peter bassill · operator
$ grep -l "tag:board" writing/

tag: board.

39 pieces tagged board, newest first. The full taxonomy is on the tag index.

2026·10·05 A board, no chair and a new address: the ICO becomes the Information Commission On 30 September the Information Commissioner ceased to exist and a board-led Information Commission took over, two days after the regulator left Wilmslow for Manchester. What changed, what did not, and why the chair is empty. regulation · governance · board · privacy · data protection · policy 13 min 2026·09·29 Patching is step five: inside the NetScaler zero-days Attackers exploited two Citrix NetScaler ADC and Gateway flaws for weeks before fixes shipped on 27 September. How CVE-2026-88771 turns a log line into a root shell, who is affected, and why the NCSC lists patching fifth. vulnerability management · incident response · patching · threat intel · board 12 min 2026·09·27 Critical is not the same as urgent: what 70,686 CVEs in 2026 actually ask of you Of 70,686 CVEs published between 1 January and 22 September, 161 are known to be exploited. What NVD, EPSS, CISA's catalogue and Exploit-DB say about severity, deadlines and the software attackers use, and a one-line triage rule. vulnerability management · patching · threat intel · research · board 19 min 2026·09·27 The 999 lines held: Dyfed-Powys Police and the staff question Dyfed-Powys Police kept 999 and 101 running through a cyber incident and has so far found no evidence the public's data was accessed; staff data is still under investigation. What went right, what "technical difficulties" costs, and why your own people should never hear last. incident response · data protection · social engineering · governance · board 10 min 2026·09·26 The week in cyber — 21 to 25 September 2026 A BIG-IP zero-day already under attack, Revolut's second breach this month, prompt-injected AI agents at Salesforce, an AI phishing service dismantled by Microsoft and the Met, and a whisky retailer undone by a bolt-on app — five stories, all about trust handed to someone else. weekly · governance · ned · board 6 min 2026·09·18 Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review A London property manager kept bank details, passwords and key-safe codes where a cloud analytics tool could read them; a vulnerability in that tool did the rest. Why "the cloud" is not a security decision, and a supplier review you can actually run and evidence. supply chain · data protection · governance · board · small business · cloud · plain english 19 min 2026·09·15 Aimed at a person, not a network: Iran's CHOSEN BRICK The NCSC, FBI and AIVD have published a joint advisory on CHOSEN BRICK, Windows malware Iranian state actors use to find, watch and expose dissidents, activists and journalists. A fake MRI result, a fake Norton, a Telegram bot, and a deliberate move from the work laptop to the home one. What it does, how to look for it, and what employers of people at risk should do this week. state-aligned · threat intel · spyware · social engineering · high-risk individuals · board 17 min 2026·09·12 The week in cyber — 7 to 11 September 2026 The EU’s vulnerability clock started, Microsoft shipped a record Patch Tuesday, CrowdStrike’s sensor became an escalation path, and Parliament said no to personal director liability — four things, each with a decision attached. weekly · governance · ned · board 5 min 2026·09·10 What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it. regulation · governance · board · ned · supply chain · vulnerability management 22 min 2026·09·08 No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why. governance · policy · board · regulation · ciso 9 min 2026·09·08 Trezor, ShipMonk, and the deletion that never happened Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances. breach · supply chain · privacy · governance · board 15 min 2026·09·04 The week in cyber — 31 August to 4 September 2026 Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached. weekly · governance · ned · board 6 min 2026·08·31 The UK threat landscape: August 2026 The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days. threat landscape · monthly · ransomware · governance · board · cni 33 min 2026·07·25 The week in cyber — 20 to 24 July 2026 A zero-click Russian email campaign, a SharePoint patch trailing its own exploitation, an AI agent that escaped its sandbox, and a council insider nobody was watching — four containment failures and the board questions they leave behind. weekly · governance · ned · board 5 min 2026·07·19 Buying the breach: cyber due diligence, a board read In a deal you don't just buy revenue — you buy the unpatched servers, the undisclosed incidents, and whoever is already inside the network. A board read on cyber due diligence: what's at stake, what to ask before signing, and why a court just put a PE sponsor on the hook. governance · ned · board · m&a · due diligence 10 min 2026·07·19 DORA, a board read: the rulebook that followed you home The UK left the EU. DORA did not leave the UK. A plain-English board read on the Digital Operational Resilience Act — who it reaches on this side of the Channel, why Article 5 puts it on your desk personally, and what a director should be able to evidence. regulation · governance · ned · board · resilience 10 min 2026·07·18 The week in cyber — 13 to 17 July 2026 Allied agencies named the FSB unit scanning UK routers, Microsoft shipped its largest patch on record with two flaws already exploited, the Cyber Security and Resilience Bill reached the Lords, and a poisoned npm package walked around this year's install-time defences. weekly · governance · ned · board 5 min 2026·07·17 Cyber security for the non-executive director: the NED's real job Cyber is now a tier-one board risk, but most non-executive directors were never trained for it. What the cyber security NED role actually demands — the questions to ask, the frameworks