Deepfake Tabletop Exercise - Breacher.ai

Deepfake Tabletop Exercise

Your response plan has never been tested against a face and a voice your team recognizes.

A facilitated exercise that runs your team through a live deepfake incident. Injects arrive as synthetic video, cloned audio, and the messages that surround them, and your security, finance, communications, and legal people make real decisions under real time pressure. You leave with the specific points where verification, escalation, and authorization broke down, and what to change first. Nothing installed, no system access required.

Executive Impersonation Voice Cloning Payment Authorization Escalation Paths Crisis Communications Facilitated Debrief

Included with every OSES™ red team engagement. Also available on its own.

The scenario your plan was not written for

$450K
Average business loss per deepfake incident
Source: Regula Deepfake Trends 2024
10x
Increase in detected deepfakes year over year
Source: Sumsub Identity Fraud Report
42%
Of financial sector fraud attempts are now AI-driven
Source: Signicat 2024 Report

Why the plan fails on the day

Incident response plans assume the attacker is a stranger. Synthetic media removes that assumption.

Written, never rehearsed

Most organizations have a callback policy and an escalation path on paper. Very few have watched a finance manager try to apply either while a familiar face on a video call is asking why the delay.

Authority beats process

The control that matters is the one someone is willing to enforce upward. A deepfake attack targets exactly that hesitation, and no policy document tells you how large it is in your organization.

Awareness is not a process test

Training tells people the threat exists. It does not reveal that your out of band verification number is the same one the attacker controls, or that nobody knows who authorizes a public statement at 9pm.

What your team will face

Six scenario templates, selected and adapted to your sector, your approval chains, and the executives an attacker would actually target.

Executive Impersonation on Video

A synthetic executive joins a call and directs an urgent transfer. Tests whether the approval chain holds when the person on screen outranks everyone reviewing the request, and whether anyone moves the decision out of the call.

Video CallWire AuthorizationApproval Chain
Voice Cloned Emergency Request

A cloned voice calls after hours with a time boxed request and a reason the usual channel cannot be used. Tests the out of band callback path and whether the number people reach for is one the caller supplied.

Voice CloneOut of Band CallbackAfter Hours
Fabricated Public Statement

A synthetic clip of a named executive spreads while markets or customers are watching. Tests who is authorized to confirm it is fake, how fast provenance can be established, and what goes out before legal has cleared it.

Crisis CommunicationsDisclosureStakeholder Notification
Supplier and Payment Redirection

A known supplier contact appears on video to confirm a change of banking details already sent by email. Tests master data change controls and whether a face on a screen counts as verification in your process.

Supplier FraudBanking Detail ChangeFinance Controls
Service Desk Identity Reset

A cloned voice and matching video request an account recovery or authenticator reset for a privileged user. Tests the identity proofing script and whether escalation is available when the caller applies pressure.

Identity ProofingCredential ResetService Desk Script
Confidential Transaction Pressure

A synthetic board member invokes a live transaction to justify secrecy and bypass normal review. Tests whether confidentiality is allowed to suspend controls, and who is permitted to say no in that room.

Transaction SecrecyExecutive DiscretionControl Bypass

How the exercise is built

The facilitated variant of OSES™, our orchestrated simulation framework. An OSES™ campaign measures behaviour when people do not know they are being tested. This runs the same threat model with everyone in the room, so the finding is about process rather than individuals.

01
Scope & Authorization
Participants, scenarios, consent for any executive likeness, and handling rules agreed and signed before anything is generated
02
Footprint Research
The public material an attacker would use: conference talks, earnings calls, interviews, podcast audio, org structure
03
Persona Synthesis
Video and voice built with current-generation tooling, plus the supporting messages and pretext that carry the scenario
04
Facilitated Session
Injects released on a timeline, decisions recorded as they happen, pressure applied where the process starts to bend
05
Debrief & Findings
Which decision points failed, which escalation paths went unused, and the changes worth making first

Executive likeness is generated only under written consent, media is destroyed at the end of the agreed retention period, and reporting is organizational with no named individuals. To measure the same threat unannounced across the wider workforce, see deepfake phishing simulation.

One hour, four movements

Structured so the reveal lands after the decisions are already made, not before.

