The GRF Business Resilience Council's ORF Tabletop Exercise series challenges teams to test resilience, refine incident response, and share best practices through panel-led discussions with real-time inputs and data aggregation. Participants deepen their understanding of service dependencies and their ability to adapt and maintain operations across threat types.
In this iteration
Cybersecurity, risk, operations, and resilience leaders will work through a decision-driven scenario focused on third-party service disruption, testing how organizations detect, restrict, disconnect from, operate without, and safely reconnect to a critical third-party platform during uncertainty.
Speakers
Stephen Bartolini
Partner
Next Peak
Andrew Moyad
Chief Executive Officer
Shared Assessments
Keri Pearlson
Principal Research Scientist
MIT Sloan School of Management
Matthew Rogers
OT/ICS Lead
CISA's Office of the Technical Director
Susan Rogers
Operational & Cyber Resiliency
Russell & Associates
Matthew Welling
Partner, Data Strategy, Security & Privacy Group
Holland & Knight
Mike Wilkes
Chief Information Security Officer
Aikido Security
Exercise Goals
Test third-party disconnect / reconnect readiness
Examine your organization's ability to detect, assess, restrict, disconnect from, operate without, validate, and reconnect to a critical third-party service under uncertainty.
Clarify decision criteria, authorities, and communications
Identify the evidence, permissions, governance forums, stakeholder communications, and risk-acceptance considerations required to make disconnect and reconnect decisions.
Strengthen operational resilience during disruption
Explore how organizations sustain priority operations, manage degraded service, address dependency gaps, and protect customer-facing activities when a third-party platform can no longer be fully trusted.
Support collective resilience and peer learning
Compare approaches across participating organizations and sectors to surface practical lessons, shared challenges, and reusable practices that improve resilience to third-party disruptions.
Outcomes
Participants will surface gaps in their disconnect/reconnect decision frameworks, test minimum viable operations during third-party degradation, clarify authority and risk-acceptance structures, and gain actionable insights to strengthen collective resilience against third-party disruptions.
Frequently Asked Questions
Who should attend?
This exercise is designed for professionals in cybersecurity, risk, operations, IT, legal, communications, and business continuity who have a role in managing or responding to third-party service disruptions. Not every role listed needs to be present from a single organization. The goal is cross-sector representation.
Do I need technical knowledge to participate?
No. The scenario is designed to be accessible across roles. The focus is on decision-making, governance, and coordination, not technical remediation.
How will the exercise be conducted?
Participants are polled anonymously. The crowdsourced responses are discussed by the panel, analyzed, and later captured in an after-action report. Participants further their strategic understanding of service dependencies and their organization's ability to adapt and maintain operations.
Will this be a live cyberattack simulation?
No. This is a strategic discussion exercise, not a hands-on technical simulation. The focus is on decision-making and response planning. IT and third-party dependencies will be on display, and business priorities will determine response objectives.
Do I need to prepare anything in advance?
While no formal preparation is required, participants will benefit from reviewing their organization's incident response and operational resilience plans. Reviewing the Operational Resilience Framework is also highly encouraged.
How long will the exercise last?
The exercise is expected to last 3 hours, including scenario discussions and a debrief.
Will there be a post-exercise report?
Yes. An After-Action Report (AAR) will be provided to all participants, capturing key findings, lessons learned, and recommended actions.
The GRF Business Resilience Council's ORF Tabletop Exercise series tests participants' decision-making and lets organizations compare approaches across sectors.
Agentic Attack examines how organizations prepare for and respond to malicious actors using AI agents for reconnaissance, automated attacks, and real-time adaptation to defensive action. These agents can shift tactics and targets faster than traditional response processes can handle.
The exercise centers on operational resilience and organizational decision-making. Technical detail creates pressure in the scenario, however it is not the subject of the exercise. Participants will work with incomplete information, competing business priorities, and an adversary that changes its approach as the incident develops.
