How Attackers See Your Organization Before You Do
By the time a phishing email lands in your CFO's inbox, the attacker already knows her name, her direct reports, the project she's stressed about, the conference she attended last month, and the exact format your finance team uses for invoice approvals.
She hasn't been targeted. She's been studied.
This is the part of an attack nobody talks about. No malware. No exploits. No alerts to trigger. Just a quiet, patient attacker building a picture of your organization using nothing more than what you've already published to the world.
The Setup
Every breach you've read about in the news started somewhere far less dramatic than the headline suggested. Long before the ransomware note appeared or the data leaked, someone sat at a screen and did homework.
This phase is called reconnaissance, and it is the most undervalued and least defended stage of an intrusion. Security teams pour resources into detection, response, and recovery. Almost nobody invests in understanding what an attacker can already see about them — for free, in plain sight, without doing anything technically illegal.
The result is a quiet asymmetry. Attackers know more about your organization than your own employees do. And the closer you look at why, the more uncomfortable it gets.
What Everyone Assumed
The conventional belief is that reconnaissance requires technical skill — port scans, vulnerability probes, network mapping. Things firewalls would catch.
The assumption is that if no alarms are firing, no one is watching.
The reality is the opposite. Modern reconnaissance is overwhelmingly passive. It happens on LinkedIn, on GitHub, on company websites, in earnings calls, in vendor case studies, in conference talks, in employee Twitter posts, and in the metadata of public documents. None of it touches your network. None of it triggers anything. And by the time the attacker decides to engage, they've already mapped your organization in detail your own IT team couldn't replicate in a week.
What Actually Happens
A real reconnaissance phase looks like a researcher doing investigative journalism — only the subject is your company.
It usually begins with LinkedIn. The attacker pulls a list of every employee, sorted by department. Within an hour they have the complete reporting structure, identify who manages money, who handles vendor relationships, who has admin access to systems based on job titles, and who recently joined and is therefore unfamiliar with internal norms. New hires are gold to attackers — they're less likely to question unusual requests because they don't yet know what's normal.
Then comes the technical layer, still passive. Public certificate transparency logs reveal every subdomain your company has ever issued an SSL cert for, including staging environments and forgotten internal tools. GitHub commits made by your engineers — even on personal accounts — sometimes leak internal repository names, deployment pipelines, and occasionally credentials that were never meant to ship. Job postings reveal the exact technology stack you run, the security tools you use, and the gaps you're trying to hire your way out of. A careless line in a job description like "experience with [specific EDR product] required" tells an attacker exactly what they need to bypass.
The picture sharpens further with social context. Earnings calls reveal financial pressure points and upcoming initiatives. Vendor case studies confirm which third parties have access to your systems. Conference talks given by your engineers reveal architecture decisions in detail. Employee tweets reveal travel schedules — which means the CFO who normally approves wires is on a flight and unreachable, which means a fake email asking for an urgent transfer feels plausible. Even photos posted from the office can leak badge designs, screen contents, and the layout of secure areas.
By the time the attacker is ready to act, they aren't guessing. They're operating from a dossier — and the entire dossier was assembled from things you and your employees made public yourselves.
Decoded
The mental model worth carrying out of this issue is simple: your attack surface is not just your network. It includes everything your organization has ever made discoverable, by anyone, to anyone, in any format. Most security programs treat the perimeter as the place where defenses begin. The truth is the perimeter begins at your public profile.
The shift that matters is treating reconnaissance as a defensible phase rather than an unavoidable one. Attackers have a methodology — they look for specific things in specific places. That methodology can be reversed. Knowing what an attacker would find about you, and removing or quietly correcting it before they ever look, is one of the highest-leverage activities a security team can do. Almost no one does it consistently. The ones who do are noticeably harder to hit.
The hard part isn't building defenses. It's recognizing that defense begins long before anything technical happens — in the choices your organization makes about what to publish, what to brag about, and what to leave lying around in public.
Tell me honestly: if a stranger spent two hours researching your organization online tonight, what would they walk away knowing that you'd rather they didn't? Hit reply — I read every one.
Think clearly.
— DJ Brar SKBSEC | SKB Decoded www.skbsec.com