peter bassill · operator
peter@hardened:~$ whoami

Peter
Bassill.

I'm a British cyber security operator at board level — the CEO who still writes the code, the advisor who has actually carried the pager. Kernel to chair, in the same conversation.

CEO · UK Cyber Defence CREST · European Council CREST · IR Pan Europe en_GB · since 1998 Status · available for advisory
$ cat /var/log/now
00 / Now

What's on the desk this week.

No smoke. The brief says transparency, so here is the actual state of things. Updated when something changes, not when a content calendar says so.

RUNNING
UK Cyber Defence, year one.
Six months in from the Hedgehog merger. Still rationalising the stack and the rota.
WRITING
An guide to AI.
A simple but necessary guide to AI for boards.
READING
A business owners guide to Privacy.
I wrote it 5 years ago, and now im going to renew it.
SHIPPING
A PHP rewrite of an old triage tool.
Yes, PHP. No, I won't apologise for it. Ubuntu, Apache, MySQL, fail2ban.

LAST UPDATED — 2026-06-21 · drift since update: 0 days

$ man peter.bassill
01 / About

Operator. At the board. Both at once.

Most people pick a side: the hands or the room. I've spent twenty-eight years refusing to.

I run a small British cyber defence company. I still write the production PHP, harden the Ubuntu boxes, and configure the Apache and MySQL myself. I also sit on the CREST European Council and CREST IR Pan Europe, where the people in the room have read the same incident reports I have, and we argue about what to do next.

The combination is rarer than it sounds. Most CEOs at this end of the industry have stopped touching the consoles. Most engineers good enough to run the consoles haven't sat in a regulator's office. I do both, deliberately, because the gap between those rooms is where most cyber security goes wrong.

If you're a board chair, I can brief you in plain English on Tuesday. If you're a CISO, I can argue with you about detection engineering on Wednesday. If you're a tier-three responder, I can stand at the back of the bridge on Thursday and not get in your way. The brand is just the shape of that.

2026CREST · IR Pan Europe (advisory)third year on the body.
2025CEO · UK Cyber Defenceformed Nov 2025 from the Hedgehog merger.
2023CREST · IR Pan Europe (joined)incident response, Europe-wide remit.
2022CREST · European Council (joined)the accrediting body for much of the industry.
Hedgehog Security · Founder / CEOtwenty years on the consoles before this.
1998First production box, first pagera Sun box in a basement.
$ ls -l /etc/roles
02 / Work

Three positions. One job.

An executive role, two advisory ones. They share an audience and a remit: keep European cyber defence honest, and keep practitioners in the room.

EXECUTIVE

Chief Executive Officer

UK Cyber Defence

Day-to-day operator of a British cyber defence firm formed from the November 2025 merger of Hedgehog Security and UK Cyber Defence. Strategy, delivery, and yes — still the one writing the more interesting bits of the platform.

SINCE — 2025·11
ADVISORY

European Council Member

CREST

One of the seats on the European Council of the body that accredits much of the industry. Policy, standards, and arguing on behalf of operators who'd rather be on the console than in the room.

SINCE — 2022
ADVISORY

IR Pan Europe

CREST

Working with the pan-European incident response scheme — the shape of how IR is practised, accredited, and held to a standard across borders. Less ribbon-cutting; more rota and runbook.

SINCE — 2023
$ ls writing/ -t | head
03 / Writing

Some things I've written down.

Notes from the desk, not thought leadership. Specifics over slogans.

2026·06·21 Least certain exactly where it has to decide: the Home Office age guesser A facial age-estimation system whose error margin is widest at the one line it exists to draw is not a decision aid. Setting the immigration politics aside, it fails on accuracy and privacy alone. 6 min 2026·06·20 Prinz Eugen: the ransomware that takes your newest work first A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown. 15 min 2026·06·20 The week in cyber — 15 to 19 June 2026 The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account. 6 min 2026·06·19 Breached without being touched: the Klue attack and the case for digital sovereignty Two security firms were caught in a data theft this week without an attacker going anywhere near their systems. The way in was a sales tool they had connected to their CRM themselves. This is the clearest argument I have for owning your stack that I have seen in a while. 8 min 2026·06·19 The criminals have a product team now: The Gentlemen and the industrialised EDR-killer A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model. 6 min 2026·06·13 The week in cyber — 8 to 12 June 2026 Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other. 6 min

all posts  ·  subscribe by email  ·  rss

$ cat talks.tsv
04 / Talks

Where I've spoken. Where I'm speaking next.

I keep this list short on purpose. I'd rather give one good talk a quarter than four mediocre ones.

$ contact --advisory

If you need someone who's actually done the thing.

I take on a small number of advisory engagements at any given time — board briefings, IR-readiness work, the occasional NED conversation. Not retainers I won't use. Not panels I haven't read for.

replies within 2 working days · en_GB · pgp on request · no agency intros
$ finger peter
05 / Contact

Direct channels.

No contact form funnels, no calendly. If you'd write to a colleague, write the same way to me — or use the form below.

Email is fastest. If your message includes who you are, what you'd like, and a rough sense of when, you will get a useful answer within two working days.

EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox