MODULE 03 EXECUTIVE CRISIS RESPONSE

When AI Attacks
Your Organization

The first 72 hours after an AI-enabled breach or executive impersonation attack determine whether you contain the damage or lose control of the narrative. This playbook gives board members and C-suite leaders a clear, tested framework for the decisions that matter most when the pressure is highest.

15 min read
Decision-tree framework
Board-level content
// LEARNING OUTCOMES
01
Activate the Response Framework
Know exactly what to do — and in what order — in the first two hours of a confirmed AI incident.
02
Communicate With Authority
Align the board, notify regulators, and manage the media narrative without creating panic or legal exposure.
03
Make Decisions Under Pressure
Use the structured decision framework to navigate containment vs. continuity trade-offs with confidence.

Why AI Incidents Are Different

Standard incident response playbooks assume you know what happened. AI incidents often start with ambiguity — a CFO receives a convincing but fabricated wire request, a deepfake of the CEO circulates internally, an AI-generated data breach claim arrives with stolen-looking documents. You don't know if it's real. Meanwhile, time is collapsing.

Attribution Ambiguity
Was the wire request genuine? Is the deepfake real? AI attacks deliberately blur the line between real and fabricated to slow your response. Every minute you spend verifying is a minute the attacker has to consolidate.
Speed Asymmetry
The attacker only needs to move money or disseminate content. You need to stop the transfer, verify the threat, notify multiple stakeholders, and contain the damage — simultaneously. Attackers operate at machine speed; organizations don't.
Narrative Capture Risk
If a deepfake of your CEO is circulating, the attacker controls the first 24 hours of the story. Your response — what you say, when you say it, and whether you say it — shapes whether the incident becomes a crisis or a manageable event. Executives who wait for facts lose the narrative.
// THE MONEY CLOCK
Wire transfers become irreversible within 2–4 hours. Cryptocurrency transactions can be irreversible within 20 minutes. AI-generated content — whether a deepfake video or fabricated internal memo — reaches your entire workforce and investor base in under 60 seconds of being posted. The 72-hour playbook exists because the damage window is measured in hours, not days. By the time most incident response plans are fully activated, the most consequential decisions have already been made by default.

The Playbook: Phase by Phase

This framework organizes the first 72 hours into three operational phases. Each phase has a clear priority, a set of decisions that must be made, and a communication cadence. Use it as a reference during the incident — print it, share it with your incident commander, and refer back to it before every board update.

