<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Lucy Harper — The Small Business Cybersecurity Guy</title><description>Every article by Lucy Harper. Straight-talking cybersecurity advice for UK small businesses.</description><link>https://thesmallbusinesscybersecurityguy.co.uk/</link><language>en-gb</language><item><title>What to Ask a Data Removal Service Before You Pay: A UK Director&apos;s Checklist</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/data-removal-service-questions-uk-director-checklist-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/data-removal-service-questions-uk-director-checklist-2026/</guid><description>Lucy Harper examines what UK directors should ask data removal services before subscribing, using published coverage data and documented service limitations.</description><pubDate>Fri, 31 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>vendor-risk</category><category>business-risk</category><category>executive-security</category><category>compliance-failure</category><author>Lucy Harper</author></item><item><title>The ICO&apos;s Questions: What the Regulator Has Not Yet Answered on Data Brokers</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-data-broker-accountability-questions-unanswered-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/ico-data-broker-accountability-questions-unanswered-2026/</guid><description>Lucy Harper examines the accountability questions the ICO has not yet answered about UK data broker oversight, using the published enforcement record.</description><pubDate>Fri, 17 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>compliance-failure</category><category>public-sector-security</category><category>business-risk</category><category>executive-security</category><author>Lucy Harper</author></item><item><title>What the Data Brokers Know About You: A UK Director Investigation</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-data-broker-director-profile-investigation-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-data-broker-director-profile-investigation-2026/</guid><description>What do UK data brokers actually hold on a small business director? Lucy Harper investigates using public records, enforcement history, and ICO documentation.</description><pubDate>Sat, 11 Jul 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>data-protection</category><category>compliance-failure</category><category>executive-security</category><category>business-risk</category><category>public-sector-security</category><author>Lucy Harper</author></item><item><title>When the Patch Was Not Enough: An Accountability Audit</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-patch-not-enough-accountability-audit-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/fortinet-patch-not-enough-accountability-audit-uk-smb-2026/</guid><description>The patch closed the hole. Attackers got in through a new one. The real failure was not technical. It was the absence of anyone watching the edge.</description><pubDate>Fri, 26 Jun 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>msp-security</category><category>remote-access</category><category>vendor-risk</category><category>incident-response</category><author>Lucy Harper</author></item><item><title>The M&amp;S DragonForce Attack One Year On: What a Phone Call to IT Support Cost a Billion-Pound Retailer</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/marks-spencer-dragonforce-attack-one-year-case-study-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/marks-spencer-dragonforce-attack-one-year-case-study-2026/</guid><description>A social engineering phone call. A password reset. £300 million in losses. The M&amp;S DragonForce attack is the most expensive lesson in UK retail cyber security history.</description><pubDate>Fri, 22 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>incident-response</category><category>business-risk</category><category>social-engineering</category><category>supply-chain-risk</category><category>ransomware-groups</category><author>Lucy Harper</author></item><item><title>Operation SIMCARTEL: The SIM Farm That Made a Mockery of UK SMS Verification</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/operation-simcartel-sim-farm-uk-sms-verification-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/operation-simcartel-sim-farm-uk-sms-verification-2026/</guid><description>GoGetSMS sold SIM verification bypass on the open web for years. Europol shut it down. UK banks still rely on the control it defeated.</description><pubDate>Fri, 22 May 2026 09:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>social-engineering</category><category>credential-theft</category><category>compliance-failure</category><category>supply-chain-risk</category><author>Lucy Harper</author></item><item><title>One Password, 700 Jobs: How Cheap Security Killed a 158-Year-Old British Business</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/knp-logistics-ransomware-cheap-security-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/knp-logistics-ransomware-cheap-security-2026/</guid><description>KNP Logistics had antivirus, firewalls, backups, and insurance. No MFA. No EDR. One guessed password later, 700 people were out of work and a 158-year-old company was gone.