
The Small Business Cyber Security Guy
Welcome to my personal blog — a space where I share my own views, opinions, and insights on technology, cyber security, and the realities of working in IT.
This blog is entirely personal. The thoughts and opinions expressed here are mine alone. They do not represent the views, policies, or positions of my employer, past or present, or any organisation I’m associated with professionally or personally.
Expect a mix of:
Straight-talking advice for small businesses
Honest takes on cyber security and IT trends
The occasional rant
A few war stories from the frontlines (names removed to protect the guilty)
With over 40 years in the industry, I’ve seen a lot — some of it brilliant, some of it baffling.
This blog is where I unpack all of it.

Malicious Chrome Extensions Are Now Your Password Manager — And They’re Keeping Your Logins (For Themselves)
Security researchers have discovered malicious Chrome extensions that detect and impersonate popular password managers, tricking users into handing over master passwords. Learn how this attack works, why Chrome’s extension security is still a disaster, and what users and businesses should do to stay safe.

ChatGPT Operator Data Leak – Why Your AI Assistant Can’t Keep a Secret
ChatGPT Operator, the AI agent with browsing powers, can be hijacked via prompt injection, causing it to leak private data or obey hidden attacker commands. Learn how this exploit works, why AI assistants need serious supervision, and what businesses must do to avoid their AI leaking client data to the internet.

The StubHub Ticket Heist: When Cybercriminals Outsmarted the Entire Concert Industry with Basic URL Tricks
Two criminals stole £500k worth of Taylor Swift tickets using nothing more than stolen StubHub URLs. This basic security failure exposes a flaw in how digital tickets are secured — and it’s a lesson for every business that relies on magic links. Find out what went wrong and how to protect your own platform from the same fate.

Silk Typhoon Supply Chain Attack: How Crap MSPs Sell You Out for £20 a Month
If your MSP isn’t certified to Cyber Essentials Plus (CE+) and charges less than £60 per user per month (excluding productivity licensing), you’re not getting a bargain — you’re buying a front-row seat to the next supply chain breach. China-backed hackers, Silk Typhoon, are targeting crap MSPs who cut corners on security, using their remote management tools to compromise every customer they support.
This isn’t theory — it’s happening right now, and businesses who blindly trust their providers without checking certification, audit history, or internal security are sitting ducks. Find out how cheap MSPs are fuelling the next wave of cyber attacks, and why CE+ should be your absolute minimum requirement for any provider touching your network.

Jaguar Land Rover Cyber Breach: Hackers Drive Off with Luxury Brand's Secrets!
Jaguar Land Rover—known for luxury, performance, and now, apparently, spectacular cybersecurity fails—has become the latest high-profile victim of a cyberattack. Hackers allegedly snatched critical internal documents, sensitive employee data, and the company's precious source code, then dumped it all online like yesterday's leftovers. As connected cars transform into rolling computers, cybercriminals are clearly buckling up for joyrides through corporate data. Is your business ready, or are you just waiting your turn to become tomorrow’s headline? Time to shift gears and get serious about cybersecurity—before it's too late.

Microsoft's March 2025 Patch Tuesday: 57 Vulnerabilities and a Side of Zero-Day Chaos
March 2025 Patch Tuesday just dropped a cybersecurity bombshell. Discover why your sleep-deprived IT team might never forgive Microsoft (and why your MSP had better be on this ASAP!).

Urgent Alert: Apple Users Under Attack—Is Your Device Safe?
Is your Apple device silently compromised? Hackers are exploiting a dangerous new vulnerability RIGHT NOW—find out if you're at risk and how to protect yourself immediately!

Eleven11 Botnet: The Newborn Monster That Can DDoS You Into Next Week
Meet Eleven11, the brand-new botnet responsible for record-shattering DDoS attacks peaking at 3.6 Tbps. This fast-growing menace, built from 30,000 compromised devices, can cripple networks, wipe out online businesses, and expose weak cybersecurity in minutes. Find out how it works, why it’s terrifying, and what every business should do right now to avoid becoming the next victim.

Leuma Stellar: The Malware That Wants Your Crypto and Thinks You’re Dumb Enough to Hand It Over
Hackers are using fake PDFs disguised as bot detection images to deliver Leuma Stellar, malware designed to steal cryptocurrency wallets, logins, and browser data. Find out how this ridiculously simple scam works, why businesses and crypto holders should care, and how to lock down your assets before your Bitcoin buys someone else’s Lamborghini.

Rayhunter – The Free Tool That Lets You Spot Stingrays Before They Hoover Up Your Life
Stingrays are tracking devices disguised as phone towers, used to spy on your location, calls, and messages. The EFF’s free open-source tool Rayhunter lets you detect these covert surveillance devices — putting control of your privacy back in your hands. Find out how Stingrays work, why Rayhunter matters, and why your phone is probably betraying you right now.

Microsoft Signed a Shit Driver, Now Hackers Have the Keys to Your Entire F’ing Network
Microsoft signed a vulnerable driver, and ransomware gangs couldn’t believe their fucking luck. With SYSTEM access gifted on a plate, malware could disable your antivirus, wipe your backups, and redecorate your operating system. This is what happens when you trust Microsoft to check their own homework. Learn how it happened, why BYOVD is back, and what you need to do before your network becomes the next crime scene.

