Scenario library / Destructive attack

Enterprise Ransomware Shutdown: a tabletop exercise scenario

Encryption starts on a finance file share at 02:10 and spreads into virtual infrastructure. A ransom note demands payment inside 48 hours. Backup integrity is only partially confirmed.

90–120 min · Executive + technical

Abstract graphic representing enterprise ransomware shutdown

What this is modelled on

Modelled on large-scale ransomware events where an intruder gains a foothold through remote access, escalates to domain administrator over several days, disables endpoint protection and then encrypts server estates and virtual infrastructure in a single overnight window.

Why it matters

Ransomware compresses weeks of decisions into hours: containment that stops the business, restoration that may be incomplete, and a payment question that no single executive should answer alone. Teams that have never rehearsed it default to silence or improvisation.

Exercise objectives

  • Confirm who can authorise a full network isolation and how fast
  • Test the organisation's stated position on ransom payment under real pressure
  • Validate confidence in backups, not just their existence
  • Rehearse customer, staff and regulator messaging while facts are still moving

Decision points tested

  • Isolate the estate now or preserve evidence first
  • Engage insurer, counsel and incident response retainer
  • Position on ransom negotiation and who signs it off
  • Whether to notify customers before impact is fully scoped

Sample inject timeline

  1. T+0

    First alerts

    Endpoint agent reports mass file rename on a finance share; the on-call engineer is unsure whether to isolate or investigate.

  2. T+15

    Spread confirmed

    Two hypervisors show encrypted datastores. Two production applications are unavailable.

  3. T+30

    Ransom note

    A note names the organisation and threatens publication of exfiltrated HR data in 48 hours.

  4. T+50

    Backup doubt

    Infrastructure reports the most recent verified restore test was six months ago and excluded the affected platform.

  5. T+70

    External pressure

    A journalist emails the press inbox asking about an outage; a large customer asks for written assurance.

What the after-action report should capture

  • Time from first alert to containment authority
  • Backup assurance gaps and named owners
  • Decision quality on the payment question
  • Communications drafts produced during the exercise

Run this scenario with your team

Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.