for your firewall. Thirty for a weekly review process. Here is the practical logging guide your IT provider should have given you.</description><pubDate>Thu, 28 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>cloud-security</category><category>remote-access</category><category>business-risk</category><author>Graham Falkner</author></item><item><title>How To Roll Out TPM Plus PIN BitLocker On A Windows 11 Fleet</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/tpm-plus-pin-bitlocker-deployment-windows-11-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/tpm-plus-pin-bitlocker-deployment-windows-11-uk-2026/</guid><description>TPM plus PIN BitLocker is one Group Policy change, one command per device, and a Tuesday of user communication. The whole job fits in two weeks. Here is how.</description><pubDate>Thu, 21 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>compliance-failure</category><category>executive-security</category><category>business-risk</category><author>Graham Falkner</author></item><item><title>The Seven Questions to Ask Your IT Provider Before They Cost You a Breach</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/seven-questions-it-provider-audit-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/seven-questions-it-provider-audit-uk-2026/</guid><description>Seven questions. Ask them calmly, in writing, before your next contract renewal. A good provider will welcome them. A bad one will hand-wave. That is the test.</description><pubDate>Thu, 14 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>business-risk</category><category>vendor-risk</category><category>incident-response</category><author>Graham Falkner</author></item><item><title>Patch Tuesday May 2026: The Four Bugs UK SMBs Must Fix This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-may-2026-uk-smb/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-may-2026-uk-smb/</guid><description>137 patches. 30 critical. No zero-days. The four bugs UK SMBs must fix this week, plus the perfect-10 one that needs no action at all.</description><pubDate>Wed, 13 May 2026 16:25:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>compliance-failure</category><category>remote-access</category><category>vendor-risk</category><author>Graham Falkner</author></item><item><title>Five Things You Can Do This Week to Beat the UK Cyber Security Survey Average: No Budget Required</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/five-cyber-security-actions-uk-small-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/five-cyber-security-actions-uk-small-business-2026/</guid><description>53% of UK businesses have no MFA. 56% have no continuity plan. Five steps to beat the average this week. No budget. No consultants. No excuses.</description><pubDate>Thu, 07 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>incident-response</category><category>credential-theft</category><category>supply-chain-risk</category><author>Graham Falkner</author></item><item><title>Cyber Essentials Before Summer: The Step-by-Step Guide to Getting Certified Before the Pledge Arrives</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-certification-guide-before-pledge-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-certification-guide-before-pledge-2026/</guid><description>The Pledge launches this summer. Certification takes four to six weeks. Here is the exact process, with costs, timelines, and the steps your IT provider should handle.</description><pubDate>Thu, 30 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>compliance-failure</category><category>supply-chain-risk</category><category>business-risk</category><category>executive-security</category><author>Graham Falkner</author></item><item><title>The Five Step DNS Troubleshooting Guide Your Small Business Actually Needs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/dns-troubleshooting-guide-five-steps-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/dns-troubleshooting-guide-five-steps-uk-smb-2026/</guid><description>Website not loading? Before you blame DNS, follow these five steps. A practical guide that saves hours of wasted time.</description><pubDate>Thu, 23 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>remote-access</category><category>incident-response</category><category>vendor-risk</category><category>compliance-failure</category><author>Graham Falkner</author></item><item><title>April 2026 Patch Tuesday: 167 CVEs, Two Zero-Days, and a Deadline You Cannot Afford to Miss</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-april-2026-sharepoint-zero-day-uk-smb/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-april-2026-sharepoint-zero-day-uk-smb/</guid><description>167 CVEs. Two zero-days. One SharePoint flaw needs no password to exploit. April 2026 Patch Tuesday demands your attention today, not next week.