</description><pubDate>Fri, 15 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>ransomware-groups</category><category>incident-response</category><category>business-risk</category><category>compliance-failure</category><author>Lucy Harper</author></item><item><title>The Quantum Computing Threat: What UK SMBs Need to Know</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/the-quantum-computing-threat-what-uk-smbs-need-to-know/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/the-quantum-computing-threat-what-uk-smbs-need-to-know/</guid><description>Quantum computing could break encryption soon. UK SMBs must act now to secure data. Learn the steps to protect your business and gain a competitive edge.</description><pubDate>Thu, 14 May 2026 14:00:00 GMT</pubDate><category>quantum computing</category><category>encryption</category><category>data security</category><category>small business</category><author>Lucy Harper</author></item><item><title>Six Percent: The Supply Chain Number That Should Terrify Every Small Business in the UK</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/supply-chain-cyber-risk-uk-small-business-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/supply-chain-cyber-risk-uk-small-business-2026/</guid><description>6% of UK businesses review their wider supply chain for cyber risk. 94% are flying blind. The most dangerous number in the 2026 Breaches Survey.</description><pubDate>Fri, 08 May 2026 07:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>vendor-risk</category><category>business-risk</category><category>compliance-failure</category><category>msp-security</category><author>Lucy Harper</author></item><item><title>Jaguar Land Rover: How One Cyberattack Cost the UK Economy £1.9 Billion and Left 5,000 Businesses Scrambling</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/jlr-cyberattack-supply-chain-case-study-uk-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/jlr-cyberattack-supply-chain-case-study-uk-2026/</guid><description>The JLR attack cost £1.9 billion. Suppliers six tiers down the chain had no say in JLR&apos;s security decisions. They paid anyway. Here is the full story.</description><pubDate>Fri, 01 May 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>supply-chain-risk</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><author>Lucy Harper</author></item><item><title>The Accountancy Firm That Blamed DNS for Three Weeks While a Compromised Router Rewrote Their Network Map</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/dns-misdiagnosis-compromised-router-case-study-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/dns-misdiagnosis-compromised-router-case-study-2026/</guid><description>Three weeks. Two resolver changes. One compromised router nobody checked. How a UK accountancy firm blamed DNS while the real threat hid.</description><pubDate>Fri, 24 Apr 2026 08:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>incident-response</category><category>vendor-risk</category><category>compliance-failure</category><category>supply-chain-risk</category><author>Lucy Harper</author></item><item><title>The Invoice That Wasn&apos;t: A UK BEC Case Study Built From Documented Real-World Patterns</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-bec-invoice-fraud-case-study-vendor-email-compromise-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/uk-bec-invoice-fraud-case-study-vendor-email-compromise-2026/</guid><description>Learn from a UK BEC case study where a property firm lost £12,100. Discover the one free policy that could have stopped it.</description><pubDate>Sun, 19 Apr 2026 06:00:00 GMT</pubDate><category>social-engineering</category><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>compliance-failure</category><category>credential-theft</category><category>incident-response</category><author>Lucy Harper</author></item><item><title>A Fridge Failed. The Complaint Went Nowhere. The Data Request Became the Next Dispute.</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/domestic-general-complaint-dsar-case-study-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/domestic-general-complaint-dsar-case-study-2026/</guid><description>A household with refrigerated medication says the paid route delivered a worse practical outcome than the free one, and that the later data request became a dispute of its own.</description><pubDate>Mon, 13 Apr 2026 06:00:00 GMT</pubDate><category>uk-business</category><category>consumer-rights</category><category>data-protection</category><category>complaint-handling</category><category>vendor-risk</category><author>Lucy Harper</author></item><item><title>MFA on the Firewall, Not the Servers: The Case That Shows How UK Cyber Claims Really Die</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-mfa-void-uk-case-study-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-insurance-mfa-void-uk-case-study-2026/</guid><description>A UK business said yes to MFA on their proposal form. The attack came through servers with no MFA. The policy was voided. Lucy Harper investigates.