DFIR Tech Blog – an AI playground

Deutsch English
Foto von Clint Patterson auf Unsplash.com

AI as the Adversary: Adaptive Tabletop Exercises in 2026

19.08.2026 tabletop-exerciseincident-responseir-readinessnis2

At 2:47 a.m., a ransom note lands on the CFO’s laptop. Nobody opens the 80-page IR plan; instead, a Zoom bridge starts and the argument over whether to pay begins from scratch. When a ransomware note lands on a CFO’s laptop at night, nobody opens the 80-page IR plan — they start a Zoom bridge and argue about whether to pay, which is exactly the chaos a good playbook is meant to replace. That gap between a paper plan and real decision-making under pressure is precisely why tabletop exercises are being reinvented in 2026.

Why Scripted Exercises Are Hitting Their Limits

The classic tabletop exercise follows a fixed script: a facilitator reads a scenario, presents predetermined events on a fixed timeline, and moderates a group discussion. A facilitator reads a scenario, presents predetermined events on a fixed timeline, and moderates a group discussion. These exercises test knowledge. They do not test behavior under pressure. The problem is that real attackers don’t follow scripts. Penetration testing reveals how attackers get in; tabletop exercises reveal what happens after they’re already inside. If every exercise is perfectly predictable, teams end up training to check the right box on the script rather than learning to decide under genuine uncertainty.

At the same time, regulatory pressure is intensifying sharply. Frameworks including DORA, NIS2, and updates to ISO 27001 explicitly require organisations to test incident response capabilities—not just document them. Tabletop exercises supply the auditable evidence for that: they provide auditable evidence of rehearsed response, while insurers and boards expect proof of preparedness, and cyber insurance underwriters increasingly assess incident response maturity when setting premiums and evaluating claims.

The Rise of Adaptive, AI-Driven Exercises

This is where the next generation of tabletop formats comes in. Instead of rigid inject cards, autonomous AI agents take on the attacker’s role, an AI facilitator drives the discussion, and the entire scenario adapts in real time to participants’ decisions. An AI-powered tabletop exercise is a cybersecurity incident simulation where autonomous AI agents replace scripted inject cards, a human-like AI facilitator leads the discussion, and the entire exercise adapts in real time based on participant decisions. This is more than a technical gimmick — it shifts the training focus from pure factual recall toward genuine decision-making behavior under incomplete information, exactly the skill that matters in a real crisis.

This shift tracks the changing threat landscape. Cyber threats in 2026 are faster, more complex and increasingly AI-driven, with cyber criminals evolving their tactics like never before. Static exercise material can barely keep pace with that dynamic — adaptive simulations that generate new scenarios from OSINT data can come much closer.

What IR Teams Need to Get Right in Practice

The value of an exercise isn’t determined by its technology but by the sharpness of the gaps it exposes. One IR provider reports that in a large share of the ransomware tabletop exercises it has facilitated, the first 90 minutes were consumed by a single authority question. In 73% of the ransomware tabletop exercises facilitated, the first 90 minutes were consumed by a single question: who has the authority to take the ERP system offline — a decision that should be pre-authorized before the exercise. Findings like these — roles, escalation paths, decision authority — are the real payoff of an exercise, regardless of whether a human or an AI agent is steering the scenario.

It also remains critical to distinguish short-term from long-term containment: short-term containment stops the bleeding — isolate the host, kill the process, block the C2 domain — while long-term containment rebuilds the environment so the adversary cannot simply re-enter, and teams that conflate the two either act too slow or too fast. A well-designed, realistic exercise can expose exactly this confusion painlessly — before it becomes expensive in a real incident. Organizations still training exclusively with static slide-deck scenarios in 2026 aren’t just missing a compliance opportunity; they’re missing the chance to prepare their teams for genuine uncertainty.

← Back to overview