peter bassill · operator
$ ls -l /etc/services --sort=priority

work.

One board seat at a time, taken seriously. A Non-Executive Director who still reads the logs — cyber security, information security, IT and AI oversight from someone who has actually operated all four. Full board appointment, a standing advisory seat, a retainer, or a scoped piece of work — chosen to fit what the board actually needs.

Base · United Kingdom Day job · CEO, UK Cyber Defence CREST · European Council · IR Pan Europe Status · open to NED & advisory
$ cat engagement-models.tsv
01 / How I can help

Four ways to put an operator in the room.

Not every board needs a full directorship, and not every problem needs a permanent seat. These are the shapes the work takes — from a formal NED appointment down to a few scoped days. Each one is the same person: an operator who has carried the pager, not a slide-deck advisor.

Model · 01

Non-Executive Director

Who it's forUK boards where cyber, IT or AI is a material line on the risk register — regulated financial services, insurance, technology, critical infrastructure, and PE-backed businesses at scale.
CadenceA formal board appointment: board and committee meetings, the reading behind them, and the between-meeting calls that actually decide things.
What you getIndependent challenge to the executive's security narrative, audit- and risk-committee support, and a director who can read the logs behind the dashboard — not just nod at it.
Model · 02

Board Cyber Advisor

Who it's forBoards and executive teams that want senior, independent cyber counsel on a standing basis but don't yet need — or can't yet justify — a full NED appointment. Scaling technology firms, PE portfolio companies, mid-market organisations.
CadenceA structured advisory-board seat on a recurring rhythm — typically quarterly or monthly — attending the board or a sub-committee, with access between sessions.
What you getConsistent input on the risk register, the security roadmap and the questions the board should be asking — the substance of a NED without the formality or permanence of a directorship.
Model · 03

Strategic Advisory Retainer

Who it's forChairs, CEOs and CISOs who want a senior, responsive sounding board on call — through a transformation, a post-incident recovery, or a stretch of significant regulatory change.
CadenceAn ongoing retainer: regular touchpoints, with more availability when circumstances demand it. Responsive rather than scheduled.
What you getDirect access to one experienced person who already holds your context — so you are not briefing a stranger from scratch at the worst possible moment.
Model · 04

Programme & project advisory

Who it's forOrganisations running one specific, high-stakes initiative — a Cyber Essentials Plus certification in a complex estate, an AI adoption programme, an incident-response readiness review, or a security-architecture decision.
CadenceTime-bound and scoped: days to weeks, with a defined start, end and deliverable. No open-ended retainer.
What you getSenior strategic and governance direction on the thing in front of you — without a permanent commitment. The AI Security Starter Kit is the free version; this is the one with me in the room for the complicated parts.
Fit & candour: I run a UK cyber defence firm, so I will not take a seat or a retainer where that creates a conflict — and I will say so in the first conversation, not the fourth. Audit and risk committee work welcome. One or two board seats, done properly, rather than a portfolio.
$ man ned --section=board
02 / The remit

Three specialisms the board can interrogate.

Most boards get their cyber oversight second-hand — a slide from the CISO, a paragraph from the auditors. An operator in a non-executive or advisory seat gets it first-hand, in plain English, with the follow-up questions asked before the meeting rather than after the incident.

SPECIALISM · 01

Cyber & information security

risk oversight · incident governance

Security posture the board can interrogate: what the risk register should say, what the CISO's report leaves out, what an incident will demand of directors — and whether the recovery plan survives contact with an actual Tuesday-morning breach.

CREST · EUROPEAN COUNCIL
SPECIALISM · 02

IT & technology

strategy · resilience · spend

Technology oversight from someone who still builds: whether the platform bet is sound, whether the resilience claims are tested or theatrical, and whether the IT budget is buying risk reduction or shelfware.

OPERATOR · SINCE 1996
SPECIALISM · 03

AI governance

adoption · risk · policy

The newest line on the risk register. Where AI genuinely helps the business, where it quietly leaks its data, and what the board must be able to evidence — UK GDPR, the EU AI Act where it reaches, and the questions insurers have started asking.

