Agentic Attack — Virtual Tabletop Exercise
Choose an exercise
Operational Resilience Series  ·  Virtual Tabletop Exercise

Agentic
Attack

A decision-driven exercise operating through a fast-moving, adaptive AI-enabled cyber threat campaign.

Wednesday, September 30, 2026
1:00 PM – 4:00 PM ET
Virtual
Register Here

Free to attend  ·  Stay updated at grfbrc.org/subscribe

The GRF Business Resilience Council's ORF Tabletop Exercise series tests participants' decision-making and lets organizations compare approaches across sectors.

Agentic Attack examines how organizations prepare for and respond to malicious actors using AI agents for reconnaissance, automated attacks, and real-time adaptation to defensive action. These agents can shift tactics and targets faster than traditional response processes can handle.

The exercise centers on operational resilience and organizational decision-making. Technical detail creates pressure in the scenario, however it is not the subject of the exercise. Participants will work with incomplete information, competing business priorities, and an adversary that changes its approach as the incident develops.

Cybersecurity, risk, technology, operations, business continuity, and resilience leaders will work through a fictional campaign built around agentic AI techniques in a fast-moving cyber incident affecting a business-to-business platform provider.

Participants will confront questions of containment, continuity, recovery, trust, and residual risk in an environment where full certainty isn't quickly available.

Panelists to be announced. The exercise will include practitioners across cybersecurity, operational resilience, business continuity, technology, risk, third-party management, and executive leadership.

Test decision-making against an adaptive threat
Examine how organizations recognize and respond to malicious activity that moves faster, generates more noise, and changes behavior as defensive actions reveal new information.
Examine how peer signals change the operating picture
Test how organizations use information from peers, ISACs, vendors, and other trusted sources when internal evidence is incomplete and multiple organizations may be facing the same activity.
Strengthen resilience under sustained operational pressure
Examine how organizations balance containment, continuity, degraded operations, recovery, customer impact, and responder capacity when standard remediation doesn't immediately restore control.
Test recovery and trust under uncertainty
Examine what evidence is enough to begin recovery, which systems, identities, data, and sources can be trusted, and how much residual risk the organization will accept before resuming full operations.

Participants will examine whether their incident response, continuity, recovery, and governance models are ready for an adversary that acts and adapts at machine speed. The exercise will examine considerations including:

  • Escalation and decision authority
  • Minimum viable operations
  • Peer and collective-defense coordination
  • Response capacity under sustained attack
  • Recovery and restoration decisions
  • Trust in systems, identities, data, and backups
  • Evidence thresholds for returning services to operation
  • Executive acceptance of residual risk

Participants will also compare approaches across organizations and sectors to identify common challenges and resilience measures they can bring back to their own organizations.

Who should attend?
This exercise is designed for cybersecurity, operational resilience, business continuity, technology, risk, third-party risk, legal, communications, customer operations, and executive or crisis leadership professionals. Organizations don't need every function represented, though cross-functional perspectives are encouraged.
Do I need AI or technical expertise to participate?
No. Participants don't need to understand how to build AI agents or carry out technical exploitation. The focus is on the organizational decisions created by an adversary that automates activity and adapts based on what it observes.
How will the exercise be conducted?
Participants will work through a facilitated fictional scenario and respond to key decision points as the incident develops. Anonymous polling compares participant approaches, and a panel of practitioners discusses the decisions, tradeoffs, and differences across organizations and sectors. The scenario allows for several defensible approaches — there is no single predetermined correct answer.
Will this be a live cyberattack simulation?
No. This is a facilitated tabletop discussion, not a hands-on cyber range or penetration test. The exercise focuses on organizational interpretation, escalation, operational continuity, coordination, recovery, and risk decisions.
What makes this different from a traditional cyber tabletop?
The scenario is built around an adversary with greater automation, speed, and tactical adaptability than a typical cyber tabletop assumes. Participants will encounter high volumes of activity across multiple fronts, incomplete or conflicting evidence, and situations where their own responses change what the attacker does next. The exercise emphasizes decision-making and resilience in a scenario where defenders can't assume the attacker follows a fixed sequence of actions.
Do I need to prepare anything in advance?
No formal preparation is required. Participants may want to consider how their organization identifies and escalates unusual or coordinated activity, which services and processes must continue during a major disruption, how peer and industry information factors into incident decisions, who has authority to restrict, restore, or resume critical services, and what evidence is required before a compromised environment can be trusted again. Reviewing your organization's incident response, business continuity, and operational resilience plans is encouraged.
How long will the exercise last?
Between three and four hours. The session includes scenario discussion, participant polling, panel commentary, and a closing debrief.
Will there be a post-exercise report?
Yes. Participants receive an After-Action Report covering key findings, areas of agreement and divergence, lessons learned, and practical considerations for strengthening resilience against adaptive AI-enabled threats.

Free to attend  ·  Stay updated at grfbrc.org/subscribe

Register Here
Choose an exercise