Artificial Intelligence in Cybersecurity: The Digital Arms Race No One Asked For
Cybersecurity has become an AI-driven arms race. Attackers now use AI to automate phishing, bypass security, and mimic human behavior to slip past defences. Meanwhile, AI-powered security tools fight back, detecting threats in real-time.
But most businesses are unprepared. If your security relies on outdated defences, you’re already losing. AI isn’t just changing cybersecurity—it’s redefining it.
The only way to stay ahead? Cyber Essentials Plus as your baseline. Anything less, and you’re gambling while cybercriminals use AI to exploit weaknesses.

Cyber Essentials: Does It Work and Is It Worth the Effort for Small Businesses?
Cyber Essentials is a government-backed certification that helps small businesses get basic cybersecurity right. But does it actually work, and is it worth the time and money? In this article, we look at what Cyber Essentials involves, how much it costs, and whether it genuinely protects your business from cyber threats. With fresh insights from the UK government’s 2024 evaluation, we uncover the real-world benefits for small businesses.

Why Small Businesses Are a Hacker’s Favourite Snack (And How Not to Be One)
Small businesses love to think they’re “too small” for hackers to bother with. Reality check: that’s exactly why cybercriminals love you. No security team. No proper defences. Just an unlocked digital front door and a password that might as well be ‘password123’. If you’re not taking cybersecurity seriously, you’re practically begging to be hacked.
In this post, we break down why small businesses are an easy target, the biggest security mistakes they make, and how Cyber Essentials can stop your business from becoming a cybercriminal’s next easy payday. Spoiler: it’s easier (and cheaper) than you think.

Teams & Quick Assist: Microsoft’s New Gift to Cybercriminals Everywhere
In one of the most embarrassing cyber trends of 2025, hackers are using Microsoft Teams to impersonate IT support, then tricking employees into launching Windows Quick Assist, effectively handing remote control of their computers to criminals. Once inside, attackers install malware, steal credentials, and deploy persistent backdoors — all thanks to tools Microsoft built and businesses blindly trust. If your staff still believe every Teams message with ‘IT’ in the name is legitimate, congratulations — you’re already a statistic. Learn how this absurdly preventable scam works and what you need to do right fucking now to avoid becoming the next case study in cybersecurity failure.

Protecting Personal Data in the Era of IoT: Best Practices for Businesses and Consumers
From smart fridges to connected doorbells, IoT devices collect mountains of personal data; and they’re prime targets for hackers. This guide explores how businesses and consumers can secure their devices, protect sensitive data, and avoid turning their smart home into a cyber criminal’s playground.

Snail Mail Ransomware – When Hackers Go Full 1950s and Post You a Demand Letter
Hackers are sending ransom demands via the post, pretending to be BianLian and demanding Bitcoin. Find out why this bizarre scam works, how to respond, and what every UK business must know.

Top Cyber Security Certifications in 2025: Boost Your Career and Your Sanity
In the chaotic world of cyber security certifications, 2025 offers more choices than ever; but not all of them are worth your time (or sanity). From the gold-standard CISSP to the controversial CompTIA Security+, this guide cuts through the marketing fluff to reveal which certifications actually boost your career and which ones just boost someone’s profit margins. Whether you’re aiming to become a penetration tester, security manager, or cloud security expert, this brutally honest review will help you pick wisely — and avoid the snake oil.

Tata Technologies Ransomware Attack: 1.4TB of Data Gone Walkabout
Tata Technologies hit by ransomware attack, exposing 1.4TB of sensitive client data linked to Airbus, Ford, Jaguar and Honda. Learn what happened and how supply chain security failures put everyone at risk.

Over 4,000 ISP Networks Hacked Because People Still Use ‘admin123’ as a Password — WTF?
More than 4,000 ISP networks got hacked because they left their admin passwords set to 'password123' — and shockingly, that didn’t work out well. Cybercriminals brute-forced their way into routers, servers, and management systems, planting infostealers, cryptominers, and enough malware to make an antivirus cry. This wasn’t some elite state-sponsored operation; it was basic-level script kiddie shit that worked because ISPs still treat security like a hobby. Find out how it happened, why your broadband might be slower than a fax machine, and how these companies left the front door wide open for hackers.
⚠️ Full Disclaimer
This is my personal blog. The views, opinions, and content shared here are mine and mine alone. They do not reflect or represent the views, beliefs, or policies of:
My employer
Any current or past clients, suppliers, or partners
Any other organisation I’m affiliated with in any capacity
Nothing here should be taken as formal advice — legal, technical, financial, or otherwise. If you’re making decisions for your business, always seek professional advice tailored to your situation.
Where I mention products, services, or companies, that’s based purely on my own experience and opinions — I’m not being paid to promote anything. If that ever changes, I’ll make it clear.
In short: This is my personal space to share my personal views. No one else is responsible for what’s written here — so if you have a problem with something, take it up with me, not my employer.