The Fix That Actually Exists: Closing the Open Book on OSINT Exposure
The open book problem is structural. But that does not mean small businesses are helpless.
This is the final episode of The Open Book Problem. The full cast is here. Corrine Jefferson ranks the exposures by real attack risk. Graham Falkner delivers the thirty-day action plan. Mauven MacLeod makes the policy argument. Lucy Harper closes with the accountability questions still waiting for answers. And then we name the phrases that need to stop.
Corrine Ranks the Risk
Not every public exposure deserves the same level of concern. Panic is useless. Prioritisation is useful.
Highest priority: information that supports identity compromise or financial authorisation abuse.
Director identity, finance contacts, reporting lines, personal addresses, personal phone numbers, current suppliers, and internal approval patterns. These are the details that help an attacker sound legitimate when requesting money, access, or a reset. Fix these first.
Second priority: information that supports technical targeting.
Exposed login portals, email provider records, outdated service banners, remote access systems, public cloud naming patterns, and job adverts that reveal security tooling. This is where IT housekeeping starts.
Third priority: information that supports timing and pressure.
Travel posts, event attendance, staff absence signals, mergers, major projects, recruitment campaigns, new supplier announcements, and public complaints. These details help an attacker decide when to strike, not just how.
Fourth priority: general background noise.
Old bios, harmless marketing copy, broad sector membership, and public content that does not identify people, systems, or processes may carry lower risk. Do not spend a week deleting harmless material while your home address and finance process remain exposed.
Fix what enables action. Everything else is secondary.
Graham’s Thirty-Day Action Plan
Week one: discover.
Search your company name, trading names, director names, senior staff names, registered address, domain names, and common email formats. Use search engines as an attacker would. Capture screenshots. Build the exposure list. Tag each finding by risk category using Corrine’s framework: identity and finance, technical, timing, or background noise.
Week two: fix official sources.
Check Companies House. Correct any live records that include home addresses as service addresses or registered offices. Apply for removal or suppression where eligible. Opt out of the open electoral register. Confirm domain registration privacy settings. Correct obvious incorrect directory entries.
Keep evidence of every change you make. Date each action. This matters if you later need to demonstrate compliance or challenge persistent data.
Week three: reduce social and commercial exposure.
Clean up LinkedIn profiles: remove unnecessary supplier names, system references, reporting structures, and internal project detail. Review job adverts for the same. Submit broker removal requests and people-search opt-outs for the highest-priority results identified in week one.
Brief your staff on what you are doing and why. Someone will helpfully republish removed information on a team social post if they do not understand why it was removed in the first place.
Week four: harden processes.
Payment changes. MFA resets. Password resets. Supplier onboarding. Emergency access exceptions. Director requests. Every sensitive process needs an out-of-band verification step using a known contact route.
This fourth week matters most. Reducing data exposure helps. Process controls stop the attack when data still leaks, because it will.
Mauven’s Policy Argument
Individual action helps. It cannot solve the whole problem.
You cannot personally regulate a data broker market with a spreadsheet and righteous fury. The structural problem requires a structural response.
A properly regulated UK data broker market would be more transparent, more accountable, and less difficult for individuals to challenge. It should be clear who holds data, where it came from, who receives it, which lawful basis applies, and how removal or objection is handled. And those claims should be auditable by the regulator, not self-certified by the brokers themselves.
Companies House needs continued reform around personal exposure. Business transparency and personal safety are not the same question. The government should not be required to choose between them. It should be designing for both.
The specific ask for business owners: raise this through trade bodies, local business groups, chambers of commerce, and sector associations. Individual complaint is weak. Collective pressure is stronger. If your trade body is not discussing director exposure as a security risk, ask them why.
Joining the dots between cyber risk, fraud risk, and privacy risk also matters. These sit in separate policy teams, separate government departments, and separate regulatory remits. The attacker does not see separate boxes. The response should not either.
Lucy’s Accountability Summary
Five questions that have not received satisfactory public answers from the ICO.
How many UK data broker audits have been completed since UK GDPR came into force?
How many enforcement actions have targeted repeated reprocessing after erasure or objection requests have been submitted by individuals?
How many brokers have been required to explain the lineage of data derived from public registers?
How does the regulator assess personal safety risk for directors, sole traders, trustees, and vulnerable individuals specifically?
What proactive work is being done, rather than waiting for individuals to submit complaints?
The accountability position is this: the ICO has had the tools since 2018. The data broker market has grown. Success is not being measured in terms the public can understand. Until those questions receive specific, documented answers, the regulatory response has not matched the scale of the harm.
This does not mean the ICO has done nothing. It means nothing has been done at sufficient scale to change the market.
When to Get Help
Some situations require professional assistance rather than self-help.
Get help if personal safety is involved. If you have received harassment, threats, or stalking linked to your public data, this is not a spreadsheet problem.
Get help if fraud has already occurred. Preserve evidence before cleaning anything. Contact your bank immediately. Report to Action Fraud. Do not tidy the crime scene before it has been recorded.
