The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Small Business Cyber Security Guy
The Small Business Cyber Security Guy artwork

The Open Book Problem 5: Closing it with Practical Defences for Small Businesses

The Small Business Cyber Security Guy · 2026-07-27 · 21 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density16 / 20
Originality13 / 20
Guest Caliber0 / 20
Specificity & Evidence14 / 20
Conversational Craft12 / 20

Noel Bradford closes the Open Book Problem series with practical defences tailored to SMB operators and directors. Rather than abstract threat discussion, the episode ranks OSINT exposure by actual attack likelihood: identity compromise and financial authorization abuse rank highest, followed by technical targeting information, timing/pressure details, and background noise. The core argument is that not all exposure matters equally, and panic prevents prioritization. Bradford delivers a structured 10-point audit checklist covering Companies House records, Electoral Register opt-outs, LinkedIn and job advert hygiene, domain security records (SPF, DKIM, DMARC, certificate transparency), data broker removal, and hardened verification processes for sensitive changes. The episode also addresses policy reform needed around data broker transparency, regulatory enforcement, and the misalignment between system-created exposure and individual-absorbed risk. For SMB operators, the takeaway is actionable: a 30-day plan starting with discovery week, followed by Companies House fixes, social platform cleanup, and process hardening - with clear ownership assignment preventing "rituals of concern followed by nothing." Bradford also critiques phrases like "it's public anyway" and "we're too small to target," reframing the conversation toward operational security rather than compliance theatre.

Key takeaways

  • →Prioritize removing exposure that enables identity compromise and financial authorization abuse (director addresses, finance contacts, approval patterns) before chasing obscure data broker entries.
  • →Implement out-of-band confirmation for all sensitive business changes (bank details, MFA resets, payroll changes, supplier onboarding) as the single most important control for SMB fraud prevention.
  • →Assign clear ownership of exposure reduction and quarterly review at board level - without named accountability, data cleanup becomes a ritual that never happens.
  • →Opt out of the open electoral register, audit Companies House for home addresses used as service addresses, and remove old portals and forgotten remote access routes before investing in paid removal services.
  • →Treat exposed OSINT data as operational security risk by asking what public information would let an attacker convincingly request sensitive actions, then fix the weak points in verification processes.

Topics in this episode

Cyber Essentials frameworkOSINT exposure risk rankingCompanies House records and home address suppressionElectoral Register opt-out proceduresData broker removal requestsLinkedIn and job advert hygieneSPF, DKIM, DMARC email authenticationCertificate transparency logsOut-of-band verification for sensitive changes30-day exposure remediation plan

Questions this episode answers

What personal data about business directors poses the highest risk from OSINT exposure?

Director identity, personal addresses, personal phone numbers, finance contacts, reporting lines, and internal approval patterns rank highest because they help attackers impersonate legitimate requests for money, access, or account resets.

How should UK small business owners remove their home address from Companies House records?

Check Companies House for home addresses used as registered office, service, or correspondence addresses; fix live records first, then apply for removal where eligible; keep records of what you changed and when.

What is the open electoral register and should business owners opt out?

The open electoral register is the searchable version of the full electoral register; business owners should opt out because it's a primary source data brokers use to build and sell director profiles.

Why shouldn't small businesses pay for data broker removal before fixing official sources?

Public records like Companies House and the electoral register are the upstream sources that data brokers harvest from; if you don't fix those, brokers will simply refresh and repopulate their databases.

What domain security records should small businesses check to reduce technical targeting exposure?

Review SPF, DKIM, DMARC records, old subdomains, exposed portals, forgotten remote access routes, and certificate transparency logs; remove any old portals or forgotten services nobody owns.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

16 / 20

The episode packs substantive, operationally useful guidance into 21 minutes: a clear risk-prioritization framework (4 tiers), a 10-point audit checklist, a 30-day implementation sequence, and specific process hardening advice (out-of-band verification, incident response first-hour planning). The host avoids platitudes by naming concrete exposures (company house records, electoral register, certificate transparency) and explicitly rejecting panic in favor of prioritization. Minimal filler; almost every section delivers actionable claims.

