Fort Pulaski, Revisited

Fort Pulaski, Revisited

By Ken Phelan
Posted in Security
On October 01, 2026

Sixteen months ago, I wrote about a fort.

Fort Pulaski was state of the art in 1847. Eleven-foot walls, an eight-foot moat, and a full mile of open water between it and any ground an army could stand on. Then the Union showed up with rifled cannons nobody had planned for, and thirty hours later it was over. The lesson is that innovation favors the attacker, and that the right posture for a defender isn't prediction. It's humility.

I closed that piece with one word.

Resiliency.

That's a fine word. It's also the kind of word that sounds like an answer but isn't. So let me try to do better.

Scoring my own homework

I made three calls in that post. Supply chain attacks would get considerably worse. AI wouldn't deliver Terminator-grade genius attacks, but it would scale the effective ones. And spear phishing was about to get very good, very cheap, and very fast.

Two of those landed. The third landed harder than I wrote it.

In November of last year, Anthropic disclosed that a Chinese state-sponsored group had turned its own coding agent into an espionage tool and pointed it at roughly thirty organizations—technology companies, banks, chemical manufacturers, government agencies. The AI handled eighty to ninety percent of the campaign on its own. Humans stepped in maybe four to six times. Across the whole operation.

Last week Anthropic published a second report, covering December through August. A Russian operation hit more than twenty organizations and walked off with drone technology SDKs (software development kits), and three hundred thousand national identity records. A criminal crew pulled down 1.8 million Android apps and scanned them all for hardcoded secrets, then breached a single SaaS vendor and reached two hundred of its downstream customers. University students in China running what the report calls agent swarms—parallel subagents splitting up reconnaissance—produced multiple zero-days against security products inside of one month.

And one actor hit more than thirty AI companies in four days, looking for API keys. Not customer data. Keys.

The breakthrough I keep coming back to is this one: breaches that used to take weeks now take two to three hours.

What actually changed

Here's the part worth sitting with. Nobody invented a new attack.

The kill chain is the same kill chain. Recon, phish, exploit, move laterally, find the good stuff, take it. What changed is the cost of the labor inside it. Reconnaissance, exploit development, credential harvesting, sorting terabytes of stolen junk to find the twelve files that matter—that work is exactly what separated a well-funded nation-state from a guy in an apartment. It was slow, expensive, and it required people who were hard to find and harder to keep.

It isn't expensive anymore.

That's the Pulaski moment. Not a better cannon. A cannon that costs a hundredth of what it used to, that anybody can buy, and that can be aimed at everyone simultaneously. Anthropic's own phrasing is that AI has inverted the cost back onto defenders. I'd put it more plainly. The economics that used to protect you because you weren't worth the trouble are gone. You're worth the trouble now. Everyone is.

What does resiliency really mean

Four things. None of them are products.

Assume the credential is already gone. Every one of those campaigns ran on stolen access, not on some exotic breach of your firewall. And most of the identities in your environment aren't people—they're service accounts, API keys, tokens, integrations, and now agents. You almost certainly have more of them than you have employees, and nobody owns the list. The question isn't whether one gets taken. It's what it can reach on the day it does. If the honest answer is "most things," you don't have a detection problem, you have a blast radius problem, and no amount of monitoring fixes it.

Measure yourself in hours. If a breach completes in three hours and your mean time to detect is six days, you are not running a defense. You are running a forensics practice. That gap is the single most useful metric you have, and most organizations have never actually measured it. Not the vendor's metric. Yours.

Verify out of band, every time. No exceptions for the boss. Anything that moves money or grants access gets confirmed on a second channel. The voice on the phone is not evidence anymore. Neither is the video. The reason this control fails isn't that people don't know it,” it's that it feels rude to use it on an executive, which is precisely why executives are the ones being impersonated. Make it policy so nobody has to be the person who says no.

Practice. Not the policy document. The actual thing. Restore a system from backup and time it. Pull the network on a subsidiary and see who notices. Run a tabletop where the scenario is that your identity provider is compromised and you can't trust your own directory. You will learn more in that one afternoon than in a year of watching dashboards.

The obvious objection

None of that is new. Least privilege, fast detection, callback verification, tested restores. That's a 2015 security program with a fresh coat of paint. Where's the AI part?

There isn't one. That's the whole point.

The Pulaski garrison didn't lose because they lacked a counter-rifled-cannon strategy. Nobody had one. They lost because every assumption they'd built on—the mile of water, the range of a smoothbore, the idea that the walls were the hard part—stopped being true, and they found out on the morning of April 10th along with everyone else. A better prediction wouldn’t have saved them, but betting everything on the prediction they’d already made guaranteed their defeat.

Fundamentals aren't boring because they're old. They're fundamentals because they're the only things that keep working after the thing you didn't see coming shows up. And something always shows up.

The garrison at Pulaski had a fine fort. They just had the wrong assumptions about what a mile of water was worth.

Check yours.

Ken Phelan

Ken Phelan

Ken is one of Gotham’s founders and its Chief Technology Officer, responsible for all internal and external technology and consulting operations for the firm. A recognized authority on technology and operations, Ken has been widely quoted in the technical press, and is a frequent presenter at various technology conferences. Ken is the Chairman of the Wall Street Thin Client Advisory Council.