peter bassill · operator
$ grep -i board writing/ -r

for boards.

The writing aimed at the boardroom, pulled out from the rest. Cyber, IT and AI governance for non-executive directors and the executives who answer to them — written from the seat, not the sidelines, by someone who has both run the security function and sat on the body that accredits the industry.

Audience · NEDs · chairs · audit & risk Author · CEO, UK Cyber Defence · CREST See also · what I do for boards →
01 / The non-executive's job

What the role actually demands — the questions worth more than any maturity score, and the personal accountability that now comes with the seat.

02 / Regulation, and what boards must now evidence

The polite phase is over. What the regulators have started drawing lines around, and what the executive should be preparing to show.

2026·07·19DORA, a board read: the rulebook that followed you homeThe UK left the EU. DORA did not leave the UK. A plain-English board read on the Digital Operational Resilience Act — who it reaches on this side of the Channel, why Article 5 puts it on your desk personally, and what a director should be able to evidence.10 min2026·02·14The Cyber Security and Resilience Bill, a board readWhat the Bill actually does, what it changes for boards in and out of scope, and what the executive should be preparing to evidence over the next twelve months.8 min2025·09·27The line the ICO is now drawingCapita £14m. Advanced Computer Software £3.07m. Neither fine was for the breach. Both were for the controls that preceded it. The ICO has redrawn what "adequate security" means in evidence — and most boards have not noticed.6 min2026·05·22The regulator pivotFour documents in May, from four different parts of the UK regulatory apparatus, tell one story. ICO five-step guide. BoE/FCA/HMT joint statement. Cabinet Office letter. South Staffordshire Water fine. The polite phase is over.6 min2026·01·20The CSR Bill and AI in cyber: what the regulator now expectsPost 18 of the AI series. The Cyber Security and Resilience Bill is moving toward commencement. What it changes for AI in cyber security specifically, what the secondary legislation drafting suggests, and what vendors and customers should be preparing.7 min2025·08·05Determinism and regulatory defensibility, eighteen months laterPost 14 of the AI series. The bit-identical-inference property I wrote about in 2024 is showing up in regulatory drafting. What the Cyber Security and Resilience Bill drafting work suggests about how regulators are going to evaluate AI-driven security decisions.7 min
03 / The director's own exposure

From an eighteen-part series on digital privacy for board directors — the footprint the role creates, and the board-paper habits most likely to leak.

The judgement behind the writing.

If this is the kind of counsel your board is missing, the engagement models set out how to put it in the room — from a full NED appointment to a standing advisory seat. The credentials are the vetting page.

replies within 2 working days · en_GB · no agency intros

→ more by tag: board  ·  ned  ·  governance  ·  regulation  ·  all writing