Scenario library / Destructive attack
Enterprise Ransomware Shutdown: a tabletop exercise scenario
Encryption starts on a finance file share at 02:10 and spreads into virtual infrastructure. A ransom note demands payment inside 48 hours. Backup integrity is only partially confirmed.
90–120 min · Executive + technical

What this is modelled on
Modelled on large-scale ransomware events where an intruder gains a foothold through remote access, escalates to domain administrator over several days, disables endpoint protection and then encrypts server estates and virtual infrastructure in a single overnight window.
Why it matters
Ransomware compresses weeks of decisions into hours: containment that stops the business, restoration that may be incomplete, and a payment question that no single executive should answer alone. Teams that have never rehearsed it default to silence or improvisation.
Exercise objectives
- Confirm who can authorise a full network isolation and how fast
- Test the organisation's stated position on ransom payment under real pressure
- Validate confidence in backups, not just their existence
- Rehearse customer, staff and regulator messaging while facts are still moving
Decision points tested
- Isolate the estate now or preserve evidence first
- Engage insurer, counsel and incident response retainer
- Position on ransom negotiation and who signs it off
- Whether to notify customers before impact is fully scoped
Sample inject timeline
- T+0
First alerts
Endpoint agent reports mass file rename on a finance share; the on-call engineer is unsure whether to isolate or investigate.
- T+15
Spread confirmed
Two hypervisors show encrypted datastores. Two production applications are unavailable.
- T+30
Ransom note
A note names the organisation and threatens publication of exfiltrated HR data in 48 hours.
- T+50
Backup doubt
Infrastructure reports the most recent verified restore test was six months ago and excluded the affected platform.
- T+70
External pressure
A journalist emails the press inbox asking about an outage; a large customer asks for written assurance.
What the after-action report should capture
- Time from first alert to containment authority
- Backup assurance gaps and named owners
- Decision quality on the payment question
- Communications drafts produced during the exercise
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
