Companies House breach is a warning for automated compliance: identity data is now an attack surface
Companies House is treating its latest security incident as a contained breach. Businesses should treat it as a preview of the next compliance failure mode.
The uncomfortable truth is that we have turned identity and company data into infrastructure. It underpins onboarding, credit, procurement checks, and automated due diligence. Once that data is widely relied on, it becomes a high-value target and a single point of failure.
This is where automation quietly makes risk worse. Firms are building workflows that assume registries are authoritative, up to date, and tamper-resistant. That assumption is rarely tested. When the underlying source is compromised, every downstream model, rule, and decision inherits the error at speed.
The fix is not more dashboards. It is provenance and redundancy: the ability to verify a claim across sources, detect anomalies, and fall back to manual checks when signals diverge. If your compliance stack cannot say where a decision came from and what it trusted, it is not defensible.
We'd like your views:
- Which company and identity signals are too brittle to automate against today?
- What is the minimum viable provenance trail for automated due diligence?
- Should critical registries provide cryptographic proofs of integrity, not just PDFs and APIs?
- How should SMEs balance speed with verification when vendors push "automated compliance"?
- When a source of record is breached, who owns the downstream liability: the registry, the vendor, or the user firm?


