Scenario-Based Security Training
Tabletop Exercises
Overview
Tabletop exercises are discussion-based sessions where team members walk through simulated security scenarios. They help organizations identify gaps in processes, improve coordination, and build readiness for real incidents — without the pressure of a live event.
Why Tabletop Exercises for AI Security?
AI-assisted development introduces novel attack vectors and incident types that many teams have never rehearsed:
- Prompt injection leading to data exfiltration
- AI tool compromised via supply chain attack
- Sensitive data inadvertently sent to AI provider
- AI-generated code introducing vulnerabilities at scale
- Insider misuse of AI tools to bypass controls
Exercise Format
Each exercise follows a structured format:
| Phase | Duration | Activity |
|---|---|---|
| Briefing | 10 min | Scenario introduction and ground rules |
| Scenario Inject | 15 min | Present the incident trigger |
| Team Discussion | 30 min | Walk through response actions |
| Escalation | 15 min | Introduce complicating factors |
| Debrief | 20 min | Lessons learned and action items |
Available Scenarios
Coming soon — scenarios currently under development.
- Scenario 1: AI Coding Assistant Data Leak
- Scenario 2: Compromised AI Plugin in CI/CD
- Scenario 3: Mass Vulnerability Introduction via AI-Generated Code
- Scenario 4: AI Tool Credential Theft
How to Use
- Select a scenario appropriate for your team’s maturity level
- Assign roles (Incident Commander, Security Analyst, Communications, Legal)
- Run the exercise with a facilitator guiding the discussion
- Document findings and update your incident response playbooks