The exercise everyone says you need.
We’ve already run it.
CISA has conducted federal AI security tabletop exercises. RAND and the UK AI Security Institute have warned European governments against AI-enabled cyber crises.
The Cloud Security Alliance tells CISOs to practice for an AI vulnerability storm.
We designed and delivered that exercise for a commercial enterprise, and we can build yours.
- The first commercial AI-accelerated vulnerability storm exercise, delivered August 2026
- Scenario classes for the AI era: vulnerability storms, deepfakes, AI system failures, AI vendor incidents
- Built by practitioners, grounded in real threat research, run at your organization’s real tempo
Schedule an Initial Consultation
Explore the Scenario Library
Why Now
Three developments changed the exercise landscape in the last eighteen months:
- AI has collapsed attacker timelines. Vulnerabilities are discovered, weaponized, and exploited faster than traditional patch cycles can respond. Incident responders now report exploitation attempts within minutes of disclosure.
- The authorities have moved. CISA and JCDC ran the first federal AI security tabletops and published the AI Security Incident Collaboration Playbook. RAND and the UK AI Security Institute exercised senior officials from three European governments against a frontier-model misuse scenario. The Cloud Security Alliance’s AI Vulnerability Storm paper tells security leaders to run tabletops for multiple simultaneous high-severity incidents.
- Almost nobody can run the exercise. Platform vendors use AI to generate injects. Technical firms drill SOC teams against AI-enhanced attacks. Exercising the enterprise, from patching velocity to vendor exposure to executive decisions to workforce sustainability, is a different discipline. It is ours.
The AI Vulnerability Storm
Our flagship AI scenario, first delivered to a healthcare technology enterprise in August 2026.
A fictional open-weights AI model demonstrates the ability to autonomously discover vulnerabilities and chain them into working attack paths.
Within days, criminal groups run it on their own infrastructure, and disclosures spike to an unprecedented rate, with real findings buried in AI-generated noise.
The storm hits three surfaces at once:
- The products you sell, where every patch needs testing before it ships
- Your internal infrastructure, where zero-days land across the production fleet
- Your vendors and third parties, where you have zero patch control
The exercise tests discovery, prioritization, and remediation at machine tempo, decision authority, and testing requirements under pressure, vendor dependency seams, and the human question almost nobody exercises: whether your people can sustain the response.
Fictional model, fictional CVEs. Your real vendors, your real tempo.
Other AI Scenario Classes
- Deepfake of a senior leader. A convincing fake of your CEO moves money, markets, or employees. Tests verification protocols, communications, and executive response.
- AI system failure. An AI system your business depends on produces harmful outputs at scale, or fails silently. Tests detection, rollback authority, customer notification, and regulatory exposure.
- AI vendor incident. The AI provider embedded in your workflow has a security incident, an outage, or a model behavior change. Tests third-party crisis response where you control nothing.
- AI-enhanced social engineering campaign. Voice cloning and tailored phishing at scale against your workforce and help desk. Tests the human perimeter.
Formats run the full ladder: tabletop, executive exercise, or enterprise simulation.
Who This Is For
- CISOs and CIOs whose boards are asking what AI threats mean for the company
- Organizations shipping software, where an AI-accelerated vulnerability storm is a when, not an if
- Companies deploying AI in products or operations that have never exercised its failure modes
- Security teams that have run the ransomware tabletop and need the next scenario
How It Works
Same discipline as every Bryghtpath exercise: designed from SME interviews and your real environment, delivered through your real channels with live adaptive facilitation, closed with a hot wash, survey, and an after-action report your program executes.
Design runs 4 to 8 weeks for a tabletop.
The AI Storm methodology brief and design artifacts from the first delivery accelerate yours.
What You Get
- A custom AI-era scenario built from your environment, vendors, and AI footprint
- Run of play, moves, and injects at the tempo the threat actually moves
- Senior practitioner facilitation with the methodology from the first commercial delivery
- After-action report with prioritized recommendations, including the resourcing and sustainability findings unique to AI-tempo incidents
- A defined path to the next cycle as the threat landscape shifts
Frequently Asked Questions
What is an AI crisis exercise?
A facilitated exercise where the AI threat itself is the scenario: an AI-accelerated vulnerability storm, a deepfake of a senior leader, an AI system failure, or an AI vendor incident. It tests how your whole organization responds when the threat moves at machine speed, not just how your security tools perform.
How is this different from a cyber tabletop exercise?
A cyber tabletop tests your response to a human-speed incident like ransomware. An AI crisis exercise tests what breaks when the tempo exceeds your processes: patching velocity, triage under a flood of findings, vendor dependencies you cannot patch, and whether your people can sustain the pace.
Do we need AI in production to need this exercise?
No. The most urgent AI scenarios are about attackers using AI against you, which requires nothing from your environment except software, vendors, and people. If you also deploy AI in products or operations, we add its failure modes to the scenario.
Has anyone actually run an exercise like this?
Yes. CISA has run federal AI tabletops, and RAND with the UK AI Security Institute has exercised European governments. In August 2026 we designed and delivered what our research indicates is the first commercial AI-accelerated vulnerability storm exercise, for a healthcare technology enterprise.
What does an AI crisis exercise cost?
Facilitated tabletops start at $25,000. AI scenarios are scoped to your organization after a consultation, with scope driven by format, participant count, and how deeply we model your environment and vendors.
Who should be in the room?
Security and engineering leadership, vulnerability management, vendor and third-party risk owners, communications, legal, and the executives who would own resourcing and disclosure decisions. AI-tempo incidents surface staffing and sustainability questions that belong to leadership, not just the SOC.
The authorities say to run this exercise.
Your competitors haven’t.
Fifteen minutes with the practitioner who built the first one gets
you a straight answer on what yours should look like.

