peter bassill · operator

Policy — writing by Peter Bassill

peter@hardened:~$ ls -t writing/policy/

Policy

Regulation, law, and what a board is actually accountable for. 17 articles

  • What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow

    From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.

    • 22 min read
  • No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works

    Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.

    • 9 min read
  • The trapdoor under the safe harbour

    A pornography company and a speed-camera app have just cost the internet its hosting defence. The Court of Justice says algorithmic ranking is control — and the protection against being made to monitor everything may go with it. Why the ruling I wanted worries me.

    • 9 min read
  • DORA, a board read: the rulebook that followed you home

    The UK left the EU. DORA did not leave the UK. A plain-English board read on the Digital Operational Resilience Act — who it reaches on this side of the Channel, why Article 5 puts it on your desk personally, and what a director should be able to evidence.

    • 10 min read
  • Cyber security for the non-executive director: the NED's real job

    Cyber is now a tier-one board risk, but most non-executive directors were never trained for it. What the cyber security NED role actually demands — the questions to ask, the frameworks that matter, and how to hold a board to account without being technical.

    • 10 min read
  • The regulator pivot

    Four documents in May, from four different parts of the UK regulatory apparatus, tell one story. ICO five-step guide. BoE/FCA/HMT joint statement. Cabinet Office letter. South Staffordshire Water fine. The polite phase is over.

    • 6 min read
  • Things I wish boards would actually ask

    Twelve questions that would tell you more than any maturity score. None of them mention zero-trust.

    • 7 min read
  • The £320 myth: what Cyber Essentials actually costs

    Cyber Essentials is marketed from £320. For an unprepared 10-person UK business under the new v3.3 Danzell question set, the true first-year cost is £13,000 to £30,000 over 10 to 14 weeks. Here is the breakdown.

    • 9 min read
  • The Cyber Security and Resilience Bill, a board read

    What the Bill actually does, what it changes for boards in and out of scope, and what the executive should be preparing to evidence over the next twelve months.

    • 8 min read
  • The CSR Bill and AI in cyber: what the regulator now expects

    Post 18 of the AI series. The Cyber Security and Resilience Bill is moving toward commencement. What it changes for AI in cyber security specifically, what the secondary legislation drafting suggests, and what vendors and customers should be preparing.

    • 7 min read
  • The line the ICO is now drawing

    Capita £14m. Advanced Computer Software £3.07m. Neither fine was for the breach. Both were for the controls that preceded it. The ICO has redrawn what "adequate security" means in evidence — and most boards have not noticed.

    • 6 min read
  • The thing an accreditation cannot do

    I have sat on the CREST European Council since 2022. This is what the work has taught me about what accreditation can and cannot do, and why I think the next chapter is harder than the last.

    • 6 min read
  • The law, the insurance, the incident plan, and the culture that holds it all together

    Year-end consolidation. Your UK GDPR obligations, cyber insurance, the one-page incident response plan you need, and how to build a security culture that lasts beyond this series.

    • 9 min read
  • Board portals and document handling

    Part 12 of 18. Diligent, BoardEffect, Nasdaq Boards, the email-attachment habit, and the moments in board-paper handling when sensitive material is most likely to leak. The practical posture for non-executive directors.

    • 7 min read
  • The CISO in the dock

    The SEC's charges against Tim Brown over the SolarWinds disclosures, alongside Joe Sullivan's conviction over Uber a year ago, signal a regime change in personal accountability for security leaders. What it means for UK CISOs and the boards that employ them.

    • 7 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…