1
Activate the Incident Commander
Designate a single decision-maker with authority to halt transactions, pause business processes, and authorize external communications — without requiring multi-signature approval in the first two hours. The CEO should NOT be the incident commander — they need to be available for external and board communication. Assign this role before the crisis.
INCIDENT COMMANDER: CISO or CRO by default. CEO escalates to board; does not run operations.
2
Isolate the Attack Vector
For financial fraud: freeze the targeted account or wire immediately. For deepfake content: identify the distribution channels (internal email, social media, news) and prepare takedown requests. For data breach claims: isolate the systems in question without alerting the attacker — they may be monitoring your response.
ACTION: Do NOT reset all passwords or take systems offline without understanding the scope — you may alert the attacker and destroy forensic evidence.
If a wire is in process: call your bank NOW using the number on the back of your card — not the number in the suspicious request. Time matters here more than process.
3
Establish the Crisis Working Group
Pull together your key responders in the first 30 minutes: CISO, General Counsel, Head of Communications, CFO, and your external legal counsel and cyber forensics firm (if pre-engaged). Define communication channels — use Signal or a separate encrypted channel, not corporate email, which may be compromised. Brief the group: what we know, what we don't know, what's been actioned.
CHANNEL: Encrypted. All incident communications logged and timestamped for regulatory and legal purposes.
4
Brief the Board — Initial Notification
The board needs to know something happened — even if you don't yet know the full scope. A brief, factual initial notification establishes board awareness and creates the legal foundation for future regulatory disclosures. Do not wait to have the full picture. An initial notification buys you goodwill with regulators; a delayed notification loses it.
BOARD BRIEF: "We are investigating a potential [fraud/deepfake/data incident]. We have activated our response protocol. We will provide a fuller assessment within 6 hours."
5
Scope the Incident — Forensic Assessment
Engage your external forensics team. For AI-generated fraud: timeline analysis of the attack, identification of all communication channels used, audit of all transactions in the previous 48 hours. For deepfake content: origin tracing, distribution map, content authenticity analysis. For data breach: scope the data at risk — customer data, financial records, intellectual property, board communications.
FORENSICS: Preserve all logs, emails, communication records. Do not delete anything. Document the timeline of your own response — this matters for regulatory and legal defense.
6
Notify Regulators — You're on the Clock
Regulatory notification timelines vary by jurisdiction and incident type, but they are measured in hours — not days. For CBK-regulated entities: critical incidents typically require notification within 24 hours. For data breaches involving personal data: PDPL requirements in Saudi Arabia, UAE, and Kuwait dictate specific timelines. Your General Counsel must identify applicable requirements in the first 6 hours.
REGULATOR NOTIFICATION: CBK for financial institutions, NCA/CSFEC for cybersecurity incidents in KSA, TDRA in UAE. Do not wait for full scope — initial notification is expected; updates follow as facts emerge.
7
Control the Narrative — External Communications
By hour 12, the market or the public may already be aware of the incident. If a deepfake of your CEO is circulating, it's circulating whether you've said anything or not. Issue a holding statement — one paragraph, factual, no speculation: "We are aware of [incident description]. We are investigating and have taken steps to [immediate action taken]. We will provide an update when more information is available." This is not a full press release. It's a bridge that buys you 24 hours.
EXTERNAL COMMS: All statements cleared by General Counsel before release. No attribution of cause. No speculation. No minimization.
8
Internal Workforce Communication
Your employees are the fastest distribution channel for a deepfake — and also your first line of defense. Issue a brief internal briefing: what to look out for, how to report suspicious communications, and who to contact. If the attack involved impersonation of an executive, warn the team explicitly: "You may receive communications that appear to be from [name] — verify any unusual requests through [known channel]."
INTERNAL NOTE: Keep it factual, not alarming. Fear spreads faster than a virus.
9
Present the Full Board Brief
By hour 48, you should have a clearer picture of the incident's scope, the financial impact or exposure, any regulatory notifications filed, and the containment measures in place. Present to the full board with: incident summary, current status, financial exposure, regulatory status, response actions taken, and recommended next steps. Do not present unknowns as facts — the board needs honest assessment, not confident guesses.
BOARD DECK: Incident timeline, financial exposure, regulatory notifications, containment status, recovery plan, recommended decisions.
10
Initiate Recovery and Lessons Learned
Once the immediate threat is contained, shift to recovery and prevention. Update your response protocol based on what you learned — every real incident reveals gaps that tabletop exercises missed. Brief your peer organizations through appropriate channels (ISACs, industry forums) if the attack pattern is new — this is how the industry builds collective defense. Finally: document everything. The incident log is evidence for regulatory review, legal defense, and your own institutional memory.
RECOVERY: Update response protocol. Share IOCs (Indicators of Compromise) with relevant threat intelligence sharing groups. Schedule a formal post-incident review within 30 days.
11
Long-Term Stakeholder Management
After the 72-hour window, the incident moves into a longer arc: investor communication, customer trust management, regulatory engagement, and media follow-up. Assign a long-term communications lead. Establish a regular update cadence — weekly, then monthly — until the incident is fully resolved. The organizations that recover best from AI incidents are the ones that communicate early, honestly, and consistently.
ONGOING: Weekly investor updates until resolved. Monthly regulatory updates as required. Media engagement managed by designated spokesperson — no ad hoc interviews.

When the Playbook Was Used — and When It Wasn't

These three incidents illustrate the difference between a well-executed response and a reactive one. The outcomes were shaped in the first hours.

