Guides · 10 min read
Ransomware Tabletop Exercise: Full Scenario Walkthrough
This is a runnable 90-minute ransomware exercise. It assumes an executive room of six to ten people plus observers, and it is built around one question: how long can you keep trading while encryption is active and scope is unknown?
Scenario premise
Two accounts payable clerks and a controller report that files on the finance share now open as gibberish and end in an unfamiliar extension. A README appears in every folder. The helpdesk has already rebooted one machine — destroying volatile evidence — before anyone escalated.
Phase 1 — Detection (0–15 minutes)
- Inject: helpdesk escalation, three users locked out of the finance share.
- Decision under test: who declares an incident, and how fast.
- Facilitator prompt: "Who has the authority to declare, and are they in this room right now?"
Phase 2 — Triage and containment (15–35 minutes)
- Inject: EDR timeline shows a service account authenticating from an unmanaged host, with live sessions on two more servers.
- Decision under test: isolate immediately versus preserve evidence first.
- Watch for: the room assuming backups are good. Ask when the last successful restore test was.
Phase 3 — The trading decision (35–55 minutes)
This is the centre of the exercise. Taking the ERP offline stops lateral spread but halts the day's operations. Put the CFO on the record with a two-minute deadline, then ask the incident commander for a go/no-go at the top of the hour.
- Require a documented risk acceptance if the system stays online. Most rooms do not produce one.
- Note who actually made the call versus who was asked.
Phase 4 — Escalation, notification and press (55–80 minutes)
- Inject: a customer forwards a leak-site listing naming you, with a 72-hour countdown and sample contract PDFs.
- Inject: trade press calls for comment an hour before your statement is ready.
- Decision under test: who owns the regulatory notification clock, and did anyone start it?
Phase 5 — Hot wash (80–90 minutes)
Capture confidence before and after, three things that surprised the room, and every action with an owner and a date. Anything without a name attached will not happen.
What the report should say
- Containment speed and whether evidence survived it.
- Whether the notification clock had a single owner.
- Whether availability decisions were recorded as risk acceptances.
- Backup integrity assumptions the room made without evidence.
Frequently asked questions
- Should a ransomware tabletop include the ransom payment decision?
- Yes, but frame it as a governance question: who is authorised to approve payment, what does the cyber policy require, and what does the board need to know first. The interesting failure is not the answer, it is the absence of a process.
- Do we need technical participants for an executive ransomware exercise?
- One technical seat is enough — usually the CISO or IR lead. More technical people tend to pull the room into architecture and away from the business decisions the exercise is testing.
Run this exercise in TableTop Sim
The scenario library, the facilitator control room and the after-action report — included in the free trial.