Highest priority. Information that supports identity compromise or financial authorization abuse.
Removing data helps. Process stops the attack when data still leaks.

Originality

13 / 20

The framing of OSINT exposure as a structural policy problem rather than purely a technical one is relatively fresh for SMB cybersecurity content. The four-tier risk taxonomy (identity/finance → technical → timing → background) is practical and contrarian to blanket privacy panic. However, the underlying tactics (LinkedIn cleanup, domain hardening, MFA) are standard security practice; the originality lies in sequencing and governance framing rather than novel insight into attack mechanics.

The open book problem is a political choice presented as an administrative necessity.
The system creates exposure. The individual absorbs risk. The remedy is fragmented.

Guest Caliber

0 / 20

This is a solo host episode with no guest. The host, Noel Bradford of 'Small Business Cybersecurity Guy,' appears to be a practitioner-focused educator, but without a co-interlocutor or guest expert, there is no guest caliber to evaluate. The dimension cannot meaningfully apply.

I'm Noel Bradford, and this is the final episode in our five-part series, The Open Book Problem.

Specificity & Evidence

14 / 20

The episode grounds advice in named systems (Companies House, electoral register, LinkedIn, certificate transparency, SPF/DKIM/DMARC) and specific exposure types (supplier names, firewall vendor references, old portals). The 30-day plan includes week-by-week sequencing. However, the episode lacks: named real-world breaches or incidents, quantified data on how often removals reappear, metrics on data broker prevalence, or dollar-value impact estimates. The questions posed in the middle ('how many UK directors know...') acknowledge data gaps rather than fill them.

Step two check company's house look for home addresses used as service addresses Correspondence addresses or registered office addresses fix live records first then apply for removal where eligible.
Check SPF, DKIME, DMARC, old subdomains, exposed portals, forgotten remote access routes and certificate transparency records.

Conversational Craft

12 / 20

Solo host format limits conversational dynamic; no pushback, guest challenge, or dialectic tension. The host does employ rhetorical devices (brief thought-partner moments like 'Correct. Fix the exposure that enables action.') that simulate debate, but these are scripted monologue beats, not genuine follow-up. Strong on structure and clarity of argument, weak on the genuine questioning and productive disagreement that characterize top conversational craft. The legal disclaimer at the end is necessary but padding.

Correct. Fix the exposure that enables action.
Beautiful, boring, useful, the holy trinity of grown-up security.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

exposure20data19public18open13personal12risk12broker10records9doesn8small8stop8step8book7problem7plan7access7

Episode notes

The final episode in the five-part Open Book series delivers a practical action plan for UK small business directors facing public data exposure. Noel Bradford and the SBCSG team rank OSINT risks by real attack potential, from identity compromise to technical targeting. Graham Falkner provides a 30-day implementation plan covering Companies House corrections, electoral register opt-outs, data broker removal, and process hardening. Mauven MacLeod examines the policy gaps that leave individuals absorbing systemic risk, while Lucy Harper summarises outstanding accountability questions for regulators and government. The episode includes a board-level conversation framework, guidance on when to seek help, and a tabletop exercise for testing verification processes. This is not about vanishing from the internet. It is about reducing avoidable harm, prioritising exposure that enables fraud, and turning regulatory frustration into collective pressure for structural reform.

Full transcript

21 min

Transcribed and scored by The B2B Podcast Index.

The open book problem is structural. Public registers expose business context. Data brokers amplify personal exposure. Attackers convert that exposure into trust.

Regulators haven't forced enough structural change. But that doesn't mean small businesses are helpless. Not every exposure matters equally. Not every fix costs money.

Not every policy failure has to remain permanent. And not every question has been answered. So today, we stop admiring the problem. We fix what we can, name what others must fix, and make the open book a little less open.

Business Cybersecurity Guy. I'm Noel Bradford, and this is the final episode in our five-part series, The Open Book Problem. To catch anyone diving into this episode without listening to the whole series, we started with public exposure. Then we looked at the attacker's playbook.

Then we looked at data brokers and the regulator. Then we looked at paid removal services. Today is the practical close. I'll rank OSINT exposure by real attack risk.