</description><pubDate>Wed, 15 Apr 2026 09:48:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><category>remote-access</category><category>compliance-failure</category><author>Graham Falkner</author></item><item><title>Six Controls That Stand Between You and a Denied Cyber Claim</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-controls-uk-smb-checklist-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-controls-uk-smb-checklist-2026/</guid><description>UK insurers check six specific technical controls after a breach. If they&apos;re not in place and documented, your claim is at risk. Here&apos;s the practical checklist for UK SMBs.</description><pubDate>Thu, 09 Apr 2026 05:00:00 GMT</pubDate><category>cyber-insurance</category><category>mfa-failure</category><category>smb-security</category><category>uk-business</category><category>backup-security</category><category>patch-management</category><category>incident-response</category><author>Graham Falkner</author></item><item><title>Red Canary&apos;s March 2026 Threat Report: What UK Small Businesses Need to Do This Week</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/red-canary-march-2026-threats-uk-smb-practical-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/red-canary-march-2026-threats-uk-smb-practical-guide/</guid><description>Paste-and-run is now the dominant attack method. Mac is not safe. Vidar is back. Red Canary&apos;s March data, translated into steps you can actually take.</description><pubDate>Wed, 08 Apr 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>credential-theft</category><category>social-engineering</category><category>remote-access</category><category>business-risk</category><category>incident-response</category><author>Graham Falkner</author></item><item><title>The Proposal Form That&apos;s Building a Landmine Under Your Business</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-proposal-form-uk-smb-truth-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-proposal-form-uk-smb-truth-2026/</guid><description>Every answer on your cyber insurance proposal form will be checked against your network logs if you ever claim. Most SMBs answer how they&apos;d like things to be, not how they actually are.</description><pubDate>Tue, 07 Apr 2026 04:00:00 GMT</pubDate><category>cyber-insurance</category><category>claims-denial</category><category>mfa-failure</category><category>uk-business</category><category>insurance-act-2015</category><category>smb-security</category><category>2026-threats</category><author>Graham Falkner</author></item><item><title>The Tech Fridge Audit: How to Do It in 30 Minutes Without Breaking Anything</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/tech-fridge-audit-guide-uk-small-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/tech-fridge-audit-guide-uk-small-business-2026/</guid><description>A 30-minute walkthrough any small business owner can do without specialist knowledge. By the end, you&apos;ll have a clear list of what&apos;s safe, risky, and what needs to go.</description><pubDate>Thu, 02 Apr 2026 04:00:00 GMT</pubDate><category>smb-security</category><category>tech-lifecycle</category><category>end-of-support</category><category>software-inventory</category><category>asset-management</category><category>uk-business</category><category>cyber-essentials</category><author>Graham Falkner</author></item><item><title>The Importance of Cybersecurity in Political Donations</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-importance-of-cybersecurity-in-political-donations/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-importance-of-cybersecurity-in-political-donations/</guid><description>Political donations need cybersecurity to prevent foreign interference. Secure your processes and build trust with these practical steps.</description><pubDate>Wed, 01 Apr 2026 16:00:00 GMT</pubDate><category>Political Donations</category><category>Cybersecurity</category><category>Compliance</category><author>Graham Falkner</author></item><item><title>How to Use SMB1001 as a Practical Roadmap (Not Just Another Badge): A Step-by-Step Guide for UK Small Businesses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/smb1001-msp-roadmap-practical-guide-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/smb1001-msp-roadmap-practical-guide-uk-2026/</guid><description>Most small businesses that call their IT company and say &quot;can you just make us secure?&quot; get back either an incomprehensible technical list or a vague proposal with no defined deliverables. What they rarely get is a structured conversation about where they actually are, where they need to be, and what that journey will cost. SMB1001&apos;s five tiers give you the framework for exactly that conversation. In this practical guide, I&apos;ll walk you through how to assess your current position honestly, choose</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>smb1001</category><category>msp-security</category><category>smb-security</category><category>uk-business</category><category>certification-framework</category><category>it-provider-accountability</category><category>cyber-essentials</category><author>Graham Falkner</author></item><item><title>From Cyber Essentials to SMB1001 — Is One Badge Ever Enough?