The Small Business Cyber Security Guy · 2026-06-29 · 20 min
Key moments - from our scoring
Substance score
70 / 100
Five dimensions, 20 points each
This episode exposes how open-source intelligence (OSINT) enables attackers to build comprehensive profiles of UK SMB directors and their businesses before ever attempting to breach systems. Noel Bradford and Corrine Jefferson walk through the passive reconnaissance chain: Companies House reveals company structure, directors, and financial signals; the electoral register adds residential identity; LinkedIn publishes organizational charts and technology stacks through job adverts; public DNS records expose email providers like Microsoft 365, Google Workspace, or Mimecast; and domain records surface forgotten VPN pages and legacy systems. The core insight is that transparency mechanisms designed for legitimate purposes - fraud prevention, credit checking, accountability - become weaponized when combined across data sources. An attacker doesn't need stolen credentials or exploits; they need correlation. SMBs are particularly vulnerable because directors often lack the organizational separation (dedicated comms teams, executive assistants, approval workflows) that protect larger enterprises, making them high-value targets simply because they can authorize payments or system changes. The episode argues this isn't about paranoia but threat-informed data hygiene.
Companies House provides registered office address, company number, incorporation date, active and resigned officers, persons with significant control, filing history, accounts, confirmation statements, and historic address patterns - all freely searchable with no hacking required.
Job adverts published on LinkedIn reveal internal technology stacks (e.g., Microsoft 365, Sage, SharePoint, Fortinet, Datto), allowing attackers to craft lures that reference the exact systems the target company uses, significantly increasing click-through rates.
Yes - within 20 minutes an attacker can establish director name, company structure, registered office, financial profile, likely email provider, technology stack, organizational hierarchy, recent hiring signals, and possible residential addresses using only legal, passive public sources.
SMB directors are vulnerable because they often lack organizational separation (dedicated finance teams, approval workflows, executive assistants) that larger companies have, making the director the sole approver for payments and system changes.
First fix the live record by changing the registered office address; then apply for address suppression through Companies House, though note that suppression doesn't erase copies already collected by data brokers.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers consistent, substantive claims about OSINT reconnaissance that a small business operator would find genuinely useful: Companies House API rates remain practical for attackers, electoral register opt-outs don't erase historical data brokers hold, job adverts leak technology stacks, DNS records expose email providers, and the critical insight that attackers correlate multiple public sources into a unified profile. The host avoids obvious platitudes and focuses on specific, actionable threat vectors. Minor padding exists in metaphorical language and legal disclaimers, but the core content is dense with concrete intelligence.
Before an attacker sends one phishing email, they may already know who runs your business. They may know the company structure, the directors, the registered office, the filing history, and the public contact routes.
Once personal data leaves the original source, it becomes digital glitter.
The episode takes a genuinely underexplored angle - not 'hackers are bad' but 'your own government transparency infrastructure is the attacker's reconnaissance platform' - which is fresher than standard cybersecurity fare. The framing of OSINT as 'information people leak by existing' and the systematic walkthrough of how Companies House, electoral registers, LinkedIn, and DNS records form a joined attacker profile is coherent and contrarian. However, the core OSINT concept itself is not new; the originality lies in making it tangible for SMBs rather than reinventing the wheel.
The UK has built one of the best open source intelligence databases in the world, and then called it Transparency.
Transparency without threat modeling becomes a weaponized phone book.
Noel Bradford is the primary voice and appears to be a practitioner in UK cybersecurity with hands-on experience advising SMBs, evidenced by his familiarity with specific regulatory frameworks (Companies House, electoral register opt-out mechanics) and his ability to construct realistic attack narratives. However, the transcript provides limited evidence of large-scale operational experience or notable institutional credentials. Corrine Jefferson is introduced but barely speaks (one short hypothetical response about a 20-minute profile build). The episode lacks a second high-caliber guest with contrasting perspective or greater seniority, limiting guest caliber to solid practitioner level rather than standout.
I'm Noel Bradford, and this is the first episode in a five-part series called The Open Book Problem.
A recently appointed director may be a better impersonation target. A newly changed registered office may suggest transition. A late filing may suggest pressure or poor administration.
The episode anchors claims in named systems (Companies House, electoral register, LinkedIn, Sage, Microsoft 365, Fortinet, Datto, Mimecast, etc.) and specific data points (600 API request limit per five minutes, MX records, SPF/DKIM/DMARC). It references realistic scenarios: a finance assistant posting about payroll, a recruiter listing specific tech stacks, abandoned VPN gateways. The five-step mitigation is concrete. However, the episode lacks dollar figures, specific attack success rates, or real-world case studies with names/outcomes. The depth is sufficient for threat modeling but not maximally granular.
The register is free to search. It exposes structured information. It also offers an API with a published limit of 600 requests within five minutes.