I'll give a realistic action plan for UK SMB directors. I'll cover the policy and trade association angle. I'll summarise the accountability questions that remain. And I'll try to behave like a responsible adult, which regular listeners will recognise as an experimental format.

We remain cautiously pessimistic. Not every public exposure deserves the same level of concern. This matters because panic is useless. Prioritization is useful.

Highest priority. Information that supports identity compromise or financial authorization abuse. That includes director identity, finance contacts, reporting lines, personal addresses, personal phone numbers, current suppliers, and internal approval patterns. Because those details help someone sound legitimate when asking for money, access, or a reset.

Second priority, information that supports technical targeting. That includes exposed login portals, email provider records, outdated service banners, remote access systems, public cloud naming patterns, and job adverts that reveal security tooling. That's where the IT housekeeping starts. Third priority, information that supports timing and pressure, travel posts, event attendance, staff absence, mergers, major projects, recruitment campaigns, new supplier announcements, and public complaints.

Those details let an attacker decide when to strike. Fourth priority, general background noise, old bios, harmless marketing copy, broad sector membership, and public content that doesn't identify people, systems, or processes may be lower risk. So don't waste a week deleting harmless fluff while your home address and finance process are sitting in the window. Correct.

Fix the exposure that enables action. Step one audit what's public search your company name trading names director names senior staff names Registered address domain names and common email formats. Do it like an attacker would Calmly methodically no drama Step two check company's house look for home addresses used as service addresses Correspondence addresses or registered office addresses fix live records first then apply for removal where eligible. Keep records of what you changed and when.

Step three, check the electoral register position. Make sure you understand the difference between the full register and the open register. Opt out of the open register if you don't want your details sold from that source. Which, for most business owners, is a sentence that answers itself.

Step four, clean up obvious broker and people search entries. Start with the ones ranking in search results. Use access and erase your rights. Track every request.

Don't chase 50 obscure brokers before removing the first page results that shout your address into Google. Step five. Review LinkedIn and job adverts. Remove unnecessary supplier names, technology stack detail, reporting lines, screenshots, customer references and timing clues.

You can still hire a systems administrator without publishing a love letter to your firewall vendor. Step 6. Review domain and email security records. Check SPF, DKIME, DMARC, old subdomains, exposed portals, forgotten remote access routes and certificate transparency records.

If you find an old portal nobody owns, don't admire it. Kill it. Step 7. Harden verification.

New bank details, password resets, MFA changes, payroll changes, supplier changes and urgent payment requests need out-of-band confirmation through known routes. This is the single most important control for many SMBs. It can't solve the whole problem. Because you can't personally regulate a data broker market with a spreadsheet and righteous fury.

Although some listeners may try. A properly regulated UK data broker market would be more transparent, more accountable and easier for individuals to challenge. It should be clear who holds data, where it came from, who receives it, which lawful basis applies and how removal or objection is handled. And those claims should be auditable.

Companies Howes also needs continued reform around personal exposure. Business transparency shouldn't default to unnecessary personal risk. And we need to stop treating cyber risk, fraud risk and privacy risk as separate boxes owned by separate committees that never meet unless there are biscuits. That's inelegant, but correct.

SMB owners can ask trade bodies, local business groups, chambers, accountants and sector associations to raise this. individual complaint is weak, collective pressure is stronger. If your trade body isn't talking about director exposure, ask why. The investigation leaves several questions.

First, how many UK directors know whether their home address has ever appeared on public records? Second, how many understand the company's house removal process? Third, how many know whether they appear on the open electoral register? Fourth, how many data brokers hold director profiles built from public and commercial sources?

Fifth, how often does supposedly removed data reappear after refresh from upstream sources? Sixth, how often has the regulator tested broker claims at scale since UK GDPR came into force? These aren't academic questions. They map directly to fraud, harassment, social engineering and personal safety.

The accountability gap is this. The system creates exposure. The individual absorbs risk. The remedy is fragmented.

The enforcement record doesn't yet show sufficient structural correction. That's the open book problem. Here's the checklist. 1.

