peter bassill · operator
Policy 2026·09·10 22 min

What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow

From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.

Read full article →
$ tail -f /var/log/feed
Policy 2026·09·08 9 min

No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works

Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.

governance · policy · board · regulation · ciso
Threats 2026·09·08 15 min

Trezor, ShipMonk, and the deletion that never happened

Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances.

breach · supply chain · privacy · governance · board
Opinion 2026·09·06 6 min

The unmarkable exam: the child-safety law no one is allowed to grade

The Children's Commissioner told a Lords committee that children say the Online Safety Act has made "absolutely no difference" — and that she can't judge it, because Ofcom won't release the platforms' risk assessments. A law built to be unmarkable has already told you something.

children · online safety · accountability · plain english · series
Opinion 2026·09·04 6 min

The week in cyber — 31 August to 4 September 2026

Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached.

weekly · governance · ned · board
Opinion 2026·09·01 12 min

The consent nobody sought: Britain says no to the keys

Someone finally asked the public — and across every party, Britain said it would not trust the state with the keys to its private life. A sidebar to the series that goes to the foundation the whole age-verification project rests on: a consent never sought, and never given.

privacy · encryption · online safety · plain english · series
Threats 2026·08·31 33 min

The UK threat landscape: August 2026

The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days.

threat landscape · monthly · ransomware · governance · board · cni
Opinion 2026·08·30 6 min

The honeypot changes address

Part 11: Meta settles the US child-safety case for up to $18bn and the UN comes out against outright bans — the week the ban model lost the argument. But the age check just moved from the platform to the app store, and the identity honeypot moved with it.

children · online safety · plain english · series
Privacy 2026·08·27 8 min

AI-generated harm against children in 2026

Revisiting the September 2024 post on deepfakes and children. UK law has criminalised creation of intimate deepfakes of minors. Schools have policies. The IWF reports massive growth in AI-generated CSAM. Voice clone fraud is mature. What has actually changed and what to do.

privacy · children · ai · deepfake · update
Opinion 2026·08·18 7 min

Struck down before the start: France's court reads the argument back

Part 10: eighteen days before launch, France's Constitutional Council struck the under-15 ban down — on the grounds this series pressed: disproportion, and age verification with no guarantees for private life. A reprieve, but the redraft is already commissioned.

children · online safety · plain english · series
Privacy 2026·08·06 7 min

Gaming and online communities in 2026: what changed

Revisiting the 2023 post on gaming, voice chat, and the communities that look least like social media. Three years of platform safety overhauls, AI moderation, AI voice in games, and the new financial and AI-companion risks that did not exist last time.

privacy · children · gaming · update
Opinion 2026·07·25 10 min

The first hour

Part 3: a child has just told you they are being extorted over an image. What to do, in what order, in the hour that follows. Why not to pay, why not to block before you capture, what Report Remove actually does, and why the image is not the emergency.

children · online safety · exploitation · plain english · series
Opinion 2026·07·25 9 min

The first message is always kind

Part 2: how contact with a child actually starts. Not a stranger saying something obviously wrong, but attention, aimed at a child having a bad week. The pattern, the four things that stop them telling you, and the sentence to say before anything happens.

children · online safety · exploitation · plain english · series
Opinion 2026·07·25 5 min

The week in cyber — 20 to 24 July 2026

A zero-click Russian email campaign, a SharePoint patch trailing its own exploitation, an AI agent that escaped its sandbox, and a council insider nobody was watching — four containment failures and the board questions they leave behind.

weekly · governance · ned · board
Opinion 2026·07·25 10 min

They were never on the dark web

Part 1 of a new series. Europol has just referred 4,340 URLs tied to The Com, a network that grooms and coerces children on the platforms they already use. Why the dark-web mental model fails parents, what the numbers say, and what follows.

children · online safety · exploitation · plain english · series
Opinion 2026·07·25 9 min

The trapdoor under the safe harbour

A pornography company and a speed-camera app have just cost the internet its hosting defence. The Court of Justice says algorithmic ranking is control — and the protection against being made to monitor everything may go with it. Why the ruling I wanted worries me.

platform liability · eu law · online safety · free expression · plain english
Opinion 2026·07·24 9 min

The experiment comes home: Britain bans under-16s

Part 10: the experiment comes home. Britain will ban under-16s from social media by spring 2027 — the ban the Commons rejected in March, revived by regulation in June. Held to the same standard as France and Australia, including the objection the government made itself.

children · online safety · plain english · series
Opinion 2026·07·22 8 min

Four days, 490 records: the insider breach nobody budgets for

A new council worker opened ~490 sensitive safeguarding records and downloaded 94 over four days — then got a suspended sentence. The sentence is the least interesting part. Why insider snooping is the breach nobody budgets for, and why you can't rely on prosecution to stop it.

data protection · insider risk · privacy
Opinion 2026·07·22 7 min

The experiment goes live: France bans under-15s

Part 9: France becomes the first country in Europe to ban under-15s from social media — and the first to make everyone verify their age. Braver than Australia's version, and it builds the identity honeypot at national scale. Scoring the law against the argument.

children · online safety · plain english · series
Opinion 2026·07·22 14 min

An AI broke containment and hacked Hugging Face to cheat a test

An autonomous AI agent broke into Hugging Face's production systems — thousands of actions, stolen credentials, lateral movement. OpenAI admitted it was theirs: models in a cyber eval escaped their sandbox and hacked a real company to cheat the test. Not malice — optimisation.

AI · agentic ai · assurance
Opinion 2026·07·19 10 min

Buying the breach: cyber due diligence, a board read

In a deal you don't just buy revenue — you buy the unpatched servers, the undisclosed incidents, and whoever is already inside the network. A board read on cyber due diligence: what's at stake, what to ask before signing, and why a court just put a PE sponsor on the hook.

governance · ned · board · m&a · due diligence

full archive  ·  subscribe by email  ·  rss