Loading...
Loading...
A complete, step-by-step guide to planning and executing ransomware tabletop exercises that prepare your team for real attacks.
Ransomware attacks are unique because they combine technical, legal, financial, and reputational challenges simultaneously. Your exercise must test all these dimensions:
Isolation, forensics, eradication, recovery
Pay or don't pay the ransom?
Law enforcement, regulatory notification
Operations during 21+ day recovery
Proper planning ensures a realistic and valuable exercise. Follow these preparation steps:
Choose a specific ransomware family to simulate. Popular choices:
Ransomware response requires cross-functional teams:
Exercise realism depends on accurate environment details:
Identify what you're testing:
What specific capabilities are you testing?
Here's a proven timeline for a ransomware tabletop exercise. Adjust based on your team's experience and objectives:
The toughest decision in ransomware response: Should you pay? Walk your team through this decision framework:
Your exercise should force participants to make real decisions. Include these critical decision points:
Scenario: You detect encryption on 3 servers. Do you isolate entire network segment (kills production) or just affected systems (may allow spread)?
Tests: Technical judgment vs business impact tolerance
Scenario: Your last clean backup is 4 days old. Recent backups show suspicious activity. Do you restore old backup (lose 4 days data) or risk restoring compromised backup?
Tests: Risk assessment and data loss tolerance
Scenario: Attacker demands $2M. Recovery from backups will take 28 days. Cyber insurance covers $1M ransom. What do you do?
Tests: Financial decision-making and negotiation strategy
Scenario: Local news contacts you about "ransomware at your company." Do you confirm, deny, or "no comment"? When do you proactively disclose to customers?
Tests: Communications strategy and transparency
The debrief is where real learning happens. Capture these insights immediately after the exercise:
Breakpoint provides realistic ransomware tabletop exercise scenarios with dynamic injects, decision points, and automated scoring. Start running quarterly ransomware drills in minutes, not weeks.
Complete guide to ransomware detection, containment, and recovery
The case for frequent incident response training
General guide to running effective IR exercises