that matter, and how to hold a board to account without being technical. cyber security · ned · board · governance 10 min 2026·07·11 The week in cyber — 6 to 10 July 2026 Whitehall credentials for sale after a Fortinet campaign that needed no zero-day, a voluntary pledge launched at Number 10 that most of the FTSE ignored, the Bank of England naming frontier AI as a stability risk, and npm about to break your build on purpose. weekly · governance · ned · board 7 min 2026·07·04 The week in cyber — 29 June to 3 July 2026 A CitrixBleed sequel exploited within a day, on-prem SharePoint on a patch clock that runs out today, the police pricing UK ransomware and asking you not to pay, and the Cyber Security and Resilience Bill heading for the Lords. weekly · governance · ned · board 6 min 2026·06·29 The week in cyber — 24 to 28 June 2026 Cisco phone systems, an engineering PLM vault and the Linux kernel each turned into a route to root in the same week — against a CISA patch deadline that fell on Sunday. weekly · governance · ned · board 5 min 2026·06·20 FortiBleed: your firewall, turned into a wiretap An update on the FortiGate exploitation story. SOCRadar's dismantling of FortiBleed shows 430,000 firewalls targeted and 110 million credentials harvested — by turning the appliance's own diagnostics into a credential tap. A board read, then the technical detail. fortinet · credential theft · threat analysis · board 8 min 2026·06·20 Prinz Eugen: the ransomware that takes your newest work first A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown. ransomware · threat analysis · technical · board 15 min 2026·06·20 The week in cyber — 15 to 19 June 2026 The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account. weekly · governance · ned · board 6 min 2026·06·19 The criminals have a product team now: The Gentlemen and the industrialised EDR-killer A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model. ransomware · byovd · endpoint · board 6 min 2026·06·13 The week in cyber — 8 to 12 June 2026 Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other. weekly · governance · ned · board 6 min 2026·06·06 The week in cyber — 1 to 5 June 2026 A self-propagating worm hiding under Red Hat's npm name, two actively-exploited flaws at the edge and the core of the typical UK network, an Android zero-day in the June update, and the Cyber Security and Resilience Bill reaching its final Commons stage. weekly · governance · ned · board 5 min 2026·05·30 The week in cyber — 25 to 29 May 2026 GCHQ's director on a 'moment of consequence', the TrapDoor supply chain campaign reaching into AI coding assistants, the Cyber Security and Resilience Bill still grinding through Report Stage, and quantum quietly becoming a 2026 planning item. weekly · governance · ned · board 6 min 2026·05·27 What is AI in 2026 One word is doing too much work. What people actually mean when they say "AI" in 2026 — neural networks, NLP, LLMs, generative AI, and agentic AI — what each one is, and which conversation you are actually in. ai · explainer · governance · board · series 22 min 2026·05·23 The week in cyber — 18 to 22 May 2026 A self-spreading npm worm, a government letter that boards should read, and the second-quietest Patch Tuesday in two years. What the past working week looked like through a UK board lens. weekly · governance · ned · board 6 min 2026·05·16 The week in cyber — 11 to 15 May 2026 A self-spreading npm worm hit TanStack, Patch Tuesday had its quietest month in two years, the Cyber Security and Resilience Bill moved to Report Stage, and the ICO issued a five-step plan boards should actually read. weekly · governance · ned · board 6 min 2026·05·14 Things I wish boards would actually ask Twelve questions that would tell you more than any maturity score. None of them mention zero-trust. governance · ned · board 7 min 2026·05·09 The week in cyber — 4 to 8 May 2026 The ICO fined South Staffordshire Water nearly £1m, the DSIT cyber newsletter quietly confirmed the regulatory direction of travel, and the Canvas extortion played out on a public timeline. weekly · governance · ned · board 5 min 2026·05·04 The £320 myth: what Cyber Essentials actually costs Cyber Essentials is marketed from £320. For an unprepared 10-person UK business under the new v3.3 Danzell question set, the true first-year cost is £13,000 to £30,000 over 10 to 14 weeks. Here is the breakdown. cyber essentials · small business · ned · board · governance 9 min 2026·05·02 The week in cyber — 27 April to 1 May 2026 A learning platform serving thirty million people was breached, cPanel disclosed a zero-day that had been live in the wild for months, and April closed as the worst month for ransomware on record. weekly · governance · ned · board 5 min 2026·04·25 The week in cyber — 20 to 24 April 2026 NCSC and CISA named the Beijing-based outfit running covert botnets, the UK cyber chief told businesses to brace, and a sitting MP's website was hit with 142 million requests. A busy week. weekly · governance · ned · board 6 min 2026·02·14 The Cyber Security and Resilience Bill, a board read What the Bill actually does, what it changes for boards in and out of scope, and what the executive should be preparing to evidence over the next twelve months. regulation · governance · ned · board 8 min 2025·12·29 The year 2025 was actually about An end-of-year reflection on what 2025 turned out to be, what the noise mostly was, and what the genuinely consequential shifts were for UK cyber security at board level. annual review · governance · ned · board 8 min 2023·02·07 Digital privacy for board directors: the eighteen-post version An honest start to a long series. What digital privacy actually means for a board director in 2023, why the home / travel / work boundary is the right framing even though it leaks, and why children deserve four of the eighteen posts. privacy · ned · board · series 6 min

→ all tags  ·  all writing