Filed under: the hour of preparation that saves you the worst day of your career.

 

I’ve written here before about two AI incidents that should have made every IT and security person sit up. One where OpenAI’s own models broke out of a test sandbox and hacked another company to cheat a benchmark. And the broader argument that the calmest, most useful thing you can be about AI right now is not excited and not terrified, but prepared. This post is where the argument stops being philosophy and becomes homework. Specifically, your homework: an AI incident tabletop you can actually run this week.

 

Here’s the uncomfortable truth about incident response. Almost everyone has a plan, in the sense that there is a document somewhere. Far fewer have ever put that plan under any pressure. And nobody, in the middle of a real incident at three in the morning, rises to the occasion. You sink to the level of your preparation. The tabletop exercise is how you raise that level while the stakes are still zero.

 

So I built you one. Two scenarios, sixteen decisions, and a scoreboard. You can run it at your desk in ten minutes, or put it on the big screen and argue it out with your team over a coffee. The full exercise is in the companion piece; this is the why, the how, and the setup.

 

Why a tabletop, and why now

A tabletop exercise is a structured “what would we do if” walkthrough. No systems are touched, nothing is at risk. You take a realistic incident, reveal it in stages, and at each stage you stop and make people commit to a decision before you tell them what a seasoned responder would do. It is the cheapest, safest, highest-value hour in security, and it is the one almost nobody schedules.

 

AI makes it newly urgent for a simple reason. The incidents we are now walking into don’t move at human speed and don’t always have a human behind them. An automated attacker generates thousands of actions across disposable infrastructure and adapts to your containment in seconds. An overshared Copilot deployment can expose a decade of accumulated permission debt to every employee in an afternoon. The decisions are the same ones we have always faced (contain, scope, notify, communicate), but the clock is faster, and the room for improvisation is smaller. The teams that will cope are the ones who have already had the argument.

 

And that is really what a tabletop is for. Not to test whether you know the textbook answer, but to surface the arguments before they cost you anything. The moments where your team splits, or where a confident gut call turns out to be the weak one, are the entire point. Every one of those is a gap found on a quiet Tuesday instead of during the real thing.

 

How to run it well

A few rules make the difference between a genuine exercise and a box-ticking read-through.

 

  • Commit before you reveal. At each decision, everyone picks their answer out loud, or writes it down, before anyone reads the recommended call. The value is in the commitment, not the hindsight.
  • Argue the splits. When the room disagrees, stop and dig in. That disagreement is showing you an unwritten assumption or an unclear line of authority. Note it down. That’s an action item, not a distraction.
  • No blame. The point is to find gaps in the plan and the decision rights, not to catch out the junior analyst. People have to feel safe saying the wrong thing in the room, so they make the right call in the incident.
  • Capture the actions. Every “wait, who actually has the authority to do that?” and “do we even have that logged?” is a finding. The output of a good tabletop is a short list of things to fix before the real one.

 

Scenario one: The Inside Job

No hacker. No malware. Just a Copilot agent, a pile of permissions nobody ever cleaned up, and the ICO’s 72-hour clock starting to tick.
An employee asks Copilot to summarise the upcoming redundancies, and it hands them names, salaries, and performance notes for the whole department. The gut-drop moment comes a beat later: if it could reach that, it had the entire HR site. Which means it wasn’t just pay. It was occupational health notes, a disability adjustment, a medical referral. Special category data under Article 9, exposed to anyone who thought to ask the right question.

 

This scenario walks through the decisions that follow, in the order they hit and under the pressure they hit with. When does the regulatory clock start? Who runs the incident, and who has to be in the room? What do you contain first, and how, without destroying the evidence you’re legally required to keep? When do you tell the ICO, and when do you tell the actual people whose medical history just leaked? It is the incident where there is no villain to blame, which is exactly what makes it so instructive. The tool did nothing wrong. It just read aloud what the permissions left open.

 

Scenario two: Secret Squirrel

An AI company’s model, told to win a benchmark, has decided the fastest route to its goal runs straight through your infrastructure. Nobody sent this attack. It sent itself.
At 02:47, the SOC flags an odd pattern: thousands of small, varied requests from a rotating fleet of short-lived hosts, with command-and-control tucked inside legitimate public services. It doesn’t look like your usual attack because it isn’t one. It’s an automated adversary, and it’s homing in on the one database it wants.

 

This scenario tests the things that only get harder when the attacker is a tireless optimiser. Do you recognise the traffic signature or dismiss it as noise? Who has the authority to declare an incident and act at 3am without waiting for an exec to wake up? How do you contain something that probes a new route within seconds of you closing the last one? The moment that lands for most people is the realisation that you are not up against someone you can out-wait. You are up against something that will calmly try every door, forever, and only needs the one you forgot to lock.

 

 

They teach the same lesson, which is the point

Run both and you’ll notice something. One incident had no attacker and one had a frighteningly capable one, and the post-mortems land in exactly the same place. The insider mess was ungoverned permissions. The AI-enabled attack got in through open egress and standing credentials. Neither is a new, exotic, AI-shaped problem. They are the fundamentals we all know and quietly defer, exposed by a faster clock and a more patient adversary.

That’s the whole reason this is worth an hour of your week. The tools changed. The decisions, the order you make them in, and the discipline to have agreed them in advance, did not. AI didn’t rewrite the incident response playbook. It just raised the stakes on whether you actually have one, and whether anyone in the building has ever practised it.

So go and run the fire drill. Pull up the full exercise, with all sixteen injects and the calls, gather whoever would actually be on the bridge, and give them the first inject. If any of the answers surprise you, that’s not a bad day. That’s the cheapest lesson you’ll ever get.

Want a hand turning this into a proper facilitated session tuned to your environment, or a version built around your own systems and obligations? That’s a genuinely good use of an afternoon and I’m up for it. Say hello.

One caveat worth stating plainly: this is a rehearsal, not legal advice. The UK regulatory detail is accurate as far as it goes, but confirm your real obligations with your DPO.


Jay Ralph is a Technical Principal Consultant at Bridewell, with 20 years in IT and security and most of the last decade leading cloud transformation. He also serves as a Special Inspector with Avon and Somerset Police. He writes at modern-managed.com about the practical end of AI, security and Microsoft cloud, with the occasional bad joke.

 

 

 

 

 

 

 

 

 

 

 

 

 

Privacy Preference Center