Cybersecurity & Corporate Governance  ·  9 August 2026

Fifteen Quid and Your Org Chart

Ransomware crews don't need to breach you to find out who can approve a payment. Statutory disclosure, LinkedIn, and your own website already told them.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

New research from Zscaler's ThreatLabz has quietly rewritten the ransomware threat model, and most organisations haven't noticed yet.

The assumption behind a decade of security awareness training is that the CEO is the prize: spear-phish the top of the org chart, compromise the account with the widest blast radius, done. ThreatLabz's data says otherwise. Tracking a single ransomware campaign across 334 organisations and 351 victims over the course of a month, the researchers found that nearly two-thirds of those compromised held manager-level titles or above; the average victim was a 46-year-old Gen Xer; and three-quarters worked in accounting and finance, sales, operations, HR, or marketing, with half in the industrial or IT sectors.

This isn't opportunistic phishing. Zscaler's own account of the campaign describes attackers combining data from already-compromised systems with publicly available information to map reporting lines, then targeting the employees best placed to influence whether a ransom gets paid. Zscaler has a name for what they're actually after: not technical privilege, but "business privilege", the access that comes bundled with a job title rather than an admin console. A manager doesn't need root to be valuable; they need the authority to approve an invoice, sign off a supplier contract, or move data between systems.

The uncomfortable question this raises for anyone running a company is simple: how much of that reporting-line map did you build for them, for free, before they ever sent an email?


The statutory disclosure

Start with the part nobody chooses. Isle of Man Companies Registry records are public, and for older 1931 Act companies, the ones carrying the "C" suffix on their registration number, the disclosure runs deeper than most directors realise. The annual return, a paid filing, lists not just directors but shareholders and shareholding changes over time. Pull the full document history on a company incorporated decades ago and, for the price of a round of drinks, you get a complete institutional timeline: every director appointed and resigned, every change of company secretary, every annual return filed, going back as far as incorporation.

That's not a snapshot. It's a genealogy. For an attacker doing the reporting-line mapping ThreatLabz describes, officer tenure is a signal in its own right: a director who's held post for twenty years likely knows exactly where the operational authority sits and would smell a pretext call a mile off; someone appointed eight months ago is a softer target for a well-crafted impersonation attempt. Fifteen pounds and a public record buys that distinction.

2006 Act companies fare somewhat better on paper, shareholders aren't disclosed at all, and directors have been filed separately from the annual return since April 2025, but the officer history is still there for anyone who asks, and beneficial ownership has its own semi-public side door: the Companies Registry has described a company's nominated officer as a matter of public record, available to anyone on request, even though the underlying beneficial ownership database itself is restricted to competent authorities and obliged entities.

None of this is a flaw in the registry. It's the registry doing exactly what a statutory public record is supposed to do. The flaw is in assuming "publicly available for £15" and "practically inaccessible" are the same thing.


The voluntary professional disclosure

The registry is compulsory. LinkedIn isn't, and finance leadership has embraced it anyway. Personal branding has become close to a professional expectation for anyone in an operational or financial leadership role, and the platform reflects it at scale: LinkedIn carries an estimated 63 million self-identified decision-makers and 10 million C-level executives among its members, a pool of exactly the job titles ThreatLabz's "business privilege" model describes.

That's not a caveat to the Zscaler findings; it's the supply chain for them. An attacker mapping reporting lines no longer needs to social-engineer an org chart out of anyone. Title, tenure, employer, headshot, and often a running commentary on travel and out-of-office periods are sitting in a searchable, indexable, entirely voluntary public profile. The 46-year-old Gen X manager in the ThreatLabz data didn't need to be found through a breach; there's a reasonable chance they were findable through a search bar.


The one nobody's forcing anyone to publish

The sharpest layer is the one with no statutory basis and no individual choice behind it at all: the corporate "about us" page. Plenty of company sites run a full staff listing from managing director down to the search clerk, published because it reads as approachable and transparent, good PR, in other words, with no security review anywhere near the sign-off. Marketing owns that page. Security typically never sees it.

Where the registry disclosure is unavoidable and the LinkedIn profile is an individual's own call, the staff directory is the company voluntarily assembling the attacker's reporting-line diagram on their own website, then linking to it from the homepage.


The trade-off nobody's adjudicating

Put the three layers together and a pattern emerges that has nothing to do with technical security posture. Security spend concentrates on hardening privileged accounts: admin rights, VPN access, MFA on anything touching production. Almost none of it touches "business privilege", the ordinary authority of the person who approves payments, holds supplier relationships, or signs off HR records. That's precisely the layer ThreatLabz says attackers have started targeting, and precisely the layer that PR, marketing, and voluntary professional branding are actively making easier to map, for free, with no equivalent scrutiny.

This is a governance gap, not a technology one. Nobody is adjudicating the trade-off between "we look approachable and transparent" and "we've published a targeting list." PR wins by default because nobody in most organisations is empowered, or inclined, to argue the other side.


A test worth running

Before the next round of phishing-awareness training gets scheduled, a cheaper exercise: pull up your own company website, your own Companies Registry entry, and the LinkedIn profiles of anyone who can approve a wire transfer or sign off a contract. Ask whether a stranger with no inside access could build an accurate reporting-line map and identify the person most likely to move money under pressure, using only what you've already made public.

If the answer is yes, the encryption event is the part everyone notices. The reconnaissance was free, and it happened months before anyone sent an email.


What to actually do about it

None of this argues for corporate secrecy; a company that discloses nothing looks evasive, and statutory disclosure isn't optional regardless. The fix isn't less transparency, it's better-governed transparency, and it comes down to three concrete controls.

Sanitise sensitive titles. Anyone with payment approval, procurement, or vendor authority doesn't need that authority spelled out in a public-facing job title. "Finance Professional" attracts no less business than "Treasury Approver", and gives an attacker one less confirmed data point when building a target profile.

Move authority off reporting lines entirely. The actual exploit in the "business privilege" model isn't that someone found the org chart; it's that knowing the org chart is enough to get a payment moved. Mandatory out-of-band verification for payment changes and contract sign-off means reporting-line knowledge alone can't authorise anything, regardless of how good the reconnaissance was.

Put security in the room before PR publishes. Org charts, team directories, and vendor partnership announcements should clear a security review before they go on the website, the same way a press release clears legal. Right now that review typically doesn't exist; marketing signs off alone, and nobody weighs the trade-off this piece has been describing until after the fact.

None of these controls require withdrawing from public life or reversing years of "approachable and transparent" branding. They require treating the org chart as a document with a threat model, not just a marketing asset.


Sources


Questions about this analysis, or interested in working with The Haunted Lighthouse?
consultancy@haunted.lighthouse.co.im

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy—with particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly—or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.