Peter Bassill — latest writing on cyber security
Latest articles · page 5 of 13
-
From self-assessment to assurance: Cyber Essentials Plus and ISO 27001
Part three: turning a self-assessment into assurance. What Cyber Essentials Plus actually tests on your real machines, and how to build a proportionate ISO 27001 management system that keeps the controls alive.
-
The week in cyber — 8 to 12 June 2026
Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other.
-
Parental Controls on Windows, macOS, ChromeOS and Linux
Configure built-in parental controls on every major operating system — screen time limits, content filtering, app restrictions, activity reports — plus browser, gaming platform and mobile device controls.
-
The five controls that do most of the work
Part two: the five Cyber Essentials controls one by one, what the Danzell question set now demands of each, the mistakes that fail firms at assessment, and how each maps onto its ISO 27001 counterpart.
-
The week in cyber — 1 to 5 June 2026
A self-propagating worm hiding under Red Hat's npm name, two actively-exploited flaws at the edge and the core of the typical UK network, an Android zero-day in the June update, and the Cyber Security and Resilience Bill reaching its final Commons stage.
-
The digital footprint we create for children, three years on
Revisiting the 2023 post on children's digital footprints, with what has actually changed by 2026 — the Children's Code enforcement, generative AI making the training-set argument operational, and Smartphone Free Childhood moving the position to the mainstream.
-
Securing Your Home Network to Protect Your Family
Harden your router, deploy DNS-level content filtering, segment your network for children's devices and IoT, and schedule internet access — a practical guide for parents.
-
A Parent's Guide to Spotting Phishing and Social Engineering
Your children receive the same phishing messages you do, with less experience recognising them. This guide teaches you what to look for and how to explain it.
-
A cyber strategy for UK small business: the foundations
Part one of a four-part cyber strategy for UK SMBs to run in the second half of 2026: three frameworks — Cyber Essentials, Cyber Essentials Plus and ISO 27001 — nested into one spine, plus the two decisions everything hangs on: scope and ownership.
-
The week in cyber — 25 to 29 May 2026
GCHQ's director on a 'moment of consequence', the TrapDoor supply chain campaign reaching into AI coding assistants, the Cyber Security and Resilience Bill still grinding through Report Stage, and quantum quietly becoming a 2026 planning item.
-
What is AI in 2026
One word is doing too much work. What people actually mean when they say "AI" in 2026 — neural networks, NLP, LLMs, generative AI, and agentic AI — what each one is, and which conversation you are actually in.
-
The nine-second problem
An AI agent took nine seconds to delete a production database and its backups. The agent did what it was authorised to do. That is the finding.
-
The week in cyber — 18 to 22 May 2026
A self-spreading npm worm, a government letter that boards should read, and the second-quietest Patch Tuesday in two years. What the past working week looked like through a UK board lens.
-
The regulator pivot
Four documents in May, from four different parts of the UK regulatory apparatus, tell one story. ICO five-step guide. BoE/FCA/HMT joint statement. Cabinet Office letter. South Staffordshire Water fine. The polite phase is over.
-
The agent age and the analyst in the loop
Post 21 of the AI series, and the closing piece. Where this is heading. The agent age has arrived; the analyst is still in the loop; the architectural decisions that made EmilyAI durable are now the wider field's emerging consensus. What I will be writing about next.