Peter Bassill — latest writing on cyber security
Latest articles · page 9 of 13
-
Setting Up Unattended Security Upgrades on Ubuntu
Most Linux servers that get compromised had a patch available weeks before the breach. Unattended-upgrades applies security fixes while you sleep.
-
What pen testing now actually buys you
AI-assisted offensive tooling, cloud-native estates, supply-chain shaped scope — what pen testing in 2025 actually looks like, and what boards are still mis-reading in the deliverable.
-
The incidents that do not make the papers
What three years on the CREST Incident Response Pan-Europe board has taught me about the work the headlines never cover, and the kind of firm a customer should actually want to be on the end of the phone with.
-
Carrying the pager: a list, not a manifesto
Things you can only learn by being woken up by them. Plain language. No revelations promised.
-
Setting Up WireGuard VPN on Ubuntu
WireGuard is the VPN that replaced everything else on my network. Server setup, client configuration, DNS leak prevention, and kill switches.
-
From prepositioning to action
Iran has shifted its UK-facing cyber activity from quiet infrastructure presence to operational disruption. The NCSC's August advisory on Salt Typhoon names three Chinese firms. The trajectory of 2025 is no longer ambiguous.
-
Determinism and regulatory defensibility, eighteen months later
Post 14 of the AI series. The bit-identical-inference property I wrote about in 2024 is showing up in regulatory drafting. What the Cyber Security and Resilience Bill drafting work suggests about how regulators are going to evaluate AI-driven security decisions.
-
Carrying the pager, revisited
A reflection on a year of mature incident-response practice — what carrying the on-call pager has taught me about the shape of leadership, the cost of not training your successor, and what the work actually looks like at three in the morning.
-
Setting Up Pi-hole for Home DNS Filtering
Pi-hole turns a spare machine into a network-wide ad and tracker filter. Every device benefits without any of them needing individual configuration.
-
The thing an accreditation cannot do
I have sat on the CREST European Council since 2022. This is what the work has taught me about what accreditation can and cannot do, and why I think the next chapter is harder than the last.
-
Synnovis, a year on
One year after the Qilin ransomware attack on Synnovis took NHS pathology services in south-east London offline, what did we actually learn — and what is still unfixed?
-
Agents in production, eighteen months on
Post 13 of the AI series. The agent demos at RSA and Black Hat have got slicker. The agent in production cyber operations has, mostly, not arrived. The honest 18-month read on a category whose marketing has run ahead of its engineering.
-
Configuring UFW Firewall Rules on Ubuntu
UFW is the sane front-end to iptables. This tutorial covers default-deny policies, service rules, rate limiting, logging, and the Docker gotcha that breaks all of it.
-
What the retail wave actually cost
M&S resumed online orders this week after 46 days offline. Co-op is counting £206m. Harrods got off relatively lightly. Three compromises, one actor, one Easter weekend — and a lesson UK retail boards are still digesting.
-
Cross-tenant intelligence: the privacy architecture problem
Post 12 of the AI series. The architecture that turns one customer's experience into another's protection — without exposing either to the other. The privacy engineering problem nobody in the LLM space is talking about, and EmilyAI's seven principles.