A deepfake voice call reaches your finance lead. It is the CEO, or it sounds exactly like the CEO, and the instruction is to move $2.3 million today to close a deal. Assume the good outcome: someone hesitates, and the wire never leaves. The tabletop does not end there. It starts there. Who declares this an incident. Who calls the bank. Who calls the board. Whether a regulator's clock is already running. Who speaks for the company if the story moves before you do.
Those are the questions a crisis plan exists to answer in advance. Most plans do not. They name owners and list phone numbers, and they sit in a shared drive until an auditor asks for them. That is a plan on paper. It is not a plan that has been tested, and the difference only shows up on the worst day.
Having a Vendor Is Not Having a Plan
Most mid-market companies have real security investment. A managed detection vendor. An IT team that patches and monitors. Cyber insurance with an incident hotline. Each of those is worth having, and none of them is a crisis-management plan. They handle detection and technical response. They do not decide, for the company, what leadership says to regulators in the first hour, or how the board hears the news before a reporter does.
The gap is not detection. It is decision-making under pressure, with reputational and regulatory clocks running at the same time. That is leadership's problem, and it is the one most plans leave for the moment it arrives.
What the First Hour Actually Demands
A tested plan answers a short list of questions before anyone is under pressure:
Who declares an incident and convenes the response team, and who holds that authority when the first person is unreachable.
What the company stops immediately to contain the damage, and who is authorized to order it.
Who gets notified, in what sequence, and which legal or regulatory clock starts on the first confirmed fact.
Who speaks for the company, internally and externally, and what the holding message is before all the facts are in.
Where leadership operates from, and how it communicates, if the normal systems or the normal room are unavailable.
None of these are technical questions. Each is a decision a person has to own, and each is far cheaper to make in a quiet conference room than in the first hour of a live incident.
Why the Deepfake Wire Is the Right Test
The deepfake-voice wire is worth running not because it is exotic, but because most plans never contemplated it. It puts finance, legal, security, and communications in the same problem at once, and it exposes the seams a paper plan hides. Voice authorization has almost no security value now, so the technical lesson is easy. The harder lesson is procedural: the verification step nobody owned, and the notification sequence nobody had written down. Swap the deepfake for ransomware, a data exposure, or an executive emergency, and the first-hour questions barely change. The scenario is a stress test for the decisions, not a prediction of the threat.
What a Fractional Crisis Program Does, and Does Not Do
Standing this up does not require a full-time chief security officer, which for a company of 50 to 500 people runs $250,000 to $500,000 loaded. A fractional crisis and resilience program is senior practitioner work delivered at a fraction of that: it builds the crisis-management plan the board will trust, runs the quarterly tabletop exercises that surface the gaps, keeps a readiness scorecard the board and the insurer can rely on, and puts an experienced hand on the bridge during an actual incident.
It is honest about its edges. A fractional program does not run your day-to-day security operations, and it does not replace a full-time CSO for an organization that genuinely needs one in the chair. What it does is make sure the first-hour decisions exist, in writing and rehearsed, before the hour arrives.
When to Do This Work
The timing is the same as most protective work: in the calm, not the crisis. Building the plan is a series of conversations. Testing it is a half-day exercise. Both are quiet, unremarkable, and far less expensive than reconstructing, under regulatory scrutiny and public attention at once, why leadership improvised its first decisions on the worst day of the year.
Triangle Point Solutions builds and tests crisis-management plans for mid-market companies, healthcare systems, and portfolio companies through its Crisis Ready program. Tell us the one scenario that would stress your current plan the most, and we can walk it through with you. Reach us at info@trianglepointsolutions.com.