The $25M Hong Kong Firm — No Playbook, No Protocol
$25M LOST
WHAT HAPPENED
Finance team received a deepfake voice call from someone claiming to be the UK director. No verification protocol existed. No incident commander was pre-designated. The team processed the transfer in 18 minutes. By the time the real director was reached, the funds were gone.
WHAT FAILED
No pre-designated verification protocol for high-value transfers. No incident response framework. No board-level awareness of AI fraud risk. The organization had cyber insurance — but insurance doesn't recover $25M from an irreversible wire transfer. The lesson: the response gap begins months before the incident.
The Finance Controller Who Used the Protocol
ZERO LOSS
WHAT HAPPENED
CFO received a call from someone who sounded exactly like the group CEO requesting an urgent transfer. The CFO had been through the ThreatAce response protocol. Without hanging up, they called the CEO on their verified number. The line was unanswered. They held — and the attack broke when the caller refused to wait for verification.
WHY IT WORKED
The verification protocol was practiced, not just documented. The CFO didn't panic — they had a decision tree. The refusal to wait was the tell. The controller's instinct was trained, not improvised. The outcome — zero funds lost, attack identified, protocol confirmed — was entirely shaped by the preparation cycle.
The Deepfake Video That Spread Before the Company Could Respond
NARRATIVE DAMAGE
WHAT HAPPENED
A fabricated video of a company's CEO announcing a fictional financial irregularity was shared internally and began spreading externally before the company knew it existed. By the time the company issued a statement — 6 hours later — the video had been shared 14,000 times across social platforms. The company's stock dropped 4% before the correction could take hold.
WHAT WENT WRONG
No media monitoring for executive impersonation. No pre-positioned holding statement. No established spokesperson. The first public acknowledgment came after the damage had compounded. The board later estimated that faster initial response — even a one-paragraph tweet in the first 30 minutes — would have reduced the narrative impact significantly.

The Pre-Incident Board Checklist

The decisions you make before an incident are the ones that determine how the first 72 hours unfold. Walk through this checklist with your board annually — or whenever there's a material change in your AI threat exposure.

GOVERNANCE DESIGN
Incident Command Structure
URGENT — requires board sign-off
FINANCIAL CONTROLS
Verification Protocols
HIGH — complete before next quarter
COMMUNICATIONS READINESS
Media & Stakeholder Response
MODERATE — within 60 days
REGULATORY COMPLIANCE
Notification Requirements
HIGH — required for CORF compliance

Who to Notify — and When

Every AI incident involves multiple stakeholders. The timing of each notification matters — too early without facts risks speculation; too late risks losing control of the narrative and regulatory goodwill.

STAKEHOLDER WHEN WHAT TO SAY WHO DELIVERS
Board of Directors
Initial + 48h update
0–2 hours Initial notification: "We are aware of [incident]. Response protocol activated. Full brief in 6 hours." Update: full scope, exposure, actions taken. CEO or Chair
C-Suite Team
Immediate + hourly sync
0–2 hours Incident commander appointed, working group formed, communication channels established. No speculation in internal comms. Incident Commander
Regulatory Bodies
Per jurisdiction timeline
2–12 hours Initial notification per regulatory requirements: incident type, initial scope, response measures. Updates as facts emerge — do not wait for full picture. General Counsel + CISO
External Legal Counsel
Immediately
0–2 hours Incident brief, preservation of evidence instructions, litigation hold assessment. All communications privileged from this point. General Counsel
Employees
Hour 6–12
2–12 hours Brief factual note: what happened, what they should do if they see related content, how to report. No blame, no speculation. CEO or designated exec
Media / Public
Holding statement at hour 12
2–12 hours One paragraph: awareness of incident, response activated, no speculation on cause, next update timeline. Full release only after legal clearance. Communications lead + legal
Customers / Partners
Only if data or service affected
12–72 hours If personal data or service integrity is affected: clear, factual disclosure per data protection regulations. What happened, what data, what's being done, what they should do. CEO + Customer Success lead
Investors / Analysts
Before public disclosure or at same time
12–72 hours If material impact: formal investor communication per securities regulations. Factual, no speculation. If not material: update on next earnings call, do not proactively contact. CFO + Investor Relations
// ENROLLMENT

Does Your Board Have This Playbook?

The first 72 hours of an AI incident are not the time to develop your response plan. ThreatAce's Board AI Incident Playbook gives your leadership team a proven, tested framework — and the decision templates to use it under pressure.

ENROLL NOW ThreatAce Board Playbook · Module 03 · Certificate of Completion