Companies House recently came under scrutiny in March of this year due to a major vulnerability being exposed that gave unauthorised access to the private dashboard of the five million registered companies on its site. This sat unnoticed for five months, potentially exposing directors’ home addresses, dates of birth, and email addresses, making it possible for would-be attackers to change sensitive details.
While access to Companies House requires an account, on the more serious end of the risk spectrum, this could have opened the possibility of impersonation of company directors and, therefore, targeted phishing attacks. Additionally, any fraudulent appointments or removals of directors could trigger reputation risk or legal exposure.
Although the vulnerability was not as severe as originally thought, many organisations have company data that’s effectively filed and forgotten, so this is a timely reminder to review where critical information sits and what would happen if a key system failed.
How did Companies House respond
Companies House became aware of the security issue on Friday 13 March and closed the WebFiling system, which was at fault, while investigations were underway. The service came back online on Monday 16 March, after independent testing. The conclusion was that the vulnerability was caused by an update made by Companies House in October 2025.
The agency clarified that passwords weren’t compromised, no identity data, such as passport information, was accessed, and no existing filed documents, such as accounts statements, were able to be changed. Companies House has reported the incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC).
What should businesses do now?
Businesses don’t need to panic, but they do need to act. Visit Companies House, review your company record, and confirm that key details such as directors, addresses and filings are accurate.
If anything looks amiss, act quickly: correct the records, notify advisers, and consider additional steps such as monitoring or legal review if there’s evidence of misuse.
Lessons for broader third-party risks
While the incident made national headlines, the direct risk appears limited based on current information. Still, it’s a reminder that these vulnerabilities can occur anywhere and sometimes have more serious consequences.
More broadly, this should prompt organisations to think about where their data sits with third parties, not just Companies House. Most firms have ‘file and forget’ systems, platforms you set up once and then barely touch, but they still hold valuable corporate and personal information.
In cases where a vulnerability leads to actual misuse of directors’ data, that is when a cyber insurance policy may be triggered.
Most SMEs rely on third‑party platforms that store valuable data long after setup. Now is the time to map those systems and ensure they’re properly governed.
A practical checklist for SMEs
-
Map where your data lives: List all third‑party platforms holding company, director, contact, financial or employee data (including CRMs, payroll, HR, and regulatory systems).
-
Ask “What if this system were compromised?”: For each platform, assess what data it holds, what an attacker could do with it, and who would be affected.
-
Check how quickly you’d notice a problem: Would you know if a director was added, an address changed, or logins were misused? Assign ownership for each account and set alerts where possible.
-
Build regular checks into governance: Review high‑impact registries and platforms quarterly or bi‑annually.
-
Understand where cyber insurance fits: Cyber insurance doesn’t respond to a vulnerability alone, but can respond if data is misused or confidentiality breached as a result.
Why this matters for SMEs
Smaller firms often lack in‑house legal or technical resources to respond quickly when something goes wrong. Access to embedded legal and risk management support, for example, through a cyber insurance policy, can help bridge that gap, providing both proactive guidance and crisis response capability.
As Duane Folkard, Lead Cyber Underwriter at rrelentless, explains, cyber insurance brokers have a key role to play not just in arranging cover, but in helping SMEs understand and manage their ongoing exposure. “The strongest policies on the market will increasingly be those that go beyond indemnity, providing practical tools, expert guidance and integrated legal or technical support that helps clients prevent issues before they arise.”
Looking ahead
While the Companies House vulnerability has had minimal impact overall, it serves as a reminder to SMEs to remain vigilant. As data and cloud systems underpin more of our daily work, understanding and managing digital exposure becomes critical. The best defence often starts with awareness, backed by accessible education, practical tools and trusted advice.
By Joshua Walsh, Information Security Practitioner at rradar


