peter bassill · operator
$ ls ai-security-starter-kit/ -la

ai security
starter kit.

Seven documents that take a 5–250 person firm from "people are quietly using ChatGPT" to governed, defended, and drilled — in ninety days, mostly for free. No email gate. No vendor pitch. Take them.

Documents · 7 Cost · £0 Licence · CC BY 4.0 Version · 1.0 · 2026-07 Locale · en_GB
$ cat README

Roughly half of employees now use AI tools their employer never approved, and about half of those have pasted non-public company data into them. Meanwhile agents — AI that acts, not just advises — are being wired into inboxes and ledgers by whoever watched the video first.

None of this needs a platform purchase or a consultancy engagement to get under control. It needs an inventory, one page of policy, a handful of settings, two fraud procedures, a DPIA where personal data is in play, and a quarterly hour. That is what this kit is: the sequence, written down, in the order I would do it.

Use the documents in order, or take what you need. If you only take one thing: document 02 goes on the wall, and payment changes get verified by a call to a number you already had.

$ ls -l downloads/
01

The AI security roadmap for small business

Ninety days from "people are quietly using ChatGPT" to "we know what we run, we've decided what's allowed, and we'd notice if it went wrong." Four phases, roughly fifteen hours of effort, mostly settings and conversations. Start here.

02

AI at work — the staff cheat sheet

One A4 sheet for the wall. The do's, the don'ts, the three data bins, the three questions before you paste, and the one hard rule about money. Designed to be read in ninety seconds and remembered.

03

AI usage policy — template

A fill-in-the-brackets policy that stays on two pages, because one page of policy that gets read beats forty that don't. Approved tools, the three-bin data rule, eight rules, sign-off. Editable Word version included.

04

Securing AI agents & MCP

A chatbot advises; an agent acts. The five failure modes worth planning for, ten rules for running agents in a small firm, the six MCP hygiene rules, and a go-live checklist. Plain English throughout.

05

AI board & management briefing — template

The quarterly two-pager: where we use AI, the top three risks honestly stated, incidents and near-misses, money, and the decisions the meeting exists to take. Editable Word version included.

06

AI security self-assessment

Twenty-five questions across five domains, scored 0–2, with banded results and a quarterly score record. The test for every answer: could you show an outsider the evidence within five minutes?

07

The DPIA guide for AI — UK & EU GDPR

The impact assessment the law actually requires for most AI use of personal data — and doubly so when the data is your client's. The screening test, UK/EU differences, an AI risk catalogue to steal from, controller-versus-processor explained plainly, a worked example, and a fill-in template. Editable Word version included.

Licence: CC BY 4.0 — use them, adapt them, rebrand the templates as your own, keep the attribution on the guides. General guidance, not legal advice; when AI touches decisions about people, take proper advice.

$ contact --do-it-for-me
§ / Done for you

Or I do the hard work, and you get the outcome.

The kit is free and always will be. But if you would rather someone who has done this a few hundred times ran the 90 days for you — the inventory, the policy rollout, the DPIA, the agent go-lives, the board briefing — that is work I take on. Days to weeks, scoped and priced up front, your team left able to run it without me.

Tell me where you are with AI. Company size, what's already in use (roughly — that's what the inventory is for), and what you'd like taken off your plate. You'll get a considered reply — a scope and a price, or an honest "the kit alone will do you fine" — within two working days.
TYPICALLYthe 90-day roadmap, delivered · DPIAs · policy & training · agent go-lives
GOES TOmy consulting inbox, directly — plus a ping to my phone
REPLYwithin 2 working days · en_GB
PRIVACYno tracking · no third-party forms · stored only in my inbox
lands in my inbox + a ping to my phone · nothing else sees it
anti-abuse check: waiting for the form…
$ man starter-kit | grep -A3 "SEE ALSO"

The kit pairs with the twelve-part Cyber security for the small business series, which covers the non-AI foundations — passwords, patching, backups, email — that this kit stands on. If your firm holds neither, start there; Cyber Essentials first, AI governance second.

Found a gap, or something that didn't survive contact with your firm? Tell me — the kit is versioned and reviewed like everything else here.

back to home  ·  writing  ·  subscribe by email