Peter Bassill — latest writing on cyber security
Latest articles · page 8 of 13
-
SolarWinds at five
Five years on from the disclosure of the SolarWinds Orion compromise, what actually changed in how UK boards think about third-party software risk — and what did not. A practitioner's retrospective on the case study that defined the decade.
-
The supplier underneath the supplier
Three disclosures last month tell the same story from three angles: NHS England's tech provider, an NHS GP software supplier, and the Foreign Office. None of them is the headline brand. All of them are where the actual attack surface lives.
-
The year 2025 was actually about
An end-of-year reflection on what 2025 turned out to be, what the noise mostly was, and what the genuinely consequential shifts were for UK cyber security at board level.
-
Where I trusted, where I didn't
Post three of six on the Covert Cyber Deck. The supply chain decisions behind the build — why I chose the parts I chose, why I rejected several I considered, and why I ended up drawing the carrier PCB myself rather than buying one.
-
Year in cyber AI 2025: the agentic year that mostly was not
Post 17 of the AI series. The 2025 retrospective. Operator agents arrived but mostly in pilot, the determinism property went mainstream in procurement, the regulators caught up, and constrained agency became the named shape. The honest read going into 2026.
-
Building a Honeypot with T-Pot on Ubuntu
I have run honeypots since 1998. T-Pot bundles a dozen of them behind a single dashboard and turns passive observation into actionable intelligence.
-
Hardening Firefox for Privacy
Tor is for when you need anonymity. This is for the everyday browser — configured so it stops volunteering information about you to every site you visit.
-
The threat model, written down
Post two of six on the Covert Cyber Deck. The threat model I have spent the last month writing down — what I am protecting against, what I am not, and why putting it in plain English changed the rest of the build.
-
What the merger was actually for
Hedgehog Security and UK Cyber Defence merged this month. Here is the thinking the announcement did not contain — what we were trying to fix, and what kind of firm we are now trying to be.
-
How to Use GPG to Secure Your Email
Generate a GPG key pair, publish your public key, encrypt and sign email on the command line and in Thunderbird.
-
Frontier AI in CNI: the regulators are paying attention
Post 16 of the AI series. The autumn joint statements from the BoE, FCA and HM Treasury on frontier AI and operational resilience signal where financial-services regulators have arrived. The implications for AI in cyber security are sharper than the public conversation suggests.
-
Building a machine I can fully describe
First in a six-post series on the Covert Cyber Deck — a portable slate I am building around a Pi CM5, two SDRs, a custom carrier PCB, and a hardened Ubuntu. The argument is not the hardware. It is what designing it forces you to think about.
-
Full-Disc Encryption with LUKS on Ubuntu
If someone takes your machine, encryption is the difference between a hardware loss and a data breach. LUKS makes it a checkbox at install time.
-
The line the ICO is now drawing
Capita £14m. Advanced Computer Software £3.07m. Neither fine was for the breach. Both were for the controls that preceded it. The ICO has redrawn what "adequate security" means in evidence — and most boards have not noticed.
-
The single-tin posture: why we still ship on a Dell
Post 15 of the AI series. A single Dell PowerEdge R760, racked at the customer site, running the whole platform — analyst, inference, persistence, audit. The deployment shape the hyperscaler default would have us abandon, and why we have not.