What somebody can learn before they ever contact you
Targeted social engineering can involve substantial research before the first message arrives. The information often comes from ordinary public sources.
The sources are not unusual
Company websites identify senior staff. Tender documents identify suppliers. Conference programmes show who will be where. Professional profiles explain roles and responsibilities. Public documents contain contact details. Old pages remain searchable long after their original purpose has ended.
None of these things is automatically dangerous. They become more useful when somebody starts connecting them.
The picture matters more than the individual detail
Imagine someone learns that:
- You approve supplier payments.
- Your assistant’s name is public.
- Your organisation is currently working with a particular contractor.
- You will be speaking at an event outside the office on Thursday morning.
Those facts may come from four completely different websites. Together, they provide context for a message that would have been much harder to make convincing otherwise.
That is the difference between finding information and analysing exposure.
Visibility is not automatically a problem
It would be unrealistic to tell executives to stop attending events. Companies need websites. Professionals need networks. Organisations need to announce projects.
The objective is not disappearance. The useful questions are:
- What needs to be public?
- What no longer needs to be public?
- What information creates risk only because of what can be combined with it?
- And where should organisational processes assume that an outsider already knows certain details?
Start by looking at combinations
If you want to examine your own footprint, look beyond a simple name search. Look at:
- What your organisation says about you
- What public documents contain your details
- Which relationships are visible
- What events and travel are announced
- What contact information has accumulated online
- What somebody can infer by combining those sources
The important part is the connection.
That is also why assessing yourself can be difficult. You already know the context behind your own information. A stranger does not. They simply see what the sources allow them to infer.
Where an Exposure Assessment fits
An Exposure Assessment approaches the problem from outside. We document relevant public information, connect related findings and explain what the combined picture could reasonably make possible.
No passwords or private account access are required.
Filed under exposure, public information, social engineering

Written by
Teofilus Shaduka
Founder, Principia Works.
Teofilus works across open-source intelligence, cybersecurity awareness and digital exposure research.