AI Frameworks / FOCUSED SERVICE

AI Incident Response Playbooks & Tabletop

Playbooks for prompt injection, agent misuse, model compromise, and AI-assisted data theft, built into your existing incident response plan and proven in a tabletop.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a security team whose incident response plan covers ransomware but has no entry for an agent that emailed a customer list because a document it read told it to. We extend your existing incident response plan with a set of AI-specific incident types drawn from recognized industry guidance. We write three to five playbooks covering prompt injection, agent misuse, tool poisoning, model compromise, and AI-assisted data theft. Each one names where you would detect it, the steps to contain it, how to preserve evidence, and who must be notified. We check whether your logging can even reconstruct an incident, then run a tabletop with timed twists. Playbooks shorten response; they do not prevent incidents.

WHEN THIS IS THE RIGHT FIT

Incident response leads, SOC managers, and platform engineers at organizations running AI assistants that retrieve documents, copilots with access to tools, or agents that take actions in business systems. The trigger is typically a near miss, or a customer asking how an AI incident would be handled.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Map the AI systems and the logs behind them

We start with your current incident response plan and the architecture of the AI systems. We locate the logs: the prompts and outputs, the actions agents take, what they retrieve, and who made each call. We check what each source keeps and whether together they can reconstruct who asked what, what the model returned, and the action the agent took. Every gap is recorded.

Write playbooks with named containment steps

Each playbook covers the triggers, where you would detect it, and its severity. Containment names the steps: revoke the agent’s access, narrow what it may do, roll back a model or prompt, quarantine the affected data, and an emergency shut-off requiring two people. Recovery reruns adversarial tests before anything returns to service, and notification maps to contracts, breach laws, and the EU AI Act.

Run the tabletop and hand back the fixes

A facilitated session, commonly about ninety minutes, walks security, engineering, product, legal, privacy, and communications through timed twists. The scenario might be a poisoned document that steers an agent into leaking data, or an over-permissioned agent acting on a forged instruction. You receive the scenario package, an after-action report with an owner-assigned improvement list, and updated plan pages and responsibilities.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Incident response leads and SOC managers whose plan has no AI incident entry
  • Teams running RAG applications, copilots with tool access, or agents that take actions
  • Platform engineers operating AI systems inside business applications and internal APIs
  • Organizations whose logging cannot yet reconstruct what an agent did and why
WHEN IT’S TIME TO ENGAGE
  • An agent or copilot does something unexpected and nobody can explain how
  • A customer asks how you would handle an AI security incident
  • You deploy your first agent with permission to act on its own
  • A tabletop or audit reveals AI scenarios your responders cannot yet handle
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • AI incident types and a severity matrix drawn from recognized industry incident-response guidance

  • Logging review across prompts, outputs, agent actions, retrieval, and identity to confirm an incident can be reconstructed

  • Three to five playbooks covering prompt injection, agent misuse, tool poisoning, model compromise, and AI-assisted data theft

  • Containment steps per system: revoking access, narrowing permissions, rolling back a model or prompt, quarantining data, and an emergency shut-off

  • Notification mapping to contracts, HIPAA, state breach laws, and EU AI Act incident reporting for higher-risk systems

  • Facilitated tabletop with timed twists for participants from security, engineering, product, legal, privacy, and communications

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$5,200–$8,300

One AI assistant or copilot, three playbooks, one tabletop session

About 35–55 hours
Mid-size
$8,200–$13,500

Several AI systems or one agent that takes actions, four to five playbooks, one tabletop

About 55–90 hours
Large
$13,500–$22,500

Many AI systems across teams, five playbooks, tabletops for technical and executive groups

About 90–150 hours
WHAT MOVES THE PRICE
  • Number of AI systems and agents that can take actions
  • Number of playbooks and custom scenarios
  • Whether logging is already in place or must be assessed from scratch
  • Number of teams and sessions in the tabletop
TYPICAL TIMELINE

3–6 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • AI incident types, a severity matrix, and diagnostic criteria built into your existing incident response plan
  • Three to five playbooks with detection sources, containment steps, evidence preservation, and notification mapping
  • Logging gap findings stating which incidents your current telemetry cannot reconstruct
  • Scenario package, an after-action report with owner-assigned improvements, and updated plan pages and responsibilities

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

We already have an incident response plan and run tabletops. Why AI-specific playbooks?

Because the existing plan assumes an incident has a compromised host or account at its center, and an AI incident often has neither. Nobody logged in; a document the system read changed what an agent did with permissions it legitimately held. Containment is different: revoke the agent’s access, roll back a prompt version, quarantine the data it drew on. The evidence is different: prompts, outputs, what was retrieved, and the actions taken. The notification questions are different too. Our Technical Tabletop Exercises service rehearses conventional scenarios; this one adds the AI incident types and playbooks to the same plan and then exercises them.

What logs must exist before this is useful?

At a minimum, for each request: the prompt the model actually received including anything it retrieved, the response it gave, and the identity of the user or service that made the call. For agents, every action taken with its inputs and result. All of it needs timestamps you can line up across your monitoring. Most AI platforms or the provider’s own logging supply the first pieces. If those sources do not exist yet, the engagement still proceeds: the logging review becomes the first thing to fix, and the tabletop twists are written to expose exactly which questions your responders cannot answer today.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security