Your incident response plan probably has a section on ransomware notes, a section on phishing, and a section on insider threats. It almost certainly does not have a section on what to do when the incident report itself might be fake. That gap is not theoretical anymore, and it is the reason most incident response plans need an actual rewrite this year, not an annual refresh.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
The Scale of the Shift
CrowdStrike's 2026 Global Threat Report measured an 89% increase in attacks by AI-enabled adversaries compared to 2024. The same report found that 82% of detections involved no malware at all, meaning the attacker used valid credentials and trusted access paths rather than a payload your tools were built to catch, and it recorded a 563% increase in incidents using fake CAPTCHA lures as an initial access technique. Average breakout time, the window between initial access and lateral movement, dropped to 29 minutes, 65% faster than 2024, with the fastest observed case at 27 seconds.
Verizon's 2026 Data Breach Investigations Report, drawn from more than 22,000 confirmed breaches, found AI-assisted techniques deployed across a median of 15 distinct methods per documented campaign, with phishing accounting for 44% of AI-assisted initial access. The volume of AI-generated text in malicious emails has doubled year over year. On the exposure side, the same report found 45% of employees are now regular users of AI tools on corporate devices, and 67% of those employees are accessing AI platforms through personal, non-corporate accounts, invisible to most monitoring. Shadow AI usage registered as the third most common non-insider action flagged in data loss prevention systems, a fourfold increase from the prior year.
None of this means every incident now involves AI in an obvious way. It means AI has become embedded in both the attacker's toolkit and your own employees' daily workflow, on both sides of the incident before anyone declares one. A plan written for either side unchanged from three years ago is testing the wrong assumptions on both fronts.
Detection Assumptions That No Longer Hold
Most incident response plans still open detection and triage with signature-based or malware-based indicators as the primary trigger. With 82% of detections in CrowdStrike's dataset involving no malware, that assumption is now the exception rather than the rule for a meaningful share of intrusions. Update your detection section to treat identity-based anomalies, unusual access patterns from valid credentials, atypical use of legitimate integrations and approved automation tools, as a first-class trigger equal to malware alerts, not a secondary signal buried under them.
The 29-minute average breakout time also breaks any escalation path that assumes hours of runway between detection and containment decisions. If your plan's escalation chain requires sequential sign-off from three people before containment can begin, rewrite it so that a trained on-call responder can act within minutes and notify leadership in parallel, not before.
Communication Protocols for Claims You Cannot Immediately Verify
This is the section most plans are missing entirely. Build an explicit protocol for handling a scenario where someone reports receiving a call, video, or voicemail claiming to be a senior executive, a vendor, or a regulator, and the claim cannot be verified in real time. The Arup case, where a Hong Kong employee authorized $25 million in transfers after a video call with deepfaked participants who convincingly appeared to be the company's CFO and colleagues, is the reference case every plan should account for by name.
The protocol needs three elements your current plan almost certainly lacks. First, a mandatory out-of-band verification step for any high-value or high-sensitivity request that arrives through voice or video, a callback to a number stored independently of the call itself, not one provided during the call. Second, explicit authority for any employee to pause a time-pressured request without penalty, stated plainly enough that a junior employee will actually use it against a caller who sounds like a senior executive. Third, a communications holding statement prepared in advance for the specific scenario where your organization is threatened with release of material that may itself be fabricated, so legal and communications are not drafting a public response from scratch while under active pressure.
Legal and Forensic Considerations for AI-Generated Evidence
Chain of custody procedures written for digital evidence, log files, disk images, network captures, generally assume the evidence is a genuine record of what occurred, even if it needs interpretation. AI-generated content breaks that assumption at the source. A voice recording, video, or document may be entirely fabricated rather than authentic-but-misleading, and your forensic process needs a step that did not previously exist, an authenticity assessment before an evidentiary assessment.
Add a specific step to your evidence-handling procedure requiring authentication analysis, provenance checks, metadata review, and where available forensic detection tools, on any audio, video, or document evidence central to an incident, before that evidence informs legal or public statements. Coordinate this in advance with outside counsel, because the standard for what qualifies as admissible or defensible evidence in litigation or regulatory response is still being worked out across jurisdictions, and your organization does not want to discover its position on AI-generated evidence for the first time during an active incident.
The Worked Scenario
A mid-sized healthcare organization receives an email, appearing to come from its cyber insurance carrier's claims contact, requesting immediate wire confirmation of a deductible payment tied to an active incident the organization is, in fact, currently managing. The email references real details from the ongoing incident, correctly named systems, an accurate timeline, plausible enough that the finance team nearly processes it without escalation. Under the old plan, this would have routed as a standard phishing check. Under an updated plan, it triggers the out-of-band verification protocol specifically because it combines urgency, financial action, and knowledge of an active crisis, the exact profile the communications protocol above is built to catch. The organization calls the insurance carrier through the number in its policy documents, not the number in the email, and the request is confirmed fraudulent within twenty minutes.
The Strongest Objection to Rewriting Everything
A reasonable CISO will point out that most incidents still resolve through the same fundamentals that mattered five years ago, patching, backups, least privilege, and that reorganizing a plan around AI-specific scenarios risks over-indexing on the newest threat category at the expense of the boring controls that stop the majority of incidents regardless of cause. That objection is not wrong. The base rate of incidents that trace back to unpatched systems and weak access control has not disappeared, and no plan update should deprioritize those fundamentals to chase the current headline.
But this is not a case for choosing one over the other. The updates described here, identity-based detection triggers, out-of-band verification, evidence authentication steps, are additions to an existing plan's structure, not a replacement of it. They cost relatively little to add because they extend existing sections rather than building new infrastructure. The organizations that get this wrong are not the ones that keep their fundamentals. They are the ones that keep their fundamentals and stop there, leaving the newest and fastest-growing entry points completely unaddressed.
Monday Questions for Leadership and the Board
Does our incident response plan currently treat a credential-based intrusion with no malware as a first-class trigger, or does it still wait for a malware alert.
Do we have a documented, tested protocol for a request that arrives by voice or video and cannot be verified in real time.
Who on our team has explicit authority to pause a high-value transaction under pressure, and do they know they have it.
Has legal counsel weighed in on how we would authenticate AI-generated evidence before it shapes a public or regulatory statement.
The Line That Matters
The next incident report your team receives might not be real, and the plan that does not account for that is not an incident response plan anymore, it is a false sense of one.