05/28/2026
Before most targeted attacks happen, someone did research.
Your business website tells an attacker a significant amount of useful information before they take any other action. The names of your staff, useful for crafting convincing phishing emails that reference real colleagues. The email format your business uses, if one employee's email is [email protected], every other employee's email can be inferred. The software tools and platforms you use, often visible in case studies, job postings, or footer credits.
Your LinkedIn page tells them your org chart. Job postings tell them what software your team uses and what your internal processes look like. A mention of specific tools in a blog post tells an attacker exactly which platforms to target for a credential attack.
This is called open-source intelligence gathering (OSINT), and it requires no hacking. It is entirely legal research done on publicly available information, and it happens before any attack begins.
The reason this matters for small businesses is that it shifts who gets targeted from random to deliberate. A business that has publicly available information about its staff, its tools, and its processes provides an attacker with a head start.
This does not mean scrubbing your website or hiding your team. It means being thoughtful about what operational details are publicly visible and making sure the security controls are in place to make that research less useful.