</description><pubDate>Fri, 10 Apr 2026 11:39:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>business-risk</category><category>compliance-failure</category><category>remote-access</category><category>incident-response</category><author>Lucy Harper</author></item><item><title>The Package Your Developer Trusted: How the Axios Supply Chain Attack Put 100 Million Downloads at Risk</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/axios-npm-supply-chain-attack-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/axios-npm-supply-chain-attack-uk-smb-2026/</guid><description>One compromised npm account. Two poisoned packages. 100 million weekly downloads at risk. Who is accountable when open-source governance fails?</description><pubDate>Tue, 07 Apr 2026 13:00:00 GMT</pubDate><category>smb-security</category><category>supply-chain-risk</category><category>uk-business</category><category>vendor-risk</category><category>business-risk</category><author>Lucy Harper</author></item><item><title>Case File: The Cyber Attack That Locked Every School in Northern Ireland</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/c2k-cyber-attack-northern-ireland-schools-investigation-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/c2k-cyber-attack-northern-ireland-schools-investigation-2026/</guid><description>One attack. One network. 350,000 people locked out. And four days later, nobody will say what type of attack it was.</description><pubDate>Mon, 06 Apr 2026 10:00:00 GMT</pubDate><category>smb-security</category><category>uk-business</category><category>vendor-risk</category><category>compliance-failure</category><category>supply-chain-risk</category><category>public-sector-security</category><category>incident-response</category><author>Lucy Harper</author></item><item><title>Protecting Your Business from Virtual Smartphone Scams</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/protecting-your-business-from-virtual-smartphone-scams/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/protecting-your-business-from-virtual-smartphone-scams/</guid><description>Scammers use virtual smartphones to deceive small businesses. Learn how to protect your business and prevent financial loss.</description><pubDate>Wed, 01 Apr 2026 07:00:00 GMT</pubDate><category>Fraud</category><category>Scams</category><category>Cybersecurity</category><author>Lucy Harper</author></item><item><title>The Certificate That Made Things Worse: A Cyber Essentials Scope Drift Case Study</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-scope-drift-case-study-uk-smb-2026/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/cyber-essentials-scope-drift-case-study-uk-smb-2026/</guid><description>By the time anyone at Meridian Advisory noticed the problem, their Cyber Essentials certificate had been renewed four times. Each renewal had covered the same carefully defined scope: two office servers, the on-premises file share, and about fifteen managed laptops. By 2025, the actual business ran on Microsoft 365, a cloud-based CRM, a remote project management platform, and a VOIP system. None of those were in scope. When a credential-based breach exposed client financial data held in the CRM,</description><pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate><category>cyber-essentials</category><category>case-study</category><category>scope-management</category><category>uk-smb</category><category>data-breach</category><category>ico</category><category>director liability</category><author>Lucy Harper</author></item><item><title>What Happened to the 14 Million People the Currys’ Breach Left Behind</title><link>https://thesmallbusinesscybersecurityguy.co.uk/blog/currys-dsg-breach-victims-no-compensation-uk-case-study/</link><guid isPermaLink="true">https://thesmallbusinesscybersecurityguy.co.uk/blog/currys-dsg-breach-victims-no-compensation-uk-case-study/</guid><description>Darren Warren asked for five thousand pounds for the distress of having his data stolen from Currys&apos; tills. The High Court struck most of his claim out. Meanwhile, specialist law firms ran &quot;Were you affected by the Currys breach?&quot; campaigns, then quietly closed their books without any settlement. The Court of Appeal confirmed in February 2026 that DSG absolutely had a duty to protect that data. By then, most claimants&apos; limitation periods had expired. This is the story of how 14 million people en</description><pubDate>Fri, 06 Mar 2026 00:00:00 GMT</pubDate><category>dsg-retail-breach</category><category>data-breach-victims</category><category>ico-enforcement</category><category>limitation-periods</category><category>group-action-claims</category><category>compliance-failure</category><author>Lucy Harper</author></item></channel></rss>