peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ ls -t writing/ | less # page 2 of 13

Latest articles · page 2 of 13

  • The week in cyber — 20 to 24 July 2026

    A zero-click Russian email campaign, a SharePoint patch trailing its own exploitation, an AI agent that escaped its sandbox, and a council insider nobody was watching — four containment failures and the board questions they leave behind.

    • 5 min read
  • They were never on the dark web

    Part 1 of a new series. Europol has just referred 4,340 URLs tied to The Com, a network that grooms and coerces children on the platforms they already use. Why the dark-web mental model fails parents, what the numbers say, and what follows.

    • 10 min read
  • The trapdoor under the safe harbour

    A pornography company and a speed-camera app have just cost the internet its hosting defence. The Court of Justice says algorithmic ranking is control — and the protection against being made to monitor everything may go with it. Why the ruling I wanted worries me.

    • 9 min read
  • The experiment comes home: Britain bans under-16s

    Part 10: the experiment comes home. Britain will ban under-16s from social media by spring 2027 — the ban the Commons rejected in March, revived by regulation in June. Held to the same standard as France and Australia, including the objection the government made itself.

    • 9 min read
  • Four days, 490 records: the insider breach nobody budgets for

    A new council worker opened ~490 sensitive safeguarding records and downloaded 94 over four days — then got a suspended sentence. The sentence is the least interesting part. Why insider snooping is the breach nobody budgets for, and why you can't rely on prosecution to stop it.

    • 8 min read
  • The experiment goes live: France bans under-15s

    Part 9: France becomes the first country in Europe to ban under-15s from social media — and the first to make everyone verify their age. Braver than Australia's version, and it builds the identity honeypot at national scale. Scoring the law against the argument.

    • 7 min read
  • AI

    An AI broke containment and hacked Hugging Face to cheat a test

    An autonomous AI agent broke into Hugging Face's production systems — thousands of actions, stolen credentials, lateral movement. OpenAI admitted it was theirs: models in a cyber eval escaped their sandbox and hacked a real company to cheat the test. Not malice — optimisation.

    • 14 min read
  • Buying the breach: cyber due diligence, a board read

    In a deal you don't just buy revenue — you buy the unpatched servers, the undisclosed incidents, and whoever is already inside the network. A board read on cyber due diligence: what's at stake, what to ask before signing, and why a court just put a PE sponsor on the hook.

    • 10 min read
  • DORA, a board read: the rulebook that followed you home

    The UK left the EU. DORA did not leave the UK. A plain-English board read on the Digital Operational Resilience Act — who it reaches on this side of the Channel, why Article 5 puts it on your desk personally, and what a director should be able to evidence.

    • 10 min read
  • So what do I actually do?

    Seven parts on why the government's plan to protect children online will leak. So here is the other side of the ledger: the evidence-based, do-it-this-weekend guide to protecting your own child — ordered by what genuinely works, not what merely feels reassuring.

    • 15 min read
  • A curfew you can switch off

    The government's midnight social media curfew for 16 and 17-year-olds is a default, not a control — and after 29 years of telling boards the difference, I can't un-see it. Part 1 of a series on what happens when good intentions meet the technical reality of the teenage internet.

    • 7 min read
  • AI

    The AI security starter kit for small business

    Seven free documents that take a small firm from "people are quietly using ChatGPT" to governed, defended and drilled in ninety days. A roadmap, a wall chart, a two-page policy, an agents & MCP guide, a board briefing, a self-assessment and a DPIA guide. No email gate.

    • 5 min read
  • Lessons from the age gate we already built

    We don't have to predict how a national age-verification scheme performs. We switched one on last July for pornography, and a year of data is in. Part 6: what the porn age gate actually did — who it stopped, where the traffic went, and the identity honeypot it built along the way

    • 9 min read
  • The browser in the browser

    An age check inspects the visitor in front of it. But what if the visitor is a data centre in Frankfurt, streaming the real site back as video to a child in Fife? Part 5: browser-as-a-service, the school-proxy underground, and the bypass I sell as enterprise security.

    • 8 min read
  • The dark routes

    Every enforcement idea so far has needed a server to find and block. Tor and i2p are built specifically so there isn't one. Part 4: what "just block the dark web" actually asks for, why it fails, and — the twist parents don't expect — why this is the route I worry about least.

    • 8 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…