A recruiter advertising for an IT administrator with Microsoft 365, Fortinet, Datto, Sage, and SharePoint experience tells an attacker something.
Noel Bradford's delivery is clear and engaging, with strong narrative pacing that walks listeners through an attacker's reconnaissance flow. He employs productive metaphors ('digital glitter,' 'weaponized phone book') and self-aware humor ('I bought fingerless gloves specially'). However, conversational craft is limited by structure: this is largely a monologue with Corrine contributing one substantive response. There are no real follow-ups, disagreements, or challenging questions pushed back on. The host doesn't invite pushback on his transparency critique or stress-test his own arguments. The legal disclaimer section is extensive but somewhat disconnects from the main narrative flow.
That's why we drink tea like it's an incident response tool.
Social engineering isn't magic. It's admin with malice. That may be the cleanest definition we've had. No fluff.
Computed from the transcript - who did the talking, and the words that came up most.
They didn’t break in. They didn’t plant malware. They opened tabs, clicked links and joined the dots. In this episode we follow the quiet, methodical work of an attacker who builds a usable portrait of a UK small business director from nothing more than public records and a search box. It begins like a detective story and ends like a cautionary tale: Companies House entries, electoral data, LinkedIn posts, DNS records and job adverts become the clues that make fraud feel personal - because it is. Through the voices of Noel Bradford and Corrine Jefferson, the episode walks you through the attacker’s timeline: the first flick through Companies House to find directors and filing rhythms, the enrichment of that picture with open-register addresses and marketing data, the human-mapping on LinkedIn, and the technical fingerprint left in DNS, MX and certificate logs. Each step is ordinary, lawful and, crucially, assembled without a single hack. We make it concrete. In twenty minutes an attacker can produce a director profile, infer email providers, spot hiring signals that leak technology stacks, and spot behavioral seams to exploit.
Transcribed and scored by The B2B Podcast Index.
Before an attacker sends one phishing email, they may already know who runs your business. They may know the company structure, the directors, the registered office, the filing history, and the public contact routes. They may know where you work, who reports to you, which systems your staff mention, and which suppliers orbit your business. They may know your email provider from public mail records, your domain registrar from public infrastructure data, and your internal tools from job adverts.
Here's the bit that should make every UK business owner sit up. They didn't hack anything. They looked. They searched.
They clicked. They joined the dots. Then they wrote the sort of email that feels personal because frankly it is. That's passive reconnaissance.
No intrusion. No malware. No clever exploit. Just publicly available information used with hostile intent.
So today we're opening the cupboard that everyone politely pretends isn't full of petrol and matches. The UK has built one of the best open source intelligence databases in the world, and then called it Transparency. Welcome back to the Small Business Cybersecurity Guy. I'm Noel Bradford, and this is the first episode in a five-part series called The Open Book Problem.
This series is about OSINT, which means open source intelligence. In normal English, it means information people can gather without breaking into anything, which is lovely because apparently we built half the attacker research platform ourselves and then handed everyone a search box. I'm Corrine Jefferson. Today, I'm going to walk through what an attacker can learn about a typical UK small business director.
before they ever touch the organization directly. We'll stay with passive sources, public registers, public websites, public professional profiles, public technical records, public advertising. No hacking. No dark web drama.
No hoodie. No neon code falling down a screen like a budget science fiction fever dream. No dramatic keyboard hammering either. Shame.
I bought fingerless gloves specially. They aren't required. The point is simple. Before we talk about phishing emails, impersonation attacks, invoice fraud, help desk manipulation, account takeover, or executive targeting, we need to talk about the research phase.
Because attackers do research. Good attackers don't start with the payload, they start with the person. For a small business, OSINT isn't some spy film concept. It's the pile of information your business leaks just by existing.
Some of that information has to be public. Some of it's published for good reasons. Some of it's published by habit. Some of it's published because nobody ever asked why it was there.
And some of it's there because forms were designed by people who have never had to deal with a targeted fraud attempt at 4.45 on a Friday. Think about a director of a typical UK SMB. The attacker may start with the company name.
From there, they search Companies House. They can find the registered office, company number, incorporation date, active and resigned officers, persons with significant control, filing history, accounts, confirmation statements, charges, and sometimes historic address patterns. That isn't a breach. That's the public register doing what the public register was built to do.
Correct. Transparency has legitimate purposes. Credit checking, accountability, fraud prevention, supplier due diligence, journalism, and public trust. But transparency without threat modeling becomes a weaponized phone book.
The issue isn't that business data exists. The issue is that personal risk and business transparency have become tangled together. And when you run a small business, the line between business identity and personal identity can be thin enough to shave away. Step one is Companies House.
An attacker can search by company name or officer name. The register is free to search. It exposes structured information. It also offers an API with a published limit of 600 requests within five minutes.
