How to Audit Your Own OSINT Exposure: A Step-by-Step Guide for UK Directors
This week’s podcast series has covered the problem in considerable detail. What attackers see, how they use it, why the regulatory response has been inadequate, and what the data removal industry does and does not deliver.
This guide covers what you actually do. In sequence. With time estimates. Starting today.
Before You Start: The Two Rules
Rule one: fix the source before cleaning the copies. If your home address is still appearing on a live Companies House record, a data broker’s removal of their copy is a temporary fix. The source will republish it at the next data refresh.
Rule two: document everything. Date, broker name, what you submitted, what response you received, and what changed. Without a record, you lose the thread. The data broker machine relies on you losing the thread.
Phase 1: Search Yourself as an Attacker Would (30 minutes)
Open a browser in incognito mode. You want neutral results, not your personalised search history.
Search each of the following in sequence and document what appears in the first three pages:
- Your full name
- Your full name plus company name
- Your full name plus town or area
- Your company name
- Your company registered number
- Your home address if you have reason to believe it has been published
Go to the Companies House search at find-and-update.company-information.service.gov.uk. Search your company. Open every officer record. Look at the address field for each director listing, including historical ones, and for the registered office history.
Look at the persons with significant control register. Check whether addresses appear there.
Take screenshots of everything. Date-stamp them. This is your baseline.
Time estimate: 30 minutes.
Phase 2: Fix the Upstream Sources (60 minutes across several days)
Companies House
If your home address appears in any active record as a service address, correspondence address, or registered office, the first job is to change it. Update the registered office to a non-residential address. Update your service address to a registered agent, accountant, or formal service address provider.
Once the live record shows a non-residential address, you can apply for suppression of historical records. Under changes introduced from 27 January 2025 under the Economic Crime and Corporate Transparency Act 2023, directors can now apply to remove home addresses from historical filings where those addresses were used as the company’s registered office. The application costs £30. Use Companies House form SR01 or the online service.
Allow several weeks for processing. The result is that historical filings show a service address rather than your home address. Copies already taken by data brokers are not affected by this suppression.
Open electoral register
Contact your local council in writing, by phone, or via the online registration service. Request removal from the open register. This does not remove you from the full electoral register and does not affect your right to vote. It removes you from the version that is commercially available for sale to data brokers and marketing companies.
Time estimate for both: phone calls and form completion take under 30 minutes. Processing happens over days to weeks.
Domain registration
Check your domain’s WHOIS record. If it shows personal contact details, enable WHOIS privacy through your domain registrar. Most registrars provide this free or for a small annual fee.
Phase 3: Priority Erasure Requests (90 minutes)
From your Phase 1 research, you now know which people-search sites and data broker listings appear prominently for your name and address. These are your priority targets.
For each one:
Submit a subject access request first. Under UK GDPR, you are entitled to know what data the organisation holds, where it came from, and who has received it. Use the ICO’s template SAR letter. The organisation has one month to respond.
Once you have the response, submit an erasure request under Article 17 UK GDPR. Request deletion of your personal data. Provide the reason. For a director with legitimate personal safety and fraud risk concerns, the balancing test should weigh in your favour.
Track each request in a spreadsheet with these columns: Broker name, SAR sent date, SAR deadline (one month), SAR response received, Erasure request sent date, Erasure deadline, Erasure response, Data removed, Recheck date (set 90 days from removal confirmation).
If a broker misses the one-month deadline, send a chaser. If they refuse without adequate grounds, report to the ICO. Document the complaint reference number.
Time estimate: 15 minutes per broker for initial requests. Plan for 6-10 priority brokers in the first pass.
Phase 4: LinkedIn and Job Advert Hygiene (60 minutes)
Read your LinkedIn profile as an attacker would. Ask: does this tell someone which systems we use, who reports to whom, which projects are current, which suppliers we rely on, and when the director is likely to be travelling?
For each piece of unnecessary information, remove it or generalise it. Your role description does not need to name specific platforms. Your posts do not need to confirm upcoming travel or major projects.
Review your company’s last three to five job adverts. Look specifically for:
- Named software platforms (Sage, Xero, Microsoft 365, Salesforce, Datto, Fortinet, etc.)
- Migration projects (“currently migrating from X to Y”)
- Security tooling references (“experience with our SIEM” or “knowledge of our endpoint protection”)
- Reporting lines (“reporting to the Finance Director”)
Rewrite any adverts currently live to describe the role requirements without the technology inventory. Update your recruitment templates so future adverts do the same.
Time estimate: 60 minutes.
Phase 5: Technical Records (30 minutes)
Check your domain’s DNS records using a free tool such as MXToolbox or Dig. Confirm:
- SPF record exists and is correctly formatted
- DKIM record exists for your email domain
- DMARC record exists and is set to at least quarantine or reject policy, not p=none monitoring mode
Check whether old subdomains or login portals remain accessible. If your business previously used a VPN portal, remote desktop gateway, or old webmail interface, confirm whether it is still accessible from outside the network. If it is accessible but not in use, it should be decommissioned.
Time estimate: 30 minutes.
The 90-Day Recheck
Set a calendar reminder for 90 days from today. At that point, repeat Phase 1. Check whether removed data has reappeared. Check whether new information has been added to broker profiles. Submit fresh erasure requests for any reappearances.
Data brokers refresh their databases from upstream sources. Removal is not permanent. The upstream sources you fixed in Phase 2 reduce the rate of reappearance. They do not eliminate it.
How to Turn This Into a Competitive Advantage
For MSPs and IT advisers, this guide is a client engagement framework. Walk a client through Phase 1 together. The reaction to seeing their own profile assembled from public sources in real time is consistently motivating. That moment converts the abstract risk into a concrete action list.
The five-phase audit can be offered as a standalone engagement or as part of an annual security review. Most clients will not have done this themselves. Being the adviser who surfaced it is a differentiator.
How to Sell This to Your Board
The five-phase audit total time is roughly three hours across two weeks. The financial cost is £30 for Companies House suppression if applicable, and potentially nothing else.
Present this to your board as a risk reduction activity with a known cost and a measurable outcome: the before and after state of your Phase 1 search results. That is a simple governance conversation. Assign ownership. Set a completion date. Review at 90 days.
What to Do This Week
- Complete Phase 1 today. Take screenshots. Build the exposure list.
- Start Phase 2 this week. The Companies House and electoral register actions have the longest processing times. Start them first.
- Submit Phase 3 SAR letters to the top five broker results from Phase 1. Set calendar reminders for the one-month response deadline.
- Schedule Phase 4 for this weekend. LinkedIn and job advert hygiene takes one focused hour.
- Book a Phase 5 technical check for next week.