peter bassill · operator
$ man peter.bassill

Twenty-eight years inside the perimeter.

The home page is the elevator. This page is the corridor afterwards — what the hands have actually been doing, why I keep them on the keys when the title says I shouldn't, and what the chair in the boardroom is for.

en_GB · since 1998 Pager · first carried 1998 Boardroom · first walked into 2006 Both · still, deliberately
$ ps -ef | grep peter
01 / Off the consoles

Things I haven't delegated.

Most CEOs in this corner of the industry have politely stopped touching the consoles. Here is the short, honest list of what I still do myself — and why.

PRODUCTION PHP
I still write the platform.
Not "I review the PRs." I write the more interesting commits, on a Saturday, with the radio on. If a CEO can't read their own product, they're guessing in board meetings — and the board can usually tell.
UBUNTU · APACHE · MYSQL
I harden the boxes myself.
fail2ban, ufw, the AppArmor profile that broke twice this year. I keep doing it because when an engineer flags a kernel-level oddity, I'd like to know what they're talking about without a translator in the room.
INCIDENT BRIDGES
I stand at the back, not the front.
When the page goes out, the tier-three lead runs the bridge. I'm there to take the call from the client's chair, the regulator, and the journalist who hasn't been told yet — so the responders don't have to.
THE BORING HALF
I read the regulator's letters.
ICO correspondence, DORA mappings, NIS2 transposition notes. Nobody enjoys it. Outsourcing it to a law firm is how you end up with a controls register that looks tidy and doesn't match the network.

THE GAP — between the room where the kettle's on and the room where the chair's asking is where most cyber security goes wrong.

$ ls ~/off-duty/
02 / Off the consoles

What fills the time the keyboard doesn't.

Each of these has taught me something I still use at work — but mostly I do them because I like them.

Motorsport
Telemetry is a SIEM with louder sensors.

I race endurance GT in the Pro/Am class around the world. The 12 and 24 hour races combine endurance, strategy, trust and deep team working. Half-hour after the chequered flag, when the data download lands and you work out what actually happened versus what it felt like in the car, is the part I came for. Same shape as a post-incident review; better fun and catering.

Aerobatics
When the aeroplane is upside down, you don't argue with the checklist.

Standard aerobatic rating · a Pitts S-2A out of Old Buckenham. Half the discipline is in the briefing room: knowing the recovery from every attitude before you go anywhere near the runway. The other half is doing precisely what you briefed. A lot of planning, a lot of practice and a reliance on the team both on the ground and in the air.

Sailing
Weather doesn't read your risk register.

Yachtmaster offshore · short-handed racing and cruising out of the Solent and Gibraltar depending on the time of year. Everything I know about redundancy I was taught by the boat that ran out of it forty miles offshore in a force seven. Belt, braces, second belt.

Fire & smoke
Low and slow. There's no shortcut to twelve hours.

Brisket, beef ribs, picanha. A ceramic kamado for clean smoke; a stone-built oven I made myself for the heavy lifting. The recipe is patience, an air probe, and the willingness to trust the cooker more than the clock. Multiple championships and reserves won over the years.

$ grep -r ":" credentials.txt
03 / Credentials

The letters after the name.

Listed in the order they're useful, not the order they were earned. Each one is here because the work asked for it, not the other way round.

PROFESSIONAL
FBCS · Chartered IT Professional

Fellow of the British Computer Society, royal-chartered. The one credential that says "a body of peers thinks this person should be allowed to keep doing this." It travels well in rooms that distrust acronyms.

TECHNICAL · OFFENSIVE
OSCP · CRT · G.PEN

The ones you sit a lab for, not a multiple-choice. They're proof I can still find my way around someone else's network when nobody is helping. I keep them current because the day I can't is the day I should stop signing off pentests.

TECHNICAL · DEFENSIVE
CISSP · CISM · GCIA

CISSP is necessary because clients ask for it; don't read too much into it on its own. CISM and GCIA are the ones I actually use — programme-level governance and packet-level analysis, which is most of what a CISO's week is.

REGULATORY
GDPR · ICO · DORA · NIS2

The unglamorous half of the job. Not certifications — working familiarity, earned by writing the responses, sitting across from the regulator, and watching what gets accepted and what gets sent back.

EXPERIENCE
200+ breach investigations

Led from page-out to resolution. Some were quiet. A handful made the papers. The figure isn't a trophy — it's the reason a lot of the advice on this site is shorter than people expect.

If you've read this far, you probably have a specific question rather than a general one. Ask it directly — the contact channels on the home page are the same ones I read every morning.

view my cv  ·  writing  ·  talks  ·  contact