Five Episodes In. Here Is What You Can Actually Do About It.

Practical Advice

Five Episodes In. Here Is What You Can Actually Do About It.

Five weeks ago, we opened The Open Book Problem with a simple question: what does an attacker see before they send a UK SMB director anything?

The answer was thorough and uncomfortable. Companies House. The open electoral register. LinkedIn. Job adverts. Domain records. Data broker profiles built from all of the above without anyone’s meaningful knowledge or consent. A legal, free, structured reconnaissance opportunity that takes under twenty minutes and gives an attacker enough context to sound completely normal on the phone.

Over four episodes, we covered what attackers do with that information, why the regulatory framework has not adequately addressed the market that profits from it, and why the paid services built to help individuals navigate that market exist because the friction in the rights framework is a feature, not a bug.

Today we close the series. And we try to end somewhere useful.

Episode 5: The Fix That Actually Exists

The full cast returns.

Corrine Jefferson opens with the threat ranking. Not every exposure matters equally. The things that enable financial authorisation fraud and identity-based social engineering sit at the top. The things that are visible but not directly actionable by attackers sit lower. The priority order matters, because most UK SMB directors cannot address everything simultaneously and should not try.

Graham Falkner gives the thirty-day plan. Specific actions, specific sequence, realistic time estimates, honest about what can be done in a week and what takes longer. Some of it is a phone call to your local council. Some of it is a Β£30 application to Companies House. Some of it is editing three job adverts. None of it requires a security budget.

Mauven MacLeod argues the policy case. The Data (Use and Access) Act 2025 gave the Information Commission enhanced powers. Those powers include binding assessment notices, strengthened investigatory tools under PECR, and a restructured governance framework. If those tools are used with the same rigour that EU supervisory authorities have applied to the broader data processing ecosystem, the market will change. The case for expecting the Commission to use them is legitimate. The case for waiting until it does before acting individually is not.

Lucy Harper closes with the accountability record. The questions this series raised that the public record cannot yet satisfactorily answer. The gaps between what the law promises and what the enforcement record shows. And why documenting your own erasure requests, reappearances, and non-compliant responses matters beyond your individual situation.

What the Series Found

The open book problem has three components that interact.

The first is structural data publication: public registers that require personal information disclosure, a commercially available electoral dataset that most people have never opted out of, and professional networking cultures that treat transparency as a virtue regardless of who is watching.

The second is a commercial data broker market that aggregates, enriches, and re-sells that information without most individuals’ knowledge, under a legal framework that has not been enforced at the scale required to change market behaviour.

The third is individual rights that are theoretically available to address the second problem but practically difficult enough to exercise that a profitable subscription market has grown up to do it for you, partially, at a recurring monthly cost.

None of that is going to be solved this week. But most of the individual exposure is addressable this month. That distinction matters.

The Thirty-Day Baseline

The minimum adequate response for a UK SMB director, based on five episodes and five weeks of companion investigation:

Week one: Companies House check, electoral register opt-out, LinkedIn and job advert review. Week two: Domain records check, DMARC verification, priority erasure requests submitted to top three broker results. Week three: SAR responses reviewed, erasure requests followed up, old technical portals decommissioned. Week four: Verification controls reviewed for payment changes, MFA resets, and supplier changes.

That is one month. Most of it costs nothing. None of it requires a consultant.

How to Turn This Into a Competitive Advantage

For MSPs and advisers, this series is five weeks of structured client education material. The thirty-day plan from today’s episode is a client deliverable. Run it with a client, document the before and after, and you have demonstrated governance value that most competitors have not provided.

For business owners, completing the thirty-day baseline produces a documented state of director exposure management that belongs in your risk register, your supplier questionnaire responses, and any due diligence process where security governance is assessed.

How to Sell This to Your Board

The series gives you five episodes and five weeks of companion content as board briefing material. The core argument: your directors are profiled before attackers make contact. That profiling uses free, legal, public sources. The remediation is largely administrative and mostly free. The regulatory environment has not solved this at the systemic level. Active governance is the practical posture.

That is a three-minute board conversation with a concrete action list and an assigned owner.

What to Do Today

Listen to Episode 5. Download Graham’s thirty-day plan from the companion article. Assign week one actions today. Review in thirty days.

The open book problem is structural. The fix that exists, the one that is available right now without waiting for regulatory improvement, is the one we have been describing for five weeks. Most of it takes an afternoon. The rest takes a month.

Start today.

SourceArticle
Companies HouseRemove your home address from the Companies House register
ICOElectoral register opt-out
ICOYour right to get your data deleted
NCSCDefending against social engineering
Action FraudMandate fraud guidance
GOV.UKData Use and Access Act 2025 guidance

Filed under

  • smb-security
  • uk-business
  • social-engineering
  • data-protection
  • business-risk
  • executive-security
  • incident-response