peter bassill · operator
home
$ grep -l "category: defence" articles/*.txt

Defence.

Defence 23 articles
2026·07·11 Installing NextCloud Securely on Ubuntu with Apache A hardened NextCloud deployment on Ubuntu 24.04 with Apache, PHP 8.3, MySQL, Redis and Let's Encrypt. 18 min 2026·05·12 Configure Fail2Ban: Protecting Linux Services from Brute Force Install and configure Fail2Ban on Ubuntu to protect SSH, Apache and other services with rate-limiting and IP banning. 10 min 2026·04·18 What it changed about my other machines Last in the six-post series on the Covert Cyber Deck. The deck as catalyst, not destination — what designing and living with it changed about how I look at my work laptop, my home network, the firm's estate, and the boards I advise. 6 min 2026·03·14 Living with it: the costs of offline-first Post five of six on the Covert Cyber Deck. Honest notes on using the slate as a daily driver for several months. What I gave up. What surprised me. Where the bargain felt good and where it felt silly. 7 min 2026·03·07 The two disciplines that quietly do most of the work Default-deny on USB and hardware-backed multi-factor authentication. Two unfashionable practices that, between them, would prevent more compromise than any tool a CISO will buy this year. 5 min 2026·02·11 fail2ban is not access control. It is not nothing, either. A short essay on the long argument I keep having with people who should know better. 4 min 2026·01·24 What I deliberately left off Post four of six on the Covert Cyber Deck. Every component is a question. These are the things I chose not to include — Bluetooth on the management plane, a camera, GPS, cellular, several others — and the single question that flushed each one out. 7 min 2026·01·21 Configure psad: Detecting Port Scans on Linux Install and configure psad on Ubuntu to detect and optionally block network port scans using iptables log analysis. 9 min 2026·01·19 Installing and Configuring Postfix with ClamAV and SpamAssassin Build a hardened mail server on Ubuntu with Postfix for delivery, ClamAV for virus scanning and SpamAssassin for spam filtering, integrated through Amavis. 22 min 2025·12·20 Where I trusted, where I didn't Post three of six on the Covert Cyber Deck. The supply chain decisions behind the build — why I chose the parts I chose, why I rejected several I considered, and why I ended up drawing the carrier PCB myself rather than buying one. 7 min 2025·11·22 The threat model, written down Post two of six on the Covert Cyber Deck. The threat model I have spent the last month writing down — what I am protecting against, what I am not, and why putting it in plain English changed the rest of the build. 6 min 2025·10·18 Building a machine I can fully describe First in a six-post series on the Covert Cyber Deck — a portable slate I am building around a Pi CM5, two SDRs, a custom carrier PCB, and a hardened Ubuntu. The argument is not the hardware. It is what designing it forces you to think about. 6 min 2025·09·23 The single-tin posture: why we still ship on a Dell Post 15 of the AI series. A single Dell PowerEdge R760, racked at the customer site, running the whole platform — analyst, inference, persistence, audit. The deployment shape the hyperscaler default would have us abandon, and why we have not. 7 min 2025·09·15 What pen testing now actually buys you AI-assisted offensive tooling, cloud-native estates, supply-chain shaped scope — what pen testing in 2025 actually looks like, and what boards are still mis-reading in the deliverable. 7 min 2025·08·22 Carrying the pager: a list, not a manifesto Things you can only learn by being woken up by them. Plain language. No revelations promised. 5 min 2025·07·26 Carrying the pager, revisited A reflection on a year of mature incident-response practice — what carrying the on-call pager has taught me about the shape of leadership, the cost of not training your successor, and what the work actually looks like at three in the morning. 6 min 2024·09·10 Backups: the only thing that recovers you from ransomware The 3-2-1 rule, what to back up, why testing your backups is more important than having them, and the specific changes that protect backups from modern ransomware. 6 min 2024·08·27 Single-vendor concentration: the CrowdStrike lesson applied to AI Post 6 of the AI series. The July 2024 CrowdStrike outage was not an AI incident, but it tells us a great deal about where the AI-in-security market is heading. Why single-vendor concentration of intelligent agents is a structural risk worth modelling now. 7 min 2024·07·09 Your network: Wi-Fi, routers, and home workers Your router is your only firewall. Here is how to configure it properly, secure your Wi-Fi, set up a guest network, and look after the staff who work from coffee shops and kitchen tables. 6 min 2024·06·11 Patching: the unglamorous lifesaver Why software updates matter, what actually needs updating, and how to make patching manageable for a small business without dedicated IT staff. The vegetables of cyber security. 5 min 2024·04·16 Locking the front door: passwords and access Password managers, multi-factor authentication, the principle of least privilege, and the leaver checklist. The single highest-value hour you will spend on cyber security all year. 7 min 2024·01·16 Cyber security for the small business: where to start An honest start to a year-long series. What cyber security actually is, why small businesses are targeted, and the five things every small business has that attackers want. 6 min 2023·02·28 The home network you live on Part 2 of 18. Your home Wi-Fi router is the only thing between everything connected in your house and the rest of the internet. What boards should ask their household to look at this weekend. 7 min

full archive  ·  threats · ai · policy · privacy · opinion