
CyberWire Daily One rule to rule them all.
Dec 12, 2025
Mark Lance, Vice President for DFIR and Threat Intelligence at GuidePoint Security, brings deep expertise in cyber incident response. He dives into the importance of purple team tabletop exercises tailored for AI-generated threats, highlighting their role in preparing organizations for automated phishing and model misuse. Mark discusses structuring these exercises to include realistic scenarios while emphasizing the need for collaboration among technical and executive teams. He also shares insights on evaluating organizational maturity to determine the cadence of these critical preparedness drills.
AI Snips
Chapters
Transcript
Episode notes
Set Regular Tabletop Cadence
- Perform tabletop exercises at least annually for senior leadership and more often for technical teams based on maturity.
- Use scenario-driven tabletops to vet incident response roles, escalation, and decision points.
Simulate Real Incident Uncertainty
- Tabletop exercises simulate realistic incidents by trickling information in over time.
- This reactive flow trains teams to operate without perfect upfront knowledge, mimicking real responses.
Include AI As A Threat Vector
- AI alters threat vectors but fits within existing tabletop planning frameworks.
- Include AI-enabled phishing, custom code, and compromise of internal AI infrastructure in scenarios.