In this iteration
Cybersecurity, risk, technology, operations, business continuity, and resilience leaders will work through a fictional campaign built around agentic AI techniques in a fast-moving cyber incident affecting a business-to-business platform provider.
Participants will confront questions of containment, continuity, recovery, trust, and residual risk in an environment where full certainty isn't quickly available.
Panelists
Panelists to be announced. The exercise will include practitioners across cybersecurity, operational resilience, business continuity, technology, risk, third-party management, and executive leadership.
Exercise Goals
Test decision-making against an adaptive threat
Examine how organizations recognize and respond to malicious activity that moves faster, generates more noise, and changes behavior as defensive actions reveal new information.
Examine how peer signals change the operating picture
Test how organizations use information from peers, ISACs, vendors, and other trusted sources when internal evidence is incomplete and multiple organizations may be facing the same activity.
Strengthen resilience under sustained operational pressure
Examine how organizations balance containment, continuity, degraded operations, recovery, customer impact, and responder capacity when standard remediation doesn't immediately restore control.
Test recovery and trust under uncertainty
Examine what evidence is enough to begin recovery, which systems, identities, data, and sources can be trusted, and how much residual risk the organization will accept before resuming full operations.
Outcomes
Participants will examine whether their incident response, continuity, recovery, and governance models are ready for an adversary that acts and adapts at machine speed. The exercise will examine considerations including:
Escalation and decision authority
Minimum viable operations
Peer and collective-defense coordination
Response capacity under sustained attack
Recovery and restoration decisions
Trust in systems, identities, data, and backups
Evidence thresholds for returning services to operation
Executive acceptance of residual risk
Participants will also compare approaches across organizations and sectors to identify common challenges and resilience measures they can bring back to their own organizations.
Frequently Asked Questions
Who should attend?
This exercise is designed for cybersecurity, operational resilience, business continuity, technology, risk, third-party risk, legal, communications, customer operations, and executive or crisis leadership professionals. Organizations don't need every function represented, though cross-functional perspectives are encouraged.
Do I need AI or technical expertise to participate?
No. Participants don't need to understand how to build AI agents or carry out technical exploitation. The focus is on the organizational decisions created by an adversary that automates activity and adapts based on what it observes.
How will the exercise be conducted?
Participants will work through a facilitated fictional scenario and respond to key decision points as the incident develops. Anonymous polling compares participant approaches, and a panel of practitioners discusses the decisions, tradeoffs, and differences across organizations and sectors. The scenario allows for several defensible approaches — there is no single predetermined correct answer.
Will this be a live cyberattack simulation?
No. This is a facilitated tabletop discussion, not a hands-on cyber range or penetration test. The exercise focuses on organizational interpretation, escalation, operational continuity, coordination, recovery, and risk decisions.
What makes this different from a traditional cyber tabletop?
The scenario is built around an adversary with greater automation, speed, and tactical adaptability than a typical cyber tabletop assumes. Participants will encounter high volumes of activity across multiple fronts, incomplete or conflicting evidence, and situations where their own responses change what the attacker does next. The exercise emphasizes decision-making and resilience in a scenario where defenders can't assume the attacker follows a fixed sequence of actions.
Do I need to prepare anything in advance?
No formal preparation is required. Participants may want to consider how their organization identifies and escalates unusual or coordinated activity, which services and processes must continue during a major disruption, how peer and industry information factors into incident decisions, who has authority to restrict, restore, or resume critical services, and what evidence is required before a compromised environment can be trusted again. Reviewing your organization's incident response, business continuity, and operational resilience plans is encouraged.
How long will the exercise last?
Between three and four hours. The session includes scenario discussion, participant polling, panel commentary, and a closing debrief.
Will there be a post-exercise report?
Yes. Participants receive an After-Action Report covering key findings, areas of agreement and divergence, lessons learned, and practical considerations for strengthening resilience against adaptive AI-enabled threats.