So yes, there's a rate limit. No, that doesn't make the register magically useless to anyone doing reconnaissance. It remains practical for structured research. A human attacker investigating one business won't care about that limit.
A tool collecting targeted records can work within it. That distinction matters because critics love finding one technical correction and pretending the whole argument collapses. The correct statement is this. The company's house register is public, searchable, structured, and usable for reconnaissance.
Less punchy than screaming no rate limiting into the void, but annoyingly more accurate. From company's house, an attacker can establish who owns or controls the business. They can see changes over time. They can identify finance patterns.
They can identify whether the company looks distressed, growing, dormant, or recently restructured. They can also spot the boring stuff that makes scams work. Who the directors are. Whether the business has more than one trading name.
Whether the accounts show a firm big enough to pay an invoice but small enough to lack mature controls. Filing history helps build timeline context. A recently appointed director may be a better impersonation target. A newly changed registered office may suggest transition.
A late filing may suggest pressure or poor administration. And pressure is the con artist's favorite seasoning. Residential addresses are handled differently now from older filing patterns, but exposure still happens. Directors can use a service address.
However, many directors historically used home addresses as service addresses or registered offices. Some still do. If you used your home address as a company service address or registered office, you may need to take action. Don't assume it vanished because the law got a haircut.
Company's house allows people to apply to remove a home address from the public register in certain cases. The process depends on how the address was used. And if your active company still uses your home address as the registered office, the first job is usually to change the registered office. Otherwise, you're trying to mop the floor while the tap is still on.
Address suppression isn't instant magic. It doesn't erase every copy already taken by third parties. It doesn't force data brokers to forget what they previously collected. Which is the heart of the problem.
Once personal data leaves the original source, it becomes digital glitter. That's technically accurate, though unpleasant. Like most compliance meetings. Step two is residential identity enrichment.
Attackers and data brokers don't need one source. They correlate many sources. The electoral register has two forms. The full register has restricted uses.
The open register is available for general sale and voters can opt out of appearing on it. Let's pause on that. The open register isn't a dark web leak. It's a lawful product.
Correct. It can be bought by people, companies, and organizations. The opt-out controls whether someone appears on the open version. Which means a lot of people are exposed because they never understood the box, never saw the risk, or never realized the data would be repackaged.
A person who opts out of the open register may still appear in older datasets, broker products, marketing lists, archive records, or commercial identity graphs. Once again, digital glitter. Except now it knows where you live. For attacker reconnaissance, the goal is correlation.
If companies house provides a director name and business context, other sources help link that person to a residential identity, family context, local area, or lifestyle pattern. And before anyone writes in, yes, criminals can also buy stolen data. But today we're making the uglier point. They don't always need to.
Step three is LinkedIn. This is where the attacker builds the human map. Job titles, reporting lines, work anniversaries, colleague names, hiring activity, partners, suppliers, certifications, events attended, and casual comments all help. LinkedIn is incredible.
It's a place where people complain about being targeted while publishing a live organizational chart and a motivational quote over a sunset. For a legitimate salesperson, this information supports relationship building. For an attacker, it supports pretext building. Same method, different intent.
A finance assistant posting about passing a payroll course tells an attacker something. A director congratulating a new operations manager tells an attacker something. A recruiter advertising for an IT administrator with Microsoft 365, Fortinet, Datto, Sage, and SharePoint experience tells an attacker something. That last one isn't hypothetical.
Job adverts leak technology stacks all the time. They reveal platforms, vendors, technical debt, migration plans, and sometimes security priorities. We must have experience supporting our ancient server, our half-finished cloud migration, and the security tool we bought but never configured. Apply within.
I've seen worse. We all have. That's why we drink tea like it's an incident response tool. Step four is public infrastructure.
DNS records can show which provider handles email. MX records can point to Microsoft 365, Google Workspace, Proofpoint, Mimecast, Hornet Security, or other services. Again, not secret, not illegal, not even unusual. Website headers, certificate transparency logs, subdomains, SPF records, DMARC records, and public login portals can expose more context.
Attackers love abandoned portals, old VPN pages, forgotten remote access gateways, legacy mail systems, that one server nobody owns because Barry set it up in 2017 and Barry now runs a glamping site in Devon. Even when the exposed service is patched, the existence of the service informs the attacker. It shapes the lure. If they know you use Microsoft 365, the phishing email looks like Microsoft 365.
If they know you use Sage, the invoice fraud references Sage. If they know you're hiring for a SharePoint migration, the lure mentions document access. Personalization increases success rates. Oessent enables personalization.
Let's make this real. Corrine, if you had 20 minutes and a company name, what could you build? A basic director profile, company structure, registered office, active officers, persons with significant control, recent filings, likely size and financial profile, public website, contact routes, email pattern, mail provider, domain registrar, relevant technology clues, LinkedIn map, recent hiring signals, public social media activity, Possible residential exposure routes. In 20 minutes.
