See Your Own Digital Footprint Like an Investigator
Long before anyone attacks your systems, they look you up. Here is how to see what they would find, and reduce it calmly.
Step 1. Why Looking Yourself Up Is Defence, Not Paranoia
Anyone who targets you or your business starts with public information. They are not breaking in. They are reading what you have already published, often before they ever touch a system.
You cannot manage what you have not looked at. Most of what is out there was published by you, at some point, for a perfectly good reason. This is not spying on yourself. It is tidying up your own front garden so you know what a visitor would see.
The work here is calm and methodical. Look first. Decide second.
Step 2. The First Search Pass
Open a search engine and work through a short, systematic list. Do not fix anything yet. The point of this pass is to write down what you find.
- •Search your own name, and then your business name.
- •Search your email address inside quotation marks, so the search treats it as one exact phrase.
- •Search your phone number.
Note every result you did not expect. An old profile, a directory listing, a document with your name on it, a photo you had forgotten about.
Write the list on paper or in a separate note. You are building an inventory of your exposure, not solving it in the same sitting. Fixing comes later, once you can see the whole picture.
Step 3. What Your Photos Give Away
Photos taken on phones often carry hidden data called EXIF. It is written into the file by the camera and it can include the exact location where the photo was taken, plus the date and the time.
If you post a photo of a new purchase, or a picture from the school run, that hidden data can reveal where you are and when you were there. The image looks harmless. The file underneath is not.
Practical defences that take a few minutes:
- •Turn off location tagging in your phone's camera app. This stops new photos carrying the data at all.
- •Before posting publicly, strip the location from the image. Many phones and social apps will remove it for you if you choose that option.
- •Run a reverse image search on a few of your own photos, to see where they already appear.
Step 4. Check Whether Your Details Are In A Breach
When a company you hold an account with gets breached, your email address and possibly a password end up in lists that get traded online. This happens to well run companies as well as careless ones. It is not a sign that you did anything wrong.
Use a reputable breach check service such as Have I Been Pwned to look up each of your email addresses. It will tell you which breaches your address appears in, and roughly when.
If you appear in one:
- 1.Change that password everywhere you had reused it, starting with your email.
- 2.Turn on two-factor authentication for your important accounts, so a stolen password alone is not enough.
The breach itself is not the real danger. Password reuse is. One old password sitting on twenty accounts is the thing that turns a small breach into a bad week.
Step 5. Find The Accounts You Forgot You Had
Most people have signed up to dozens of services over the years and forgotten them. An old forum account. A retired email address still forwarding. A shopping site from 2015. These are sitting there, often with an old password that you have since reused elsewhere.
A simple way to find them is to search your email inbox for words like welcome, verify, or registered. Each result is a service you once signed up to.
- •Close anything you no longer use, rather than leaving it dormant.
- •For anything you keep, reset the password to something unique.
A forgotten account is an unlocked door that nobody is watching. Nobody at that old service is looking after it, and neither are you.
Step 6. Your Business Exposure Specifically
A business publishes far more than an individual, usually on purpose. That is fine, as long as you know what is visible. The things that stand out to someone looking at you:
- •Staff names and roles, taken from a team page, which give a target list of real people.
- •An email address format that makes guessing easy, once you know one person's address.
- •Company documents published publicly, sometimes with more inside them than intended.
- •Job adverts, which reveal exactly what software and systems you run.
- •Social media, which can show the office layout and who sits where.
Practical reductions you can make this month:
- •Publish a general contact address, such as info@, rather than individual ones, where the workflow allows it.
- •Talk with staff about what they post while identifiable as staff of the business.
- •Check what documents are publicly downloadable from your own website, and remove anything that need not be there.
Step 7. A Six-Monthly Clean-Up Routine
This is not a one-off task. It is gardening. Set a reminder twice a year to repeat steps two through five, because services get breached and old accounts resurface over time.
The goal is not to vanish from the internet. For a person that is difficult, and for a business it is neither possible nor desirable. The goal is to know what is visible, and to have chosen it deliberately.
A calm hour twice a year keeps you ahead of almost everyone who would look you up.
Tips
- •Anyone can look you up, so look yourself up first.
- •Location data in photos is the single most common accidental leak.
- •A reused password in an old breach is still a danger today.
- •Forgotten accounts are the easiest thing to fix and the most commonly ignored.
- •Your business team page and job adverts tell an attacker a great deal.
- •This is gardening, not a one-time job.
Need More Help?
StarCaller Academy offers 1-to-1 sessions to help you with any of these topics and more.