"Assume breach" is now standard vocabulary. Every strategy deck says it, and saying it feels like having the posture. It usually isn't.
Assuming breach is a stance. Responding to one is a muscle, and the two are not the same thing. The value was never in the assumption. It's in having actually walked the bad day before it arrives: who decides, who speaks, what gets isolated, what happens in the first hour while everything is still on fire and half the facts are wrong.
The questions a real incident asks are awkward and operational, and they do not get better answers at two in the morning under pressure. Who has the authority to pull a production system offline, and will they use it. Who talks to customers, and who is told not to. Where are the backups, and has anyone actually restored from them this year. Does the plan quietly assume the email, chat, and identity systems that the incident may have just taken down.
The tabletop, sitting the real people in a room and walking a plausible scenario end to end, is the cheapest control most organisations skip. It finds the broken assumptions while they are still free to fix, rather than during the incident when they are expensive and public.
Do it properly. Use the people who would genuinely be in the room, not their stand-ins. Pick a scenario that takes down something you actually depend on. Time the decisions. Write down every "we'd have to check that," because each one is a gap wearing a calm voice.
Assuming breach costs nothing and proves nothing. Rehearsing it is the part that pays. A plan you have never run isn't a plan. It's a document you'll be reading for the first time on the worst day.