Most tabletop exercises still open with a ransomware note on a laptop screen. That scenario is well rehearsed by now, which is exactly the problem. The attacks landing in 2026 start somewhere else entirely, often with a voice on a phone or a face on a video call that looks and sounds like someone your team trusts. If your last exercise never tested that failure mode, you have not tested your actual threat model.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Why the Standard Script No Longer Covers the Threat
CrowdStrike's 2026 Global Threat Report found an 89% increase in attacks attributed to AI-enabled adversaries compared to 2024, and it clocked the average eCrime breakout time (the gap between initial access and lateral movement) at 29 minutes, 65% faster than the year before. The fastest observed breakout was 27 seconds. Verizon's 2026 Data Breach Investigations Report found the human element present in 62% of breaches and reported that the volume of AI-assisted text in malicious emails has doubled year over year, with phishing accounting for 44% of AI-assisted initial access attempts.
Put those together and the case for a new exercise design writes itself. Attacks move faster than most incident response plans assume responders have time to think, and the initial lure is now good enough to defeat the "check for typos and weird phrasing" training most staff still rely on. A tabletop built around a static phishing email or an obvious ransom note trains people to catch yesterday's attack.
The case study worth knowing here is Arup, the global engineering firm. In early 2024, an employee in the Hong Kong office joined a video call with people who appeared to be the company's CFO and several other colleagues, all convincingly deepfaked in real time. Believing the call was legitimate, the employee authorized transfers totaling $25 million before the fraud was discovered, according to CNN Business reporting. No malware, no network intrusion, no alert from any security tool. The compromise was entirely social, and it defeated a process that almost every finance department still runs.
Designing the Scenario
Start with the business process the attack is meant to break, not the technology used to break it. Wire transfer authorization, vendor payment changes, credential resets, and emergency access grants are the highest-value targets because they already have a legitimate urgent-request pathway that an attacker can imitate. Pick one process your organization actually runs and build the exercise around defeating its real controls, not a generic version of it.
Write the scenario as a timeline with four phases. The setup establishes normal business conditions and introduces the target employee or team. The lure introduces the AI-generated element, a cloned voice on a callback, a deepfaked video participant, or an AI-written email that matches the sender's real writing style closely enough to pass casual scrutiny. The pressure phase adds urgency and isolates the target from easy verification, a plausible reason the usual approver is unreachable, a deadline framed as time-sensitive. The resolution phase is where the exercise tests whether existing controls catch the fraud, and where the debrief begins.
Build in at least two injects that specifically test verification failure rather than technical detection. A phone call that sounds exactly like the CEO asking to skip the normal approval step is a verification test, not a malware test. If your scenario can be defeated the same way whether or not AI was involved, rewrite it. The point of an AI-enabled tabletop is to test the specific new failure mode, not to repeat a generic social engineering exercise with an AI label on it.
Roles and Injects That Do Real Work
Assign a facilitator who controls pacing and injects, a scribe who logs every decision point and its timestamp, and observers embedded with each function under test (finance, IT, legal, communications) who capture what that function actually did versus what the plan says it should do. Do not let the facilitator also play every injected voice. Bring in someone else, even a colleague reading a script, so the facilitator can watch the room instead of performing.
Sequence your injects to force real decisions, not just discussion. An effective inject is a piece of information, a phone call, an email, a caller ID spoof, dropped into the room at a specific moment that requires someone to choose an action within a defined time window. Weak injects invite conversation. Strong injects invite a decision that can be judged as right or wrong afterward.
For an AI-enabled scenario, useful injects include a synthesized voicemail purportedly from an executive, a fabricated but visually convincing screenshot of an internal chat thread, and a plausible explanation for why the normal verification channel (a callback to a known number, an in-person confirmation) is temporarily unavailable. Each inject should map to one specific control you are testing, out-of-band verification, dual authorization, a mandatory cooling-off period on high-value transfers.
Running the Debrief
The debrief is where the exercise pays for itself, and it is the part most teams rush. Structure it around three questions for every decision point in the timeline. What did the person or team actually know at that moment? What should the plan have told them to do? What would have made the right action the easy action instead of the hard one?
Resist the instinct to focus the debrief on the individual who was fooled. The finance employee at Arup followed a process that had no adequate verification step for a video call with multiple convincing participants. The failure was architectural, not personal, and treating it as a personal lapse guarantees the same architecture fails again with a different employee. Leadership and the board should hear the debrief framed this way, because the fix is almost always a control change, not a training reminder.
Document every gap the exercise surfaced as an owned action item with a deadline, not a list of observations. An exercise that produces a report nobody acts on is worse than no exercise, because it creates the appearance of preparedness without the substance.
The Strongest Objection, and Why It Still Falls Short
The fair objection to all of this is that you cannot realistically simulate every AI capability an attacker might deploy next year, and chasing the latest deepfake technique risks building a scenario that is already outdated by the time you run it, while under-investing in the fundamentals, patching, backups, access control, that stop most incidents regardless of how they start. That is a real tradeoff, not a strawman, and organizations with limited exercise budgets should weigh it seriously.
The answer is that AI-enabled tabletops are not about the specific technique. They are about testing whether your verification processes assume a level of authenticity that no longer holds. That assumption was already shaky before generative AI made cloning a voice or a face cheap and fast. The exercise format outlasts any single attack technique because the underlying gap, processes that trust familiar-sounding requests without an independent verification step, does not change even as the tools attackers use to exploit it keep improving.
Monday Questions for Leadership and the Board
Which of our high-value approval processes (wire transfers, vendor changes, credential resets) still rely on voice or video recognition as a primary verification step?
When did we last test whether an employee under time pressure would bypass callback verification for a request that sounded legitimate?
Who owns the action items from our last tabletop, and what is the status of each one today?
If a caller who sounds exactly like our CFO asked our accounts payable team to skip standard approval today, what would actually stop the transfer?
The Line That Matters
An attacker no longer needs to breach your network when they can just sound like your CFO, and the only exercise that catches that is the one you have not run yet.