Peter Bassill — latest writing on cyber security
Latest articles
-
The 999 lines held: Dyfed-Powys Police and the staff question
Dyfed-Powys Police kept 999 and 101 running through a cyber incident and has so far found no evidence the public's data was accessed; staff data is still under investigation. What went right, what "technical difficulties" costs, and why your own people should never hear last.
-
The week in cyber — 21 to 25 September 2026
A BIG-IP zero-day already under attack, Revolut's second breach this month, prompt-injected AI agents at Salesforce, an AI phishing service dismantled by Microsoft and the Met, and a whisky retailer undone by a bolt-on app — five stories, all about trust handed to someone else.
-
Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review
A London property manager kept bank details, passwords and key-safe codes where a cloud analytics tool could read them; a vulnerability in that tool did the rest. Why "the cloud" is not a security decision, and a supplier review you can actually run and evidence.
-
Aimed at a person, not a network: Iran's CHOSEN BRICK
The NCSC, FBI and AIVD have published a joint advisory on CHOSEN BRICK, Windows malware Iranian state actors use to find, watch and expose dissidents, activists and journalists. A fake MRI result, a fake Norton, a Telegram bot, and a deliberate move from the work laptop to the home one. What it does, how to look for it, and what employers of people at risk should do this week.
-
The week in cyber — 7 to 11 September 2026
The EU’s vulnerability clock started, Microsoft shipped a record Patch Tuesday, CrowdStrike’s sensor became an escalation path, and Parliament said no to personal director liability — four things, each with a decision attached.
-
What shipped, and when did you know: the Cyber Resilience Act's clock starts tomorrow
From 11 September 2026, anyone selling software or connected hardware into the EU has 24 hours from the moment they know a flaw is being exploited to tell a national CSIRT. What that means, what it does not yet mean, and why it reaches British firms that never signed up to it.
-
No personal liability, no change: the Cyber Security and Resilience Bill misses the one lever that works
Peers asked why the Cyber Security and Resilience Bill lets executives off the personal liability hook. The Government said corporate fines are enough. Thirty years of watching boards tells me they are not, and here is why.
-
Trezor, ShipMonk, and the deletion that never happened
Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances.
-
The unmarkable exam: the child-safety law no one is allowed to grade
The Children's Commissioner told a Lords committee that children say the Online Safety Act has made "absolutely no difference" — and that she can't judge it, because Ofcom won't release the platforms' risk assessments. A law built to be unmarkable has already told you something.
-
The week in cyber — 31 August to 4 September 2026
Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached.
-
The consent nobody sought: Britain says no to the keys
Someone finally asked the public — and across every party, Britain said it would not trust the state with the keys to its private life. A sidebar to the series that goes to the foundation the whole age-verification project rests on: a consent never sought, and never given.
-
The UK threat landscape: August 2026
The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days.
-
The honeypot changes address
Part 11: Meta settles the US child-safety case for up to $18bn and the UN comes out against outright bans — the week the ban model lost the argument. But the age check just moved from the platform to the app store, and the identity honeypot moved with it.
-
AI-generated harm against children in 2026
Revisiting the September 2024 post on deepfakes and children. UK law has criminalised creation of intimate deepfakes of minors. Schools have policies. The IWF reports massive growth in AI-generated CSAM. Voice clone fraud is mature. What has actually changed and what to do.
-
Struck down before the start: France's court reads the argument back
Part 10: eighteen days before launch, France's Constitutional Council struck the under-15 ban down — on the grounds this series pressed: disproportion, and age verification with no guarantees for private life. A reprieve, but the redraft is already commissioned.