</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-to-smb1001-one-badge-enough/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-to-smb1001-one-badge-enough/</guid><description>A week of Cyber Essentials v3.3 done. Scope reviews, cloud scoping rules, MFA for everyone, the 14-day patching window. You now know more about CE than most IT managers I&apos;ve spoken to this year. Next Monday we zoom out. SMB1001 runs from Bronze to Diamond and was built specifically for small businesses that want a structured security roadmap beyond the CE baseline. It is not a UK government scheme, it does not carry the same procurement weight, and the two frameworks do not map neatly. So the qu</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><category>smb1001</category><category>cyber-essentials</category><category>uk-smb</category><category>certification-differences</category><author>Graham Falkner</author></item><item><title>Your 30-60 Day Cyber Essentials v3.3 Readiness Plan: A Step-by-Step Guide</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-v33-readiness-plan-step-by-step-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-v33-readiness-plan-step-by-step-uk-2026/</guid><description>Right. Noel and Mauven have told you what&apos;s changing in Cyber Essentials v3.3 and why scope failures become legal problems. My job is the bit that comes after: what do you actually do, in what order, with realistic timelines? I have broken this into a 30-60 day plan that works for most UK SMBs, whether you&apos;re renewing before 26th April under Willow or preparing for Danzell afterwards. No tools to buy, no consultants to hire for the basics. Mostly time, a spreadsheet, and an honest look at what y</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate><category>cyber-essentials</category><category>cyber-essentials-v3.3</category><category>how-to</category><category>mfa</category><category>asset-management</category><category>patching</category><category>uk-sm</category><category>practical-guide</category><author>Graham Falkner</author></item><item><title>March Patch Tuesday 2026: No Zero-Days, No Excuses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/march-patch-tuesday-2026-no-zero-days-no-excuses/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/march-patch-tuesday-2026-no-zero-days-no-excuses/</guid><description>Microsoft shipped March 2026 Patch Tuesday on 10 March with no actively exploited zero-days. And I can already hear the conversation in the finance department: &quot;Quiet month, push it to next quarter.&quot; Wrong. This month&apos;s release covers six Windows elevation-of-privilege flaws that Microsoft itself rates as Exploitation More Likely, a critical Excel bug that can hijack Copilot Agent to exfiltrate data with near zero user interaction, and two Office remote code execution issues that fire through th</description><pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate><category>patch-tuesday</category><category>windows-security</category><category>microsoft-365</category><category>copilot-security</category><category>smb-security</category><category>2026-threats</category><category>uk-business</category><author>Graham Falkner</author></item><item><title>Your Four-Control Playbook: The Basic Security Measures Currys’ Was Missing (And How to Implement Them This Afternoon)</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/data-map-security-controls-uk-smb-playbook-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/data-map-security-controls-uk-smb-playbook-2026/</guid><description>Malware sat on 5,390 Currys tills for nine months. Nobody noticed. That is not a sophisticated nation-state attack. That is a basic monitoring failure. The ICO called the missing controls &quot;basic, commonplace security measures.&quot; In plain English: this was avoidable. If you run a small or medium-sized business and you process payment data, hold customer records, or manage staff information, this week&apos;s practical guide gives you four specific controls to implement. No expensive tooling. No consulta</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate><category>data-map</category><category>access-control</category><category>security-monitoring</category><category>ncsc-10-steps</category><category>uk-gdpr</category><category>smb-security</category><category>incident-detection</category><author>Graham Falkner</author></item><item><title>Your CLOUD Act Exposure Audit: The Step-by-Step Guide for UK Small Businesses</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-act-exposure-audit-guide-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-act-exposure-audit-guide-uk-smb-2026/</guid><description>Every