Get help if you find exposed remote access, unknown login portals, weak email authentication, or any indication that accounts may already be compromised. These require security professionals, not a removal request form.
Get help if your situation is complex: multiple trading names, multiple directors, multiple addresses, or historic exposure across several registers.
For straightforward audit and reduction work, the steps in this series are achievable without specialist assistance.
The Role of Cyber Essentials
Cyber Essentials does not solve OSINT exposure by itself. It is not a privacy removal scheme. It will not remove your address from Companies House. It will not make LinkedIn stop being LinkedIn.
But the framework’s underlying discipline is relevant. Know your assets. Reduce unnecessary exposure. Control access. Patch systems. Use MFA. Remove unnecessary services.
Use Cyber Essentials as the floor. Add the human and data exposure controls from this series above it. The certification is not the end point. Behaviour is the end point. Badges without behaviour are compliance theatre.
How to Turn This Into a Competitive Advantage
For MSPs and advisers, this five-episode series is a service framework. The thirty-day plan, the risk ranking, the upstream/downstream distinction, and the policy argument give you a structured offering that most competitors have not developed.
Help clients audit their OSINT exposure. Fix their Companies House records. Brief their staff. Harden their verification processes. Track broker removal requests. That is a documented, repeatable engagement. It is also increasingly relevant in supplier due diligence and procurement.
For business owners, the competitive advantage sits in demonstrating that you treat director exposure as governance, not IT. It belongs in your risk register. It belongs in your onboarding process for new directors. It belongs in your incident response plan. When a procurement team asks how your business manages impersonation risk, have an answer.
How to Sell This to Your Board
The series argument in three board-level points.
This is not a privacy issue that sits outside the security conversation. Director exposure is an attack surface. Attackers use public data to build credibility before committing fraud. That is a security and fraud risk with financial consequences, not a philosophical concern about privacy.
The fix is partly free and partly political. Personal action: fix official records, reduce broker exposure, harden verification. This costs time, not money. The political part: raise it with trade bodies and through collective business voice. Government and regulators respond to organised business pressure differently from individual complaint.
Doing nothing has a measurable downside. UK Finance reports hundreds of millions of pounds annually in authorised push payment fraud and mandate fraud targeting UK businesses. A proportion of that starts with the kind of reconnaissance this series has documented. The cost of basic housekeeping is negligible by comparison.
The Five Phrases That Need to Stop
Stop saying: it is public anyway.
Public does not mean harmless. The combination of public data creates risk that no individual piece carries alone.
Stop saying: nobody would target us.
Attackers target usefulness, not fame. If you can authorise payments, approve access, or reset credentials, you are useful.
Stop saying: our staff would spot that.
Maybe they would. Maybe they would not. Process should not depend on heroic suspicion from every individual, every time.
Stop saying: the regulator would act if it mattered.
Regulatory action lags harm by years. Waiting for the ICO to fix the data broker market is not a risk management strategy.
Stop saying: we will look at that later.
Later is where preventable incidents go to breed.
The Final Tabletop Exercise
Here is one practical exercise you can run this week, in under an hour.
Pick one sensitive action. A bank detail change, a payroll amendment, an MFA reset, or a supplier payment approval.
Ask what public information would help an attacker request that action convincingly. What do they already know from Companies House, LinkedIn, and job adverts?
Ask who would receive such a request. Which channel would be trusted. What pressure would work.
Ask what evidence would remain afterwards, and whether you would notice quickly.
Then fix the weakest point the exercise reveals. Repeat for each critical process.
This is how OSINT risk becomes operational security. Not panic. Not theatre. Work.
What to Do This Week
-
Start week one of the thirty-day plan. Search yourself and your directors as an attacker would. Build the exposure list. Tag by risk.
-
Prioritise identity and finance exposure. Fix what enables authorisation abuse before anything else.
-
Brief your board or equivalent. Bring the five-episode argument. Assign ownership of the thirty-day plan.
-
Contact your trade association. Ask what position they have on director exposure and data broker regulation. If they do not have one, suggest they develop one.
-
Choose one sensitive process and run the tabletop. You do not need a consultant. You need an hour and a whiteboard.
| Source | Article |
|---|---|
| Companies House | Remove your home address from the Companies House register |
| ICO | Electoral register and the open register opt-out |
| ICO | Your right to get your data deleted |
| NCSC | Cyber Essentials overview |
| UK Finance | Annual Fraud Report 2025 |
| Action Fraud | Mandate fraud |
| GOV.UK | Cyber Security Breaches Survey 2025/2026 |
Listen to the full episode: The Open Book Problem, Episode 5: The Fix That Actually Exists.
The full series: Episode 1: You Are Already an Open Book. Episode 2: The Attacker’s Playbook. Episode 3: The Regulator Who Looked the Other Way. Episode 4: The Subscription Scam That Is Not Quite a Scam. Episode 5: The Fix That Actually Exists.