<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Kathryn Renaud — The Small Business Cybersecurity Guy</title><description>Every article by Kathryn Renaud. Straight-talking cybersecurity advice for UK small businesses.</description><link>https://thesmallbusinesscybersecurityguy.co.uk/</link><language>en-gb</language><item><title>How AI Is Changing State-Sponsored Cyber Threats for UK SMBs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/state-sponsored-cyber-threats-ai-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/state-sponsored-cyber-threats-ai-uk-smb-2026/</guid><description>State-sponsored attackers are reaching small businesses through the systems they already rely on. Here is how to spot it and respond.</description><pubDate>Sun, 26 Apr 2026 16:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>remote-access</category><category>credential-theft</category><category>supply-chain-risk</category><category>incident-response</category><category>business-risk</category><author>Kathryn Renaud</author></item><item><title>Suspect a Breach? Act Now: A Practical UK SMB Playbook</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/suspect-data-breach-act-now-uk-smb-playbook-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/suspect-data-breach-act-now-uk-smb-playbook-2026/</guid><description>Most of the real damage from a data breach does not happen during the initial compromise. It happens in the scramble afterwards. Someone panics and wipes a server. Someone else coordinates the response through the email account that is already compromised. A well-meaning manager posts on social media before anyone understands what happened. The first hour determines whether this becomes a bad day you recover from or a business-ending week you do not. This playbook walks you through exactly what </description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate><category>incident-response</category><category>data-breach</category><category>ico</category><category>uk-gdpr</category><category>uk-smb</category><category>containment</category><category>breach-response</category><category>72-hour-notification</category><author>Kathryn Renaud</author></item><item><title>DUAA: The &quot;Keep Calm and Build a Workflow&quot; Act&amp;nbsp;</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/duaa-compliance-workflows-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/duaa-compliance-workflows-uk-smb-2026/</guid><description>The Data (Use and Access) Act just went live on 5 February, and if you&apos;re only hearing about it now, you&apos;re not alone. The commencement regulations were published two days before the provisions kicked in. That&apos;s the government&apos;s idea of adequate notice. Guest contributor Kathryn Renaud cuts through the panic with something actually useful: four repeatable workflows for DSARs, complaints, cookies, and automated decisions that any UK SMB can build this week with tools they already own. No expensiv</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate><category>uk-business</category><category>compliance-failiure</category><category>2026-threats</category><category>smb-security</category><category>duaa-2025</category><category>Data Protection</category><category>business-risk</category><author>Kathryn Renaud</author></item><item><title>When Your Firewall Vendor Starts Dropping Weekly CVEs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/firewall-vendor-cve-survival-guide-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/firewall-vendor-cve-survival-guide-uk-smb-2026/</guid><description>Your firewall vendor just announced another critical vulnerability. Last week brought two more. Last month? Six. When does &quot;routine security update&quot; become a vendor reliability crisis that threatens your business? For UK SMBs running Fortinet or SonicWall, the CISA Known Exploited Vulnerabilities catalogue tells an uncomfortable story: your perimeter security is under active, documented attack. This isn&apos;t vendor marketing or compliance theatre. This is your board-level &quot;do we stay or do we leave</description><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate><category>vendor-risk</category><category>fortinet-vulnerabilities</category><category>sonicwall-vulnerabilities</category><category>kev-catalogue</category><category>uk-smb-security</category><category>patch-management</category><category>Cyber Essentials</category><author>Kathryn Renaud</author></item><item><title>UK SMBs Left in the Crosshairs</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smbs-cybersecurity-bill-excludes-small-business/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-smbs-cybersecurity-bill-excludes-small-business/</guid><description>If you run a small or medium-sized business in the UK, the government just sent you a message: you are on your own. The November 2025 Cyber Security and Resilience Bill protects hospitals and power grids. It does not protect you. Of 5.5 million UK SMBs, exactly zero gained new cybersecurity protection. This was deliberate policy. Meanwhile, 43% of UK businesses experienced breaches last year, costing an average £3,550 per incident. Germany took a different approach—and it works. This article giv</description><pubDate>Sun, 21 Dec 2025 00:00:00 GMT</pubDate><category>Cyber Essentials</category><category>UK Government Policy</category><category>Germany NIS2</category><category>Board Accountability</category><category>Ransomware</category><category>Insurance Claims</category><category>Cyber Security and Resilience Bill</category><category>SMB Cybersecurity Strategy</category><author>Kathryn Renaud</author></item></channel></rss>