Less if the company has a noisy public footprint. And that's before paid broker databases, before stolen credentials, before dark web dumps, before leaked passwords, before a single user clicks anything. This is why the word sophisticated can mislead. The attack may feel sophisticated to the victim because it's well tailored.
The research may be basic. Social engineering isn't magic. It's admin with malice. That may be the cleanest definition we've had.
No fluff. can separate personal identity from business identity. Not perfectly, but better. They've role-based inboxes, comms teams, legal teams, finance controls, reception layers, executive assistants, and mature approval pads.
SMBs often don't. The director is the brand. The director is the approver. The director is the escalation path.
The director is sometimes the payroll backup because nobody else knows how the cursed thing works. That makes the director a high-value target, not because the business is famous, because the director can authorize change. Attackers don't need you to be famous, they need you to be useful. OSINT helps attackers decide whether you're useful.
And the uncomfortable part is this, a lot of that usefulness is exposed by systems the state either runs, mandates, licenses, or tolerates. I'm not arguing against corporate transparency. I'm not saying companies' house should vanish into a locked cupboard guarded by three civil servants and a suspicious badger. That would create other problems.
Exactly. Transparency matters. Fraud prevention matters. Credit checking matters.
Public accountability matters. But personal exposure isn't the same thing as business transparency. The risk grows when business registers, electoral data, broker databases, Social platforms, domain records, and job adverts become one joined profile. And when that joined profile helps criminals target real people, we need to stop pretending this is just the price of doing business.
The attacker doesn't see separate databases. The attacker sees a person. The regulator sees complexity. The attacker sees opportunity.
Guess which one moves faster? Step 1. Search your own company on Companies House. Check the registered office, officer details, persons with significant control, and filing history.
Don't delegate the first look. You need to see what the world sees. Step 2. Check whether any home address appears as a service address, correspondence address, or registered office address.
If it does, fix the live record first where needed, then look at removal or suppression routes. Step 3. Check whether you're on the open electoral register. If you're, opt out if personal exposure worries you.
And if you run a business from home, that should worry you. Step four, review LinkedIn. Remove unnecessary detail from profiles and job adverts. You can recruit without publishing your internal attack map.
Radical, I know. Step five, check your domain and email records. Confirm SPF, DKIM, and DMARC exist and make sense. Confirm old portals are gone.
This isn't paranoia. This is threat-informed housekeeping. Today, we've shown the open book problem from the attacker's side. A UK SMB director can be profiled quickly using public, legal, passive sources.
Next time, Mao Venn joins me to talk about the attacker's playbook. Social engineering isn't clever, it's repeatable, it's industrialized, and in the UK, the raw material is embarrassingly easy to find. The practical lesson isn't to disappear from the internet. That isn't realistic.
The practical lesson is to stop handing attackers the good cutlery and acting surprised when they come back for dinner. That metaphor became violent quickly. It's cybersecurity. Everything becomes violent eventually.
I'm Noel Bradford. This has been the Small Business Cybersecurity Guy. Go and search your own name. What did you find that you wish an attacker hadn't found first?
Right. Before we let you go completely, let's have a quick chat about the boring but necessary legal bits. Don't worry. I'll make this as painless as possible.
First up, and this is important, Everything we've said today represents our own personal opinions and experiences. These views are ours alone and don't represent any organisation we work for, any employers, advertisers, sponsors or anyone else who might be connected to the show. When we're giving you advice or sharing our thoughts, that's coming from us as individuals, not speaking on behalf of anyone else. Everything we've talked about today is for general guidance.
It's meant to point you in the right direction, but it absolutely shouldn't be treated as professional advice tailored specifically to your business. Your situation is unique. What works brilliantly for a Birmingham bakery might be completely useless for a Manchester marketing agency. We do our very best to keep everything accurate and current but let's be honest here.
The cyber security world moves faster than a caffeinated squirrel being chased up a tree by Movin's Jack Russell. Things can change between when we record and when you're listening so always double-check critical technical details with qualified professionals before you go making major changes to your systems. If we've mentioned any websites, products or services, we're giving you information, not necessarily giving them our seal of approval. We can't be responsible for what happens on their end or if things go sideways when you use them.
Some things we recommend might involve affiliate partnerships. We'll always flag those when they come up because transparency matters. Now, if you're dealing with serious cybersecurity incidents, actual data breaches, or gnarly legal compliance issues, please talk to proper professionals, rather than just relying on podcast advice. We're here to educate and help you understand the landscape, not to replace your security consultant, solicitor, or IT team.
This has been a Small Business Cybersecurity Guy production. Copyright 2025. All rights reserved.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.