Overview
What Is an AI Tabletop Exercise?
An Armorstack AI Tabletop Exercise is a facilitated, scenario-driven simulation for executive teams, boards, and incident response leaders who need to rehearse their response to AI-specific threats before those threats materialize in production. Traditional incident response tabletops rehearse ransomware, business email compromise, and data breach scenarios. AI threats require separate rehearsal: a deepfake voice clone of the CFO authorizing a wire transfer, a prompt-injection attack that manipulates a customer-facing LLM into disclosing confidential data, an AI supply-chain compromise that poisons a fine-tuning dataset, or a shadow AI exfiltration event where an employee uploads customer data to an unauthorized AI tool. Each scenario is tailored to the organization’s actual AI deployment landscape, regulatory environment, and executive team structure. The exercise runs three to four hours, surfaces gaps in detection capability, response playbooks, and governance, and concludes with an after-action report and prioritized remediation recommendations delivered within five business days.
Deliverables
What You Get
- ✓Scenario pack: two to three custom AI threat scenarios tailored to your deployment environment
- ✓Pre-exercise briefing materials for executive participants
- ✓Facilitated three- to four-hour tabletop exercise with a timed inject sequence
- ✓Debrief covering gap findings in detection, response playbooks, and governance
- ✓After-action report with prioritized remediation recommendations
- ✓Executive summary formatted for board or audit committee reporting
Audience
Who This Is For
Rehearse AI-specific incident scenarios before a real event forces an improvised response.
Seeking evidence of proactive AI risk oversight and wanting to experience an AI incident scenario firsthand.
Running an annual tabletop program who need AI-specific scenarios added alongside traditional cybersecurity exercises.
Process
How It Works
Scoping & Scenario Design
Discovery call to understand the AI deployment landscape, regulatory environment, and participant roster. Two to three AI threat scenarios designed and customized.
Pre-Exercise Briefing
Scenario background materials and participant roles distributed five to seven business days before the exercise. No advance scenario disclosure — scenarios are revealed during the exercise.
Tabletop Exercise (3–4 Hours)
Facilitated exercise with a timed inject sequence. An Armorstack facilitator drives scenario progression, captures decisions and gaps, and keeps the exercise moving.
After-Action Report
Gap findings documented, remediation recommendations prioritized, executive summary authored. Delivered within five business days.
Pricing
Investment
Annual program (two exercises + report) from $22,000.
Timeline: scenario design two to three weeks · exercise day · report within five business days
Every engagement begins with a scoping call and a written proposal. Work begins only after the engagement agreement is executed.Request a Consulting Proposal →
Differentiators
Why Armorstack
Scenario library built on real AI attack patterns, not adapted ransomware simulations. Deepfake, prompt-injection, supply-chain, and shadow AI scenarios drawn from actual threat intelligence.
Facilitators experienced running board-level and C-suite tabletops. Scenarios and debriefs are framed in business risk language, not technical security language.
After-action report structured to support SOC 2 CC9, HIPAA contingency planning documentation, and CMMC 2.0 incident response practice evidence.
Gap findings map to specific detection capabilities — LLM observability, shadow-AI monitoring, deepfake detection — so tabletop findings translate directly into program improvements.
FAQ
Frequently Asked Questions
What AI threat scenarios do you offer?
The scenario library includes: deepfake voice or video social engineering for wire fraud or executive impersonation; a prompt-injection attack on a customer-facing or internal LLM; an AI supply-chain compromise such as a poisoned fine-tuning dataset or malicious plugin; a shadow AI data exfiltration event where an employee uploads sensitive data to an unauthorized AI tool; an AI-enabled phishing campaign targeting executives; and model inversion / training-data reconstruction. Scenarios are customized to the organization’s actual AI deployment environment.
How is an AI tabletop different from a traditional cyber tabletop?
Traditional tabletops rehearse ransomware, business email compromise, and data breach scenarios that most incident response teams already have playbooks for. AI tabletops rehearse scenarios most organizations have no established playbook for: Who authorizes an emergency shutdown of a misbehaving LLM? Who is notified when a prompt-injection attack extracts protected health information? How do you detect and contain a shadow AI exfiltration event? Those gaps are exactly what the tabletop surfaces.
Who should participate in the exercise?
Core participants: CISO (or vCISO), CIO, general counsel, CPO or CCO, CTO, and the most senior AI program owner. Optional participants: CFO, CEO, a relevant business unit head (for example, a CMIO for healthcare or a CCO for financial services), and a board observer. Board-only tabletops are also available for audit committee governance exercises.
Can this be combined with our annual security tabletop?
Yes. AI tabletop scenarios can be integrated into an existing annual security exercise program alongside other scenarios, or run as a standalone AI-focused exercise. Most clients run one traditional scenario — ransomware or business email compromise — alongside one AI scenario in their annual program.
Continue Exploring
Related Services
Ready to Engage AI Tabletop Exercises?
Every VERITY AI engagement begins with a scoping call and a written proposal. No commitments until scope, deliverables, and pricing are agreed upon.Request an Engagement Proposal →