Copy article

Companies House breach is a warning for automated compliance: identity data is now an attack surface

ended 18. March 2026

Companies House is treating its latest security incident as a contained breach. Businesses should treat it as a preview of the next compliance failure mode.

The uncomfortable truth is that we have turned identity and company data into infrastructure. It underpins onboarding, credit, procurement checks, and automated due diligence. Once that data is widely relied on, it becomes a high-value target and a single point of failure.

This is where automation quietly makes risk worse. Firms are building workflows that assume registries are authoritative, up to date, and tamper-resistant. That assumption is rarely tested. When the underlying source is compromised, every downstream model, rule, and decision inherits the error at speed.

The fix is not more dashboards. It is provenance and redundancy: the ability to verify a claim across sources, detect anomalies, and fall back to manual checks when signals diverge. If your compliance stack cannot say where a decision came from and what it trusted, it is not defensible.

We'd like your views:

  • Which company and identity signals are too brittle to automate against today?
  • What is the minimum viable provenance trail for automated due diligence?
  • Should critical registries provide cryptographic proofs of integrity, not just PDFs and APIs?
  • How should SMEs balance speed with verification when vendors push "automated compliance"?
  • When a source of record is breached, who owns the downstream liability: the registry, the vendor, or the user firm?

Update on Companies House WebFiling security issue - GOV.UK

2 responses from the Newspage community

Copy all

Star Quote
Copy

The Companies House incident is a reminder that ‘source of record’ does not mean ‘source of truth’. Once registries are wired into onboarding, credit and procurement at scale, a breach becomes a systemic risk, not an IT footnote.

The brittle signals are the ones we treat as authoritative without cross checks: director identities, filing history, registered addresses, beneficial ownership flags, and ‘good standing’ status. They are easy to ingest and tempting to automate against, but hard to verify when an attacker can alter, replay or poison records.

Minimum viable provenance for automated due diligence is: what data you pulled, when, from which endpoint, with which version of your rules or model, and which human approved the outcome. Add redundancy: verify key claims against at least one independent source, and trigger a manual review when sources disagree.

SMEs should demand one feature from “automated compliance” vendors: explainability plus a safe fallback, not just speed.
Copy

Small businesses are being sold automated compliance as the solution to everything, right to work checks, background screening, andcompany verification, because it's fast and cheap. But when Companies House gets breached, guess who carries the liability? Not the registry. Not the software vendor. The small business does. You're the one facing the fine if you've onboarded someone based on compromised data. We've been told to trust the system, automate the checks, and move fast. Now we're finding out the system isn't trustworthy, and there's no fallback. Most SMEs don't have the resources to cross-check multiple sources or build redundancy into their processes. They're just trying to stay compliant without hiring a compliance team. So when a source of record is breached, who owns the downstream liability? In practice, it lands on the user firm every single time. Automated compliance only works if the data is reliable. When it's not, small businesses are left holding the risk and the bill