Search your name and company 2. Check company's house 3. Fix public address exposure 4. Opt out of the open electoral register, if appropriate 5.

Remove obvious broker listings 6. Review LinkedIn and job adverts 7. Check domain and email records 8. Remove old portals and forgotten services 9.

Lock down help desk and payment verifications 10. Repeat quarterly. Beautiful, boring, useful, the holy trinity of grown-up security. Add one point.

Assign ownership. Yes. If nobody owns it, it becomes a ritual of concern followed by nothing. Put it in the calendar.

Give it to a named person. Review the findings at management level. And treat exposure as a business risk, not an IT oddity. Don't try to vanish completely.

That's unrealistic. Don't pay for tools before fixing upstream sources. Don't publish supplier and system detail casually Don't assume legal rights enforce themselves And don't tell yourself you're too small to be targeted Attackers don't need you to be famous They need you to be useful, exposed and busy That's often enough The open book problem is a political choice presented as an administrative necessity. We chose transparency.

Fine, transparency has value. But we also chose to tolerate personal exposure, commercial harvesting, broker opacity, weak practical remedies and a regulatory response that hasn't changed enough. The consequences land on individuals. Directors, sole traders, trustees, volunteers, small business owners.

people who didn't sign up to become searchable targets in someone else's enrichment engine. Reform doesn't require secrecy, it requires proportionality. Publish what's necessary, protect what creates avoidable harm. Give people routes that work without requiring a second job in privacy administration.

Exactly, because if the system creates the risk, the system shouldn't dump the cleanup on the person whose data it exposed. Let's turn the checklist into a 30-day plan. Good. People need sequence, not a guilt buffet.

Week 1. Discover. Search names, companies, directors, domains, job adverts and public profiles. Capture screenshots.

Build the exposure list. Tag each finding by risk. Identity, finance, technical, timing or background. Week 2.

Fix official sources. Companies house live records first. Open electoral register opt-out Domain privacy Obvious incorrect directory entries Keep. Evidence Date each change Week 3 Reduce social and commercial exposure LinkedIn clean-up Job advert clean-up Broker requests People search removals.

Also brief staff Explain why details are being removed Otherwise someone will lovingly republish them next Tuesday Week 4 Hardened processes Payment changes MFA resets, password resets, supplier onboarding, emergency exceptions, director requests. That final week matters most. Removing data helps. Process stops the attack when data still leaks.

small business. Board level doesn't mean grand, it means accountable. If there are two directors and a dog, congratulations. You've a board and a non-executive spaniel.

The spaniel may ask better questions than some boards. Depends who has biscuits. The questions are simple. What personal data about key people is public?

What business processes could be abused using that data? Who owns reducing the risk? How often is it reviewed? Add incident response.

If impersonation succeeds, who decides, who contacts the bank, who preserves evidence, who informs affected parties, and who reports where required. Small firms don't need a 50-page plan. They need a clear first-hour plan. Because when money leaves the account, nobody wants to discover the plan lives in someone's head and that someone is on a train with no signal.

We should mention Cyber Essentials because this audience knows I will. Cyber Essentials doesn't solve OSINT exposure by itself. Correct. It isn't a privacy removal scheme.

It isn't a data broker audit. It won't make LinkedIn stop being LinkedIn. But the mindset helps. Know your assets.

Reduce exposure. Control access. Patch systems. Use MFA.

Remove unnecessary services. It also gives small businesses a governance frame. Exactly. Use cyber essentials as the floor, then add the human and data exposure controls we've discussed.

The key isn't badges, it's behaviour. Badges without behaviour are compliance theatre, and nobody needs another performance of that miserable little play. Get help if personal safety is involved, if harassment has started, if fraud has occurred, or if your exposure is complex. Also get help if you find exposed remote access, unknown portals, weak email authentication, or evidence that accounts may already be compromised.

If personal data has been misused, preserve evidence before cleaning everything up. And if the issue affects several businesses in a sector, raise it collectively. Trade bodies have more leverage than isolated directors. Don't wait for perfect certainty.

If money moved, accounts changed, or someone impersonated a director, treat it as an incident. Call the bank, preserve messages, lock accounts, review access, notify where needed, then learn from it. The worst incident plan is hoping the criminal feels bad and sends the money back. The policy ask isn't complicated.

