Peter Bassill — latest writing on cyber security
Latest articles · page 7 of 13
-
What I got wrong
An honest account of the calls I have made in the past three years that did not land — what I was reading into the evidence that was not there, and what I would do differently.
-
Living with it: the costs of offline-first
Post five of six on the Covert Cyber Deck. Honest notes on using the slate as a daily driver for several months. What I gave up. What surprised me. Where the bargain felt good and where it felt silly.
-
Hardening Microsoft 365 for a Small Business
Most small businesses run Microsoft 365 and have never touched its security settings. This tutorial covers the controls that matter, in order of impact.
-
How to Use Tor: A Practical Guide to Anonymous Browsing
Install, configure and use the Tor Browser on Linux and Windows with bridges, security levels and operational discipline.
-
The two disciplines that quietly do most of the work
Default-deny on USB and hardware-backed multi-factor authentication. Two unfashionable practices that, between them, would prevent more compromise than any tool a CISO will buy this year.
-
DeepSeek and the supply chain of intelligence
Post 19 of the AI series. The open-weight reasoning models from DeepSeek and others have changed the supply chain of intelligence. The provenance, licensing, and operational properties of the models you run are now a cyber security question worth taking seriously.
-
The Cyber Security and Resilience Bill, a board read
What the Bill actually does, what it changes for boards in and out of scope, and what the executive should be preparing to evidence over the next twelve months.
-
fail2ban is not access control. It is not nothing, either.
A short essay on the long argument I keep having with people who should know better.
-
How to Use I2P: A Practical Guide to the Invisible Internet
Install and configure the I2P router on Ubuntu, access eepsites, and understand how I2P differs from Tor.
-
Setting Up MFA Everywhere: A Practical Small-Business Guide
Multi-factor authentication is the single highest-leverage security control most small businesses still have not enabled. Ten minutes per service, done once.
-
What I deliberately left off
Post four of six on the Covert Cyber Deck. Every component is a question. These are the things I chose not to include — Bluetooth on the management plane, a camera, GPS, cellular, several others — and the single question that flushed each one out.
-
Configure psad: Detecting Port Scans on Linux
Install and configure psad on Ubuntu to detect and optionally block network port scans using iptables log analysis.
-
The CSR Bill and AI in cyber: what the regulator now expects
Post 18 of the AI series. The Cyber Security and Resilience Bill is moving toward commencement. What it changes for AI in cyber security specifically, what the secondary legislation drafting suggests, and what vendors and customers should be preparing.
-
Installing and Configuring Postfix with ClamAV and SpamAssassin
Build a hardened mail server on Ubuntu with Postfix for delivery, ClamAV for virus scanning and SpamAssassin for spam filtering, integrated through Amavis.
-
Self-Hosting a Password Manager with Vaultwarden on Ubuntu
Every credential your organisation holds, stored on someone else's server. Vaultwarden gives you the Bitwarden experience without the trust dependency.