Next Week on The Open Book Problem: The Attacker's Playbook
This week we opened The Open Book Problem.
Episode 1 with Corrine Jefferson established the baseline: what passive reconnaissance actually looks like when someone targets a UK SMB director using entirely free, entirely legal, public sources. Companies House. The open electoral register. LinkedIn. Job adverts. Domain records.
The conclusion was not particularly comfortable. A detailed director profile takes under twenty minutes to assemble. The UK’s data publication obligations give attackers a structural head start.
The week’s companion content extended the argument. Mauven’s Wednesday piece looked at how the Data (Use and Access) Act 2025 has changed the legal landscape for UK data brokers and what that means for the individuals whose data they process. Graham’s Thursday guide turned the abstract risk into a five-phase practical audit anyone can run this afternoon. Lucy’s Friday investigation went into the documented record of what brokers actually hold, what the ICO found about it in 2020, and what the Experian tribunal outcome means for the industry.
Saturday’s opinion made the political point directly: Companies House is a policy choice. The cost of that choice is carried by directors, not by the government that built the system and mandates the filings.
What Is Coming Next Week
Episode 2 of The Open Book Problem drops on Monday.
Mauven MacLeod joins me for The Attacker’s Playbook.
We go beyond the data gathered in episode one and into the method. How do attackers turn a public profile into a targeted attack? What does the social engineering chain actually look like? Selection. Mapping. Pretext. Delivery. Pressure.
We look at why UK SMBs face a structural disadvantage compared to their equivalents in some other European economies, where business register data is more restricted and commercial reuse is less permissive.
We examine what the Scattered Spider attacks on major UK retailers in 2025 reveal about the shape of modern social engineering, specifically the use of public information to manipulate help desk and identity support processes.
And we address the thing most awareness training misses entirely: the call that sounds right. Why voice attacks work. Why pressure defeats instinct. Why your help desk may be the most exposed single control in your organisation.
The Week Ahead
Monday: Episode 2 launches with the full podcast and companion article.
Tuesday: Deep-dive on the social engineering chain, how criminals industrialise targeted attacks using UK public data.
Wednesday: Mauven’s reaction piece on why UK business culture overshares on professional networks and what the intelligence tradecraft perspective reveals about the risk.
Thursday: Graham’s practical guide to hardening verification processes for the specific requests social engineers target: payment changes, MFA resets, password resets, supplier changes.
Friday: Lucy continues her investigation, this time into how the Companies House address suppression service actually works in practice and how many directors have used it.
Saturday: The opinion on awareness training. Most of it is wrong. Here is why.
This Week’s Reading
If you missed anything from this week:
Tuesday’s deep-dive covered the full OSINT exposure picture for UK directors, from Companies House through to domain records and job advert intelligence.
Wednesday’s analysis from Mauven examined the DUAA’s implications for data broker legitimate interests claims and the comparative enforcement gap between UK and EU regulators.
Thursday’s practical guide from Graham gave the five-phase OSINT audit with specific steps, time estimates, and a 90-day recheck schedule.
Friday’s investigation from Lucy covered the documented ICO enforcement record against UK data brokers, the Experian tribunal outcome, and what questions the public record still cannot answer.
Saturday’s opinion argued that Companies House is a policy failure that places the remediation cost on the directors whose data it exposes.
Episode 2 on Monday.
| Source | Article |
|---|---|
| Companies House | Companies House search |
| ICO | Electoral register opt-out guidance |
| NCSC | Defending against social engineering |
| GOV.UK | Data (Use and Access) Act 2025 guidance |
| Action Fraud | Mandate fraud guidance |