UK business using Microsoft 365, Google Workspace, or any US cloud service has an unassessed CLOUD Act exposure. This guide gives you a step-by-step process to map it: list your vendors, identify your crown jewels, check who controls the encryption keys, fold the findings into your DPIAs, and build a realistic exit plan. No consultancy fees, no jargon, no panic. One afternoon with your IT lead and a spreadsheet. By Friday you will know exactly where your business sits and what, if anything</description><pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate><category>smb-security</category><category>us-cloud-act</category><category>uk-business</category><category>compliance-failure</category><category>data-sovereignty</category><category>2026-threats</category><author>Graham Falkner</author></item><item><title>Six Zero-Days, One Tuesday, and Your Approval Process Is Still Broken</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-february-2026-six-zero-days-uk-smb-guide-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/patch-tuesday-february-2026-six-zero-days-uk-smb-guide-2026/</guid><description>Graham here. Microsoft dropped six actively exploited zero-days on us yesterday, three of them publicly disclosed before the patch even landed. That means attackers had working exploits before you had fixes. Three bypass your security warnings entirely. One gives SYSTEM access through Remote Desktop Services. CrowdStrike confirmed active abuse in the wild. Meanwhile, SAP shipped a CVSS 9.9 code injection flaw and Adobe patched 44 vulnerabilities across nine products. If your patching approval pr</description><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate><category>patch-tuesday</category><category>zero-day-vulnerabilities</category><category>microsoft-security</category><category>uk-smb</category><category>2026-threats</category><category>windows-patching</category><category>vulnerability-management</category><author>Graham Falkner</author></item><item><title>January 2026 Patch Tuesday: New Year, New Nightmares for SMB Security</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/january-2026-patch-tuesday-nightmares-smb-security/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/january-2026-patch-tuesday-nightmares-smb-security/</guid><description>Microsoft’s January 2026 Patch Tuesday delivered 114 updates and 3 zero-days – with SharePoint Toolshell, Fortinet VPN bypass, and HPE OneView RCE leading the charge. This isn’t theoretical. Attackers are already exploiting these in the wild. From Adobe Acrobat to Apple’s WebKit spyware holes, no vendor was spared. SMB IT teams, you’re on the clock. Here’s your no-fluff, brutally honest patching guide.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate><category>monthly-patch-cycle</category><category>patch-tuesday</category><category>smb-patch-management</category><author>Graham Falkner</author></item><item><title>Your First Cyber Risk Register: 2-Hour Implementation Guide with Template</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/create-first-cyber-risk-register-2-hour-guide-template/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/create-first-cyber-risk-register-2-hour-guide-template/</guid><description>Create your first cyber risk register in 2 hours. No consultant needed. Step 1: Identify five specific risks (phishing, ransomware, insider threats are mandatory for all UK SMEs). Step 2: Assess likelihood using real government statistics (85% phishing, 43% breach rate). Step 3: Document impact including business closure potential (28% of SMEs). Step 4: List current controls with verification dates. Step 5: Calculate residual risk scores. Step 6: Specify additional controls with costs. Step 7: A</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate><author>Graham Falkner</author></item><item><title>The 5-Step IoT Device Audit: Find and Secure Every Forgotten Computer on Your Network</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/10-minute-security-check-prevent-43000-breach-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/10-minute-security-check-prevent-43000-breach-guide/</guid><description>Practical Value: After Monday&apos;s podcast about the marketing agency breach through an unsecured printer, the most common question we&apos;ve received is: &quot;How do I actually do this audit myself?