June 17, 2026
The Base Is Under Attack
This post is part of my Medium blog.
Listen to people talk about InfoSec these days — the conferences, the trade press, the vendor decks, the Slack threads — and you'll hear a specific tone. I'm going to describe it with a movie scene, and you're going to name it before I do.
An underground base on a frozen planet. The enemy knows exactly where it is. Massive mechanical walkers — walking tanks the size of buildings — are advancing across the ice. The defenses can't stop them. The people inside aren't trying to fight back. They're frantically trying to get a broken ship working so they can just escape — not win, not hold the line, just get out before something catastrophic and unstoppable reaches the door.
The whole opening is just people preparing. Rushing. Running checks on equipment that isn't ready, coordinating defenses that won't hold, buying time against something too large and too fast to stop. Nobody's planning a counterattack. The entire operation is: slow it down long enough to get out.
The Empire Strikes Back.
That's what the conversation around InfoSec sounds like right now. The base is under attack. The walkers are AI-generated vulnerabilities, automated exploit chains, and speed that no human team can match. The framing has shifted from defending the perimeter to just getting the ship started — not winning, just getting out.
Go back and watch that opening sequence carefully. There are hundreds of faceless Rebel troopers in that scene — no names, no lines worth remembering — scrambling to hold the perimeter, buy time, absorb the blow. Some of them continue to fight. But maybe some already understand that the base is lost.
Han is out on the ice looking for Luke. Leia is already on the transport, making sure the mission survives. The main characters aren't defending the base — they've concluded the only way to answer the threat is to move. Most of the InfoSec conversation right now sounds like those faceless troopers: fortify what's there, slow the walkers down, hold long enough for something to change. A few people are thinking like Han. They're not buying another scanner. They're asking whether there's a different way off the planet entirely.
Here's the disconnect: most InfoSec departments have spent decades being handed a finished base and asked to defend it. Here are the walls, here are the doors, figure out the locks. This new application uses Node.js — go defend it. That was already a compromise. AI-accelerated attacks don't break that model — they expose that it was never a real model to begin with. The shift that actually matters isn't a better scanner or a faster response team. It's security people in the room when the data model is chosen, when the dependency list is assembled, when the authentication scheme is designed — before any of those systems are in production. Not reviewing the finished base. Deciding whether to build it this way at all.
"Machine speed" has become a conference catchphrase, which usually means it needs translation. Here's what it actually looks like pointed at you: a network of agents found a zero-day in ffmpeg and didn't announce it anywhere — just filed it internally. A second agent scraped your team's LinkedIn and X and noted who's in Cancun next week. A third logged your nightly load balancer latency blip as attack cover. A fourth studied your last three incident reports and estimated a 30-minute detection window. The whole operation — reconnaissance, timing, coordination — ran in seconds. What previously required a dedicated red team and weeks of planning is now background processing, running continuously, waiting for the right moment.
One thing gets patched and three more appear. Most security teams already know this. The ones who don't are about to.
Here's what the conversation keeps missing: the walkers aren't the real problem. The problem is that we've been building bases that were always going to need to be evacuated.
The response to AI-accelerated attacks is almost entirely defensive. Tighten npm's signing requirements. Fund the Maven repository. Add another scanner to the pipeline. These aren't wrong. They're just not enough — a better lock isn't enough when the door frame is rotten.
Most security professionals have spent their careers being handed finished systems and asked to hold them. That was the design of InfoSec as a discipline: a defense function, not a design function. AI doesn't break that model — it just makes the consequences undeniable.
Most of the industry is still shopping for scanners.
Some bases aren't worth defending. Build something that is.
In Essential, the third book in The Condition Set trilogy, the law that requires a human to remain in the decision loop is ninety days from expiring. Rob Coleman runs the agency that oversees every AI system in Canada. The question isn't whether the machines work. The question is whether anyone can tell when they stop working in the public's interest.