Reduce unnecessary personal exposure in public registers. Make suppression routes clearer. Improve public awareness. Create stronger broker transparency duties.

Enforce repeated non-compliance. Measure outcomes publicly. Also publish better data on complaints, investigations, broker audits, enforcement themes, and reappearance problems. Include threat modelling.

Ask how published data can be used for fraud, stalking, coercion and cyber-enabled crime. And make it easy for normal people. If the process needs a consultant, the process is broken. That's the line.

If exercising a basic right requires unusual confidence, legal literacy, spare time and stubbornness, then the right isn't working for ordinary people. Government doesn't need to choose between transparency and safety. It needs to design for both. We also need to kill a few phrases.

Stop saying it's public anyway. Public doesn't mean harmless. Stop saying nobody would target us. Attackers target usefulness, not fame.

Stop saying our staff would spot that. Maybe they would, maybe they wouldn't. Process shouldn't depend on heroic suspicion. Stop saying the regulator would act if it mattered.

Regulatory action can lag harm by years. And stop saying we'll look at that later. Later is where preventable incidents go to breed. Grim, but efficient.

Here's a useful exercise for listeners. Pick one sensitive action. A bank detail change, a payroll change, an MFA reset, or a supplier payment. Then ask what public information would help an attacker request that action convincingly.

Ask who would receive the request. Ask what pressure would work. Ask which channel would be trusted. Ask what evidence would remain afterwards.

Then fix the weak points. That's a one-hour exercise. You can do it this week. Repeat it for each critical process.

This is how OSINT risk becomes operational security. Exactly. Not panic. Not theater.

Work. That's the open-book problem. Five episodes, one argument. UK small businesses aren't just exposed by criminals.

They're exposed by public data policy, commercial reuse, and regulatory hesitation. The next step is evidence. Keep records. Ask questions.

Share findings. The policy argument needs business voices, not just privacy campaigners. The threat argument needs prioritisation, not panic. The action plan needs ownership, repetition, and verification.

So here's the question, if your business is an open book today, which page are you closing first? Right, before we let you go completely, let's have a quick chat about the boring but necessary legal bits. Don't worry, I'll make this as painless as possible. First up, and this is important, everything we've said today represents our own personal opinions and experiences.

These views are ours alone and don't represent any organisation we work for, any employers, advertisers, sponsors, or anyone else who might be connected to the show. When we're giving you advice or sharing our thoughts, that's coming from us as individuals, not speaking on behalf of anyone else. Everything we've talked about today is for general guidance. It's meant to point you in the right direction, but it absolutely shouldn't be treated as professional advice tailored specifically to your business.

Your situation is unique. What works brilliantly for a Birmingham bakery might be completely useless for a Manchester marketing agency. We do our very best to keep everything accurate and current but let's be honest here. The cyber security world moves faster than a caffeinated squirrel being chased up a tree by Marvin's Jack Russell.

Things can change between when we record and when you're listening so always double-check critical technical details with qualified professionals before you go making major changes to your systems. If we've mentioned any websites, products or services, we're giving you information, not necessarily giving them our seal of approval. We can't be responsible for what happens on their end or if things go sideways when you use them. Some things we recommend might involve affiliate partnerships.

We'll always flag those when they come up because transparency matters. Now, if you're dealing with serious cybersecurity incidents, actual data breaches, or gnarly legal compliance issues, please talk to proper professionals, rather than just relying on podcast advice. We're here to educate and help you understand the landscape, not to replace your security consultant, solicitor, or IT team. This has been a Small Business Cybersecurity Guy production, copyright 2025, all rights reserved.

More from The Small Business Cyber Security Guy

All episodes →
  • The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap90 / 100
  • The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency79 / 100
  • Erased from the Web: The Fight Over a Child's Moment58 / 100
  • Birthday Audit: Brutal Lessons for Small Business Cybersecurity64 / 100
  • If Your MSP Says ‘All Good’, Can They Prove It?89 / 100
All The Small Business Cyber Security Guy episodes →