&quot; Fair question. Telling business owners they have a problem is easy. Providing practical steps to fix it is harder. This guide walks you through conducting a comprehensive IoT device audit using free tools. Time investment: 4-6 hours for initial audit. Cost: Free to Â£200 for network scanning tools. Difficulty:</description><pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate><author>Graham Falkner</author></item><item><title>Three Zero Days And A Christmas Timebomb: December Patch Tuesday Will Hurt If You Ignore It</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/december-2025-patch-tuesday-zero-days-christmas-timebomb/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/december-2025-patch-tuesday-zero-days-christmas-timebomb/</guid><description>December 2025 Patch Tuesday is supposed to be the quiet cruise into Christmas, right? Instead we got fifty seven vulnerabilities, three zero days and one actively exploited Windows privilege escalation that hits almost every supported build. Add in one hundred and thirty nine Adobe fixes and an awkward five week gap until the next Patch Tuesday in January and you have a perfect festive storm. Are you really happy to leave servers and laptops unpatched while everyone is on holiday, or do you want</description><pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate><author>Graham Falkner</author></item><item><title>The Complete SMB Toolkit for Reverse Benchmarking: Free and Budget Tools That Actually Work</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/smb-reverse-benchmarking-toolkit-free-tools-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/smb-reverse-benchmarking-toolkit-free-tools-2025/</guid><description>Right, enough theory. Today we&apos;re getting practical: the actual tools, templates, and processes you need to implement reverse benchmarking without spending a fortune. Everything in this guide is either free or costs less than a decent takeaway curry per month. Because I&apos;m sick of &quot;enterprise security&quot; guides that assume unlimited budgets and dedicated staff. This is the real-world, shoestring-budget, one-person-wearing-multiple-hats implementation guide. Asset inventory using Google Sheets: free</description><pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate><category>free-security-tools</category><category>smb-cybersecurity</category><category>budget-security</category><category>implementation-guide</category><category>security-templates</category><category>practical-cybersecurity</category><category>uk-smb-resources</category><author>Graham Falkner</author></item><item><title>Demonstrating Reasonable Care: Your Practical Guide to Cybersecurity Accountability</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/demonstrating-reasonable-care-cybersecurity-uk-business-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/demonstrating-reasonable-care-cybersecurity-uk-business-2025/</guid><description>Enough theory. Today we&apos;re getting practical. Whether or not director liability becomes law, demonstrating reasonable care protects your business now. Insurance claims require evidence. Contracts demand due diligence. Regulators ask what you did before the breach. This guide gives you exactly what you need: the five controls that matter, documentation templates, evidence gathering processes, and realistic timelines for businesses of every size. No enterprise consultants required. No massive budg</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate><author>Graham Falkner</author></item><item><title>How to Implement MFA Across Your Business in One Afternoon (Complete Guide)</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/implement-mfa-business-complete-guide/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/implement-mfa-business-complete-guide/</guid><description>After this week&apos;s coverage of the Synnovis death, many of you have asked: &quot;How do I actually implement MFA in my business?&quot; Here is your complete, practical guide. No jargon, no theory, just step-by-step instructions for enabling multi-factor authentication across your entire organisation. This afternoon. Right now. Whether you are running Microsoft 365, Google Workspace, or a mix of different services, this guide walks you through the exact process. I will show you how to configure systems, dep</description><pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate><category>MFA implementation</category><category>multi-factor authentication setup</category><category>business security guide</category><category>authentication tutorial</category><category>Microsoft 365 MFA</category><category>Google Workspace 2FA</category><category>security key deployment</category><category>SME security</category><author>Graham Falkner</author></item><item><title>Opinion: UK SMBs Are Funding AI&apos;s Energy Crisis and Nobody Asked Permission</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/opinion-smb-funding-ai-energy-crisis-nuclear-power-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/opinion-smb-funding-ai-energy-crisis-nuclear-power-2025/</guid><description>Here&apos;s a question for your weekend: Did anyone ask if UK small businesses wanted to fund Microsoft&apos;s nuclear reactor restart? Because that&apos;s what&apos;s happening. While Microsoft spends $1.6 billion restarting Three Mile Island, Google partners with Kairos