Entrepreneur Handbook
  • Entrepreneurship
  • Funding & Finance
  • Growth
  • Operations
  • People
  • Technology
No Result
View All Result
Entrepreneur Handbook
  • Entrepreneurship
  • Funding & Finance
  • Growth
  • Operations
  • People
  • Technology
No Result
View All Result
  • Entrepreneurship
  • Funding & Finance
  • Growth
  • Operations
  • People
  • Technology
Home Technology Cybersecurity

Companies House vulnerability: Learnings for SMEs about third-party risks

By Editorial Team · Published Apr 21, 2026 · Included in Cybersecurity · Data Protection
EmailFacebookWhatsAppX (Twitter)LinkedInTelegram
A persons hand holding a large umbrella above, blocking the rain, protecting from the rain as a metaphor for insurance can protect you or your business

Table of Contents

  • How did Companies House respond
  • What should businesses do now?
  • Lessons for broader third-party risks
  • A practical checklist for SMEs
  • Why this matters for SMEs
  • Looking ahead

Companies House recently came under scrutiny in March of this year due to a major vulnerability being exposed that gave unauthorised access to the private dashboard of the five million registered companies on its site. This sat unnoticed for five months, potentially exposing directors’ home addresses, dates of birth, and email addresses, making it possible for would-be attackers to change sensitive details.

Related Posts

Business Insurance

Media Liability Insurance - Coverage, Risks and Costs

10+ min read
Entrepreneurship

The Investment Confidence Dilemma Holding Back British SMEs

10+ min read

While access to Companies House requires an account, on the more serious end of the risk spectrum, this could have opened the possibility of impersonation of company directors and, therefore, targeted phishing attacks. Additionally, any fraudulent appointments or removals of directors could trigger reputation risk or legal exposure.

Although the vulnerability was not as severe as originally thought, many organisations have company data that’s effectively filed and forgotten, so this is a timely reminder to review where critical information sits and what would happen if a key system failed.

How did Companies House respond

Companies House became aware of the security issue on Friday 13 March and closed the WebFiling system, which was at fault, while investigations were underway. The service came back online on Monday 16 March, after independent testing. The conclusion was that the vulnerability was caused by an update made by Companies House in October 2025.

The agency clarified that passwords weren’t compromised, no identity data, such as passport information, was accessed, and no existing filed documents, such as accounts statements, were able to be changed. Companies House has reported the incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC).

What should businesses do now?

Businesses don’t need to panic, but they do need to act. Visit Companies House, review your company record, and confirm that key details such as directors, addresses and filings are accurate.

If anything looks amiss, act quickly: correct the records, notify advisers, and consider additional steps such as monitoring or legal review if there’s evidence of misuse.

Lessons for broader third-party risks

While the incident made national headlines, the direct risk appears limited based on current information. Still, it’s a reminder that these vulnerabilities can occur anywhere and sometimes have more serious consequences.

More broadly, this should prompt organisations to think about where their data sits with third parties, not just Companies House. Most firms have ‘file and forget’ systems, platforms you set up once and then barely touch, but they still hold valuable corporate and personal information.

In cases where a vulnerability leads to actual misuse of directors’ data, that is when a cyber insurance policy may be triggered.

Most SMEs rely on third‑party platforms that store valuable data long after setup. Now is the time to map those systems and ensure they’re properly governed.

A practical checklist for SMEs

  • Map where your data lives: List all third‑party platforms holding company, director, contact, financial or employee data (including CRMs, payroll, HR, and regulatory systems).

  • Ask “What if this system were compromised?”: For each platform, assess what data it holds, what an attacker could do with it, and who would be affected.

  • Check how quickly you’d notice a problem: Would you know if a director was added, an address changed, or logins were misused? Assign ownership for each account and set alerts where possible.

  • Build regular checks into governance: Review high‑impact registries and platforms quarterly or bi‑annually.

  • Understand where cyber insurance fits: Cyber insurance doesn’t respond to a vulnerability alone, but can respond if data is misused or confidentiality breached as a result.

Why this matters for SMEs

Smaller firms often lack in‑house legal or technical resources to respond quickly when something goes wrong. Access to embedded legal and risk management support, for example, through a cyber insurance policy, can help bridge that gap, providing both proactive guidance and crisis response capability.

As Duane Folkard, Lead Cyber Underwriter at rrelentless, explains, cyber insurance brokers have a key role to play not just in arranging cover, but in helping SMEs understand and manage their ongoing exposure. “The strongest policies on the market will increasingly be those that go beyond indemnity, providing practical tools, expert guidance and integrated legal or technical support that helps clients prevent issues before they arise.”

Looking ahead

While the Companies House vulnerability has had minimal impact overall, it serves as a reminder to SMEs to remain vigilant. As data and cloud systems underpin more of our daily work, understanding and managing digital exposure becomes critical. The best defence often starts with awareness, backed by accessible education, practical tools and trusted advice.

By Joshua Walsh, Information Security Practitioner at rradar

Written by Editorial Team
See Author Bio
# Data Protection
EmailFacebookWhatsAppX (Twitter)LinkedInTelegram

Related Posts

Business Insurance

Media Liability Insurance - Coverage, Risks and Costs

10+ min read
Entrepreneurship

The Investment Confidence Dilemma Holding Back British SMEs

10+ min read

Contents

  • How did Companies House respond
  • What should businesses do now?
  • Lessons for broader third-party risks
  • A practical checklist for SMEs
  • Why this matters for SMEs
  • Looking ahead

Related Posts

Business Insurance

Media Liability Insurance - Coverage, Risks and Costs

10+ min read
Entrepreneurship

The Investment Confidence Dilemma Holding Back British SMEs

10+ min read
EH Dress Logo

Supporting UK entrepreneurs, startups and small businesses with practical information and resources since 2013. Using this site constitutes acceptance of our Terms of Service and Privacy Policy. To adjust preferences click .

Sections

  • Entrepreneurship
  • Funding & Finance
  • Growth
  • Operations
  • People
  • Technology
  • Markets
  • News

Company

  • Advertise
  • Sitemap
  • Contact Us

Follow Us

Copyright © 2013 - 2026 Entrepreneur Handbook Ltd. All rights reserved. Registered offices at 20-22 Wenlock Road, London, N1 7GU, United Kingdom.

  • Entrepreneurship
  • Funding & Finance
  • Growth
  • Operations
  • People
  • Technology