peter bassill · operator

Peter Bassill — latest writing on cyber security

peter@hardened:~$ ls -t writing/ | less # page 9 of 13

Latest articles · page 9 of 13

  • Setting Up Unattended Security Upgrades on Ubuntu

    Most Linux servers that get compromised had a patch available weeks before the breach. Unattended-upgrades applies security fixes while you sleep.

    • 8 min read
  • What pen testing now actually buys you

    AI-assisted offensive tooling, cloud-native estates, supply-chain shaped scope — what pen testing in 2025 actually looks like, and what boards are still mis-reading in the deliverable.

    • 7 min read
  • The incidents that do not make the papers

    What three years on the CREST Incident Response Pan-Europe board has taught me about the work the headlines never cover, and the kind of firm a customer should actually want to be on the end of the phone with.

    • 6 min read
  • Carrying the pager: a list, not a manifesto

    Things you can only learn by being woken up by them. Plain language. No revelations promised.

    • 5 min read
  • Setting Up WireGuard VPN on Ubuntu

    WireGuard is the VPN that replaced everything else on my network. Server setup, client configuration, DNS leak prevention, and kill switches.

    • 13 min read
  • From prepositioning to action

    Iran has shifted its UK-facing cyber activity from quiet infrastructure presence to operational disruption. The NCSC's August advisory on Salt Typhoon names three Chinese firms. The trajectory of 2025 is no longer ambiguous.

    • 5 min read
  • AI

    Determinism and regulatory defensibility, eighteen months later

    Post 14 of the AI series. The bit-identical-inference property I wrote about in 2024 is showing up in regulatory drafting. What the Cyber Security and Resilience Bill drafting work suggests about how regulators are going to evaluate AI-driven security decisions.

    • 7 min read
  • Carrying the pager, revisited

    A reflection on a year of mature incident-response practice — what carrying the on-call pager has taught me about the shape of leadership, the cost of not training your successor, and what the work actually looks like at three in the morning.

    • 6 min read
  • Setting Up Pi-hole for Home DNS Filtering

    Pi-hole turns a spare machine into a network-wide ad and tracker filter. Every device benefits without any of them needing individual configuration.

    • 12 min read
  • The thing an accreditation cannot do

    I have sat on the CREST European Council since 2022. This is what the work has taught me about what accreditation can and cannot do, and why I think the next chapter is harder than the last.

    • 6 min read
  • Synnovis, a year on

    One year after the Qilin ransomware attack on Synnovis took NHS pathology services in south-east London offline, what did we actually learn — and what is still unfixed?

    • 7 min read
  • AI

    Agents in production, eighteen months on

    Post 13 of the AI series. The agent demos at RSA and Black Hat have got slicker. The agent in production cyber operations has, mostly, not arrived. The honest 18-month read on a category whose marketing has run ahead of its engineering.

    • 7 min read
  • Configuring UFW Firewall Rules on Ubuntu

    UFW is the sane front-end to iptables. This tutorial covers default-deny policies, service rules, rate limiting, logging, and the Docker gotcha that breaks all of it.

    • 9 min read
  • What the retail wave actually cost

    M&S resumed online orders this week after 46 days offline. Co-op is counting £206m. Harrods got off relatively lightly. Three compromises, one actor, one Easter weekend — and a lesson UK retail boards are still digesting.

    • 6 min read
  • Cross-tenant intelligence: the privacy architecture problem

    Post 12 of the AI series. The architecture that turns one customer's experience into another's protection — without exposing either to the other. The privacy engineering problem nobody in the LLM space is talking about, and EmilyAI's seven principles.

    • 8 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…