Defence — writing by Peter Bassill
Defence · page 2 of 3
Controls, hardening and how-tos: the unglamorous work that holds. 43 articles
-
Hardening Microsoft 365 for a Small Business
Most small businesses run Microsoft 365 and have never touched its security settings. This tutorial covers the controls that matter, in order of impact.
-
The two disciplines that quietly do most of the work
Default-deny on USB and hardware-backed multi-factor authentication. Two unfashionable practices that, between them, would prevent more compromise than any tool a CISO will buy this year.
-
fail2ban is not access control. It is not nothing, either.
A short essay on the long argument I keep having with people who should know better.
-
Setting Up MFA Everywhere: A Practical Small-Business Guide
Multi-factor authentication is the single highest-leverage security control most small businesses still have not enabled. Ten minutes per service, done once.
-
What I deliberately left off
Post four of six on the Covert Cyber Deck. Every component is a question. These are the things I chose not to include — Bluetooth on the management plane, a camera, GPS, cellular, several others — and the single question that flushed each one out.
-
Configure psad: Detecting Port Scans on Linux
Install and configure psad on Ubuntu to detect and optionally block network port scans using iptables log analysis.
-
Installing and Configuring Postfix with ClamAV and SpamAssassin
Build a hardened mail server on Ubuntu with Postfix for delivery, ClamAV for virus scanning and SpamAssassin for spam filtering, integrated through Amavis.
-
Self-Hosting a Password Manager with Vaultwarden on Ubuntu
Every credential your organisation holds, stored on someone else's server. Vaultwarden gives you the Bitwarden experience without the trust dependency.
-
Where I trusted, where I didn't
Post three of six on the Covert Cyber Deck. The supply chain decisions behind the build — why I chose the parts I chose, why I rejected several I considered, and why I ended up drawing the carrier PCB myself rather than buying one.
-
Building a Honeypot with T-Pot on Ubuntu
I have run honeypots since 1998. T-Pot bundles a dozen of them behind a single dashboard and turns passive observation into actionable intelligence.
-
The threat model, written down
Post two of six on the Covert Cyber Deck. The threat model I have spent the last month writing down — what I am protecting against, what I am not, and why putting it in plain English changed the rest of the build.
-
Building a machine I can fully describe
First in a six-post series on the Covert Cyber Deck — a portable slate I am building around a Pi CM5, two SDRs, a custom carrier PCB, and a hardened Ubuntu. The argument is not the hardware. It is what designing it forces you to think about.
-
The single-tin posture: why we still ship on a Dell
Post 15 of the AI series. A single Dell PowerEdge R760, racked at the customer site, running the whole platform — analyst, inference, persistence, audit. The deployment shape the hyperscaler default would have us abandon, and why we have not.
-
Setting Up Unattended Security Upgrades on Ubuntu
Most Linux servers that get compromised had a patch available weeks before the breach. Unattended-upgrades applies security fixes while you sleep.
-
What pen testing now actually buys you
AI-assisted offensive tooling, cloud-native estates, supply-chain shaped scope — what pen testing in 2025 actually looks like, and what boards are still mis-reading in the deliverable.