AUTHOR · AI SECURITY STARTER KIT

What I bring to a boardroom is the combination: 29 years as a practitioner, a decade at executive level, current CREST European Council and IR Pan Europe seats, and a working knowledge of what regulators, insurers and incident rooms actually ask for. I can challenge an executive's security narrative because I have written those narratives — and occasionally had them fall apart under a real attack. For boards weighing what the role actually demands, I have written it up plainly in the writing for boards.

$ grep -i board /var/log/career | tail
03 / Selected engagements

Where the judgement was earned.

Thirty years of it, at board and executive level, across sectors where getting security wrong has consequences. A selection — the full record is on the credentials page.

Gala Coral Group
Group CISO · 2006–2010

Chief Information Security Officer of one of Europe's largest privately-held gaming groups — £4.5bn turnover, group-wide information risk, security strategy and architecture, and the PCI-DSS programme. Board- and executive-level accountability at scale.

Microsoft UK
European CISO Council · 2006–2008

Invited member of Microsoft UK's European CISO Council, chaired by Edward Gibson, then CSO of Microsoft UK — a peer forum for senior European CISOs on the threats then emerging. Governance among peers, not vendors.

UK Cyber Defence (founded as Hedgehog Security)
Founder & CEO · 2009–present

Built a CREST-accredited testing and incident-response firm recognised internationally, with clients including Microsoft, Tesla, Virgin Atlantic and Tokio Millennium Re. Full board accountability for strategy, finance and regulatory compliance (ISO 27001, PCI-DSS, CREST).

CREST
European Council · IR Pan Europe · 2022–present

Two non-executive seats on the body that accredits much of the industry: shaping standards, codes of conduct and accreditation frameworks, and engaging with regulators, national CERTs and law enforcement across Europe.

The Dove Service
Trustee · 2015–2019

Non-executive trustee of a UK bereavement-counselling charity, providing board-level data-protection and cyber-security oversight (ISO 27001, Cyber Essentials, PCI-DSS). Governance in the third sector, where the stakes are personal.

HM Government
Officer & reservist · 1996–2006

Where it started: officer-level operations and technical work across the electromagnetic spectrum — signals, electronic warfare, communications security, and the integration of early computer-based capability. Ten years before "cyber" was a boardroom word.

On specifics: named clients are those already a matter of public record. Current and recent engagements are covered by confidentiality and discussed only under NDA — as any board would expect of the person they are vetting.

$ cat /var/log/endorsements | head
04 / In other people's words

Endorsements you can verify.

Attributed, linked to the people who said them, and trimmed only for length — never for meaning. An endorsement you can't verify is just copy.

"I so enjoyed Peter as a member of my Chief Information Security Officer Council at Microsoft Ltd UK. He always provided a unique insight into IT security issues of import to many global companies who were also members. A respected and senior member of the IT community, Peter stands out as honorable and the person you would want on your side."

"Peter is a rare breed of individuals who (like me) have a unique combination of heavy technical skills coupled with excellent managerial and other soft skills that make him a prize for any company. The brief time I worked with Peter was great fun. He is very practical but does not give in to any argument if he knows he is in the right. Brilliant person. Highly Recommended."

Amar Singh · CISO — coached by Peter into the CISO world

"Met Peter at an event where he was the guest speaker at a hacking workshop. I knew from that moment I would work with him on many projects going forward. What Peter didn't know about gaining access to an organisation's 'crown jewels' wasn't worth knowing. … A trusted partner and advisor whom I'd have no problem recommending to people who need to protect valuable data within their organisation."

Further board and client references available on request.

$ contact --work

Start the conversation.

For NED and advisory-board approaches: the sector, the board's shape, and what has prompted the search. For a retainer or a scoped piece: the situation and rough timescale. The full record is on the credentials page; a one-page board CV is there to download, and the detailed CV is on the gated CV page.

replies within 2 working days · en_GB · pgp on request · no agency intros

back to home  ·  credentials  ·  writing for boards  ·  ai security starter kit