1
Minutes 0 to 10

Framing and ground rules

Scope, safety rules, and a reminder that nothing said in the room is attributed afterwards. Participants are told an incident is coming. They are not told which one, from whom, or when.

2
Minutes 10 to 35

Live injects

The scenario runs on a timeline. Synthetic video and audio arrive alongside the emails, messages, and follow up calls that would accompany a real attempt. The facilitator adjusts pressure based on what the room does, and every decision, deferral, and unspoken assumption is logged.

3
Minutes 35 to 50

The reveal

We show how the media was produced, what public source material it was built from, and how long each artifact took. This is the part people repeat to their colleagues afterwards, and it is why the exercise changes behaviour outside the room as well as inside it.

4
Minutes 50 to 60

Debrief and decisions

Walk back through the timeline against your own policy. Where the control existed and was skipped, where it did not exist, and which single change would have stopped the scenario earliest. Owners and dates leave the room with the findings.

One hour is the standard format. A half day version runs multiple scenarios across separate teams with a joint debrief, and suits organizations rehearsing a full crisis structure rather than a single decision chain.

Who should be in the room

The exercise tests handoffs between functions, so the value comes from having the functions present.

Security & IR
Detection, triage, escalation
Executive Leadership
Authority and final decisions
Finance & Treasury
Payment and approval controls
Communications
Public and internal response
Legal & Compliance
Disclosure and regulatory duty

What makes this different

Real media, not slides

Most tabletop exercises describe the attack in a paragraph and ask how the team would respond. Here the deepfake is in the room, produced with current-generation tooling, and the response is to the artifact rather than to a description of it.

Built from your own footprint

Scenarios use the same public source material an attacker would start from. The exercise doubles as evidence of how much usable signal your leadership has already published.

Findings about process

Output is organizational: which controls were skipped, which paths were never used, which decisions had no owner. No named individuals, no department leaderboards, nothing that discourages people from reporting next time.

Trusted by security leaders

I think the entire company is already talking about voice cloning and the risks. It's been a huge win for us already, without even seeing any of the actual results.

I was expecting a demo, not an episode of Black Mirror. This is really good, I'm surprised at how advanced it's gotten.

Users were surprised with how good the deepfakes were. I'm really impressed. Really crazy talking to a deepfake.

Trusted by security leaders at
Fortune 500 Banking & Finance Energy Legal Services Transportation

Common questions

What is a deepfake tabletop exercise?

A facilitated session where your team works a live deepfake incident in real time. Injects arrive as synthetic video, cloned audio, and supporting messages built for the exercise, and the team makes the same calls it would make during a real event. The output is a record of where the process held and where it did not.

How long is the session and what do we prepare?

One hour is standard, with a half day version when several teams take part. Preparation on your side is a scoping call, a participant list, and written authorization. Nothing is installed and no system access is required.

Do you build deepfakes of our own executives?

Only with written consent from the individuals concerned. We work from publicly available material such as conference talks, earnings calls, interviews, and podcast audio, which is the same material an attacker would use. Where consent is not given, the exercise runs with a synthetic executive persona instead.

Who should be in the room?

Security and incident response, executive leadership, finance or treasury, communications, and legal or compliance. The exercise tests the handoffs between those functions, so a room containing only the security team produces a much narrower result.

How is this different from a deepfake phishing simulation?

A simulation measures how people behave when they do not know they are being tested. A tabletop exercise is announced, and it tests process, escalation, and decision making with everyone in the room at once. Most organizations run both, starting with the exercise to align the process and following with simulation to measure it under real conditions.

What happens to the synthetic media afterwards?

Generated media is retained only for the agreed reporting period and then destroyed, with written confirmation. Source material, prompts, and outputs are never reused for another client and never appear in our public material.

Does the report name individuals?

No. Reporting is organizational. We record which decision points failed, which escalation paths were never used, and which controls were bypassed under pressure. There are no named individuals and no department leaderboards.

Is the exercise included with a red team engagement?

Yes. A tabletop exercise is included with every OSES™ red team engagement, and it can also be booked on its own as a first step before any simulation runs.

Run the scenario before someone else does

Thirty minutes. We will walk through your approval chains and pick the scenario your process is least prepared for.

One hour session No integration required Findings report after the session
Book a Free Demo

Included with every OSES™ red team engagement. Or start with deepfake phishing simulation.