Articles by 'Ken Phelan'

Blog Author - Ken Phelan

Ken is one of Gotham’s founders and its Chief Technology Officer, responsible for all internal and external technology and consulting operations for the firm. A recognized authority on technology and operations, Ken has been widely quoted in the technical press, and is a frequent presenter at various technology conferences. Ken is the Chairman of the Wall Street Thin Client Advisory Council.

By Ken Phelan, Posted in Security

Sixteen months ago, I wrote about a fort. Fort Pulaski was state of the art in 1847. Eleven-foot walls, an eight-foot moat, and a full mile of open water between it and any ground an army could stand on. Then the Union showed up with rifled cannons nobody had planned for, and thirty hours later it was over. The lesson is that innovation favors the attacker, and that the right posture for a defender isn't prediction. It's humility. I closed that piece with one word. Resiliency. That's a fine word. It's a... read more.

  • October 01, 2026

By Ken Phelan, Posted in Security

On a Saturday in late September, we patched our remote-access gateways. Routine stuff. A vendor had published fixes for two critical vulnerabilities, CVE-2026-88771 and CVE-2026-88772, and we pushed the fixed build to both nodes that afternoon. Ten minutes of downtime. Nobody noticed. About 23 hours later, the attackers showed up. Some background. These two bugs weren't new to the attackers. They were already being exploited as zero-days before the vendor published a fix. The bad guys had a head start. Th... read more.

  • September 30, 2026

By Ken Phelan, Posted in Infrastructure, Security

This post was AI-assisted — researched and drafted with Claude, which should surprise exactly no one given who I am. The arguing and editing are mine. If it's wrong, blame me, not the machine. AI is raging in your organization right now. Not piloting. Not "under evaluation by a cross-functional committee." Raging. Every employee has tried it, most of them are using it daily, and the results look like every other distribution of human performance you've ever seen. A bell curve. Let me walk you throug... read more.

  • September 16, 2026

By Ken Phelan, Posted in Infrastructure, Security, Support

A few weeks ago I wrote a post called "It's Not the Model." The short version: frontier AI is finding vulnerabilities at industrial scale, the capability will land on every platform eventually, and the scarce resource isn't the model — it's the ability to absorb what the model finds. The reactions came in two flavors. Half the room heard "the sky is falling." The other half said "the sky was always falling, why are we talking about it now?" Both halves are wrong, and it's worth being precise about w... read more.

  • September 03, 2026

By Ken Phelan, Posted in Security

You've sat at this dinner. Eight security leaders around a table, good wine, better steak, and a conversational register I've come to think of as the auditor voice. Everyone has a mature program. Everyone's board is engaged. Everyone is "well positioned" on AI. By dessert you start to wonder whether your dinner companions are interviewing for their next role or rehearsing for their next examination — because nobody talks like that to people they trust. Here's the thing: I don't blame them. The perfo... read more.

  • August 03, 2026

By Ken Phelan, Posted in Infrastructure

Everyone wants to talk about AI. Nobody wants to talk about the thing that's going to determine whether AI pays off: your data. Here's the uncomfortable truth I keep running into with clients. The models are fine. The models are, frankly, astonishing. If your AI initiative fails, it almost certainly won't be because the model wasn't smart enough. It will be because the model couldn't get to your data, or because getting it there cost more than the value it created. The Access Problem We spent the last fi... read more.

  • July 22, 2026

By Ken Phelan, Posted in Security

Last night I had the privilege of introducing Check Point's Dan Taney to a room full of New York CISOs. Preparing that introduction sent me down a memory lane that turned out to be less about nostalgia and more about strategy. I want to share some of it here, because the story of our oldest partnership says a lot about how Gotham thinks about technology — and about what's coming next. The Original Partnership Myself and the rest of the Gotham leadership were Check Point partners from the beginning.... read more.

  • July 16, 2026

By Ken Phelan, Posted in Infrastructure

So anyway, let me tell you about the robots. In 1950, Detroit employed over 220,000 auto workers. Good union jobs. Good wages. By 1970, half of them were gone. Not to Mexico. Not to China. To robots and assembly line automation that simply didn’t need much human labor. By 1982, another 400,000 jobs disappeared in just four years. Cities hollowed out. Communities devastated. Here’s the part that surprised me. Cars didn’t get cheaper. All that productivity. All that automation. A robot-ho... read more.

  • May 21, 2026

By Ken Phelan, Posted in Security

Fort Pulaski was completed in 1847. Built as a response to the War of 1812, it was a state-of-the-art fort built to protect the port of Savannah. Its walls were 11 feet thick and the moat was eight feet wide. But the real genius lay in its location. On an island in the middle of the Savannah River, it was a full mile from the nearest land on Tybee Island. It could not be approached by land. The smoothbore cannons of the time had a range of about half a mile, therefore land-based cannons could not be brought... read more.

  • May 15, 2025

79%

By Ken Phelan, Posted in Security

I spent some time with the CrowdStrike team last month going through their annual Global Threat Report. If you haven’t seen it, please do. This should be required reading for every cyber operator - https://go.crowdstrike.com/2025-global-threat-report.html 79 is the percentage of breaches that occurred without malware. Hence the much-used quote, “hackers don’t break in, they log in.” For years a quick explanation of cyber-attacks read as follows: Software has vulnerabilities. Ha... read more.

  • April 10, 2025