Power for small modular reactors, and Amazon secures nuclear capacity across multiple projects, your cloud bills are climbing to pay for it. Nobody took a vote. Nobody asked permission. Tech giants made a collective decision that AI is worth unlim</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><category>ai-energy-crisis</category><category>nuclear-power-ai</category><category>smb-responsibility</category><category>cloud-pricing</category><category>opinion-piece</category><category>finalspark</category><category>microsoft-nuclear</category><category>google-kairos</category><category>tech-industry-criticism</category><category>uk-small-business</category><author>Graham Falkner</author></item><item><title>7 Actions to Stop Your Cloud Bill Funding AI&apos;s Nuclear Ambitions</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-ai-cost-control-uk-smb-practical-guide-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cloud-ai-cost-control-uk-smb-practical-guide-2025/</guid><description>Microsoft&apos;s restarting Three Mile Island. Google&apos;s building small modular reactors. Amazon&apos;s buying nuclear capacity. And you&apos;re getting the bill. While tech giants scramble for gigawatts to power their AI fantasies, your cloud costs are climbing faster than a hyperactive squirrel on espresso. AWS up 15%, Azure up 12%, SaaS tools adding &quot;AI features&quot; you didn&apos;t ask for at 20% premium. But here&apos;s what nobody&apos;s telling you: you don&apos;t need to accept this as inevitable. Seven specific actions you ca</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><category>cloud-cost-control</category><category>ai-pricing</category><category>uk-smb-costs</category><category>azure-pricing</category><category>aws-costs</category><category>saas-inflation</category><category>cost-optimization</category><category>business-efficiency</category><category>finalspark</category><category>nuclear-ai</category><author>Graham Falkner</author></item><item><title>InfoSec, CyberSec, IT Security: Vendors Are Selling You the Wrong One on Purpose</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/infosec-cybersec-it-security-vendors-selling-wrong-security-uk-smb-2025/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/infosec-cybersec-it-security-vendors-selling-wrong-security-uk-smb-2025/</guid><description>Security vendors are playing you for fools, and they&apos;re getting rich doing it. Every week I watch UK business owners waste £20,000 on &quot;comprehensive cybersecurity platforms&quot; when they needed £5,000 of basic IT security. The industry deliberately muddies the difference between InfoSec, CyberSec, and IT Security because confused customers pay premium prices for inappropriate solutions. Meanwhile, 50% of small businesses were breached in 2025, proving that expensive confusion doesn&apos;t equal protecti</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate><category>podcast</category><category>infosec</category><category>cybersec</category><category>it-security</category><category>uk-smb-authentication</category><category>fido2</category><category>hardware-security-keys</category><category>authentrend</category><category>phishing-resistant-mfa</category><category>cyber-essentials</category><category>ncsc</category><category>secuity-budget</category><category>vendor-confusion</category><category>it-security-fundamentals</category><category>Multi-factor-authentication</category><category>uk-business-security</category><category>small-business-cybersecurity</category><category>episode-launch</category><author>Graham Falkner</author></item><item><title>Cybersecurity is Now Safeguarding - Understanding the 2025 Guidance Game-Changer</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cybersecurity-is-now-safeguarding-understanding-the-2025-guidance-game-changer/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cybersecurity-is-now-safeguarding-understanding-the-2025-guidance-game-changer/</guid><description>September 1st, 2025 marked a fundamental shift in UK education: cybersecurity officially became a safeguarding issue under the Keeping Children Safe in Education guidance. Paragraph 144 explicitly links cyber security to safeguarding responsibilities, meaning schools can no longer dismiss security as &quot;just an IT problem.&quot; This changes everything from a compliance perspective. When framed as &quot;keeping children safe&quot; rather than &quot;good IT security,&quot; schools respond differently. Governors now have st</description><pubDate>Tue, 14 Oct 2025 00:00:00 GMT</pubDate><category>KCSIE 2025</category><category>safeguarding guidance</category><category>school cybersecurity</category><category>statutory requirements</category><category>governor responsibilities</category><category>educational compliance</category><category>cyber standards</category><author>Graham Falkner</author></item></channel></rss>