Run a 60-Minute Ransomware Drill With Your Leadership Team
A complete facilitator kit for a one-hour tabletop exercise: the scenario, the injects, the questions that expose gaps, and the after-action format.
The short answer
A ransomware tabletop is a structured conversation about a disaster that has not happened. Six to eight leaders, one facilitator who does not participate, sixty minutes, phones down. The value comes entirely from discovering, in a conference room on a Tuesday, the questions nobody can answer.
A tabletop exercise is a structured conversation about a disaster that has not happened. No systems are touched and nothing is at risk. The entire value comes from discovering, in a conference room on a Tuesday, the questions nobody can answer.
Small businesses skip this because it sounds like a large-company activity requiring a consultant and a day. It does not. Here is the hour-long version, with everything you need to run it yourself.
Who is in the room
Six to eight people maximum. The owner or CEO. Whoever runs finance. Whoever runs operations. Your IT lead or a representative from your provider. Someone who speaks to customers. If you have counsel or an HR lead, include them.
One person facilitates and does not participate. Their only job is to present the scenario, ask the questions, and write down every place the room goes quiet.
Phones down. The exercise fails the moment somebody starts looking up the answer, because the point is to find out what is known, not what is findable.
The scenario
Present it in one paragraph, no warning, no preamble.
It is 6:40 on a Monday morning. Your operations manager arrives early and cannot log in. Neither can anyone else. Every workstation shows the same message: your files are encrypted, and there is a payment demand with a countdown. The file server is unreachable. The phone system, which runs on the same network, is dead. Somebody's personal cell phone is the only working communication in the building.
Then start the clock and begin asking.
The first fifteen minutes: response
Who is called first, and how does the person calling reach them without the company phone system or email.
Who has the authority to disconnect the network, and are they physically able to reach the equipment.
How do you tell 40 employees not to come in, or not to touch their machines, when your email is encrypted.
Where is the incident response plan stored. If the answer is on the file server, the room usually goes quiet on its own.
Who calls the insurance carrier, and what is the policy number. Almost no cyber policy allows you to hire your own forensics firm without approval, and doing so has caused coverage disputes.
The next fifteen: business continuity
Which operations can continue on paper, and does anyone remember how.
How do you take orders, book appointments, or dispatch crews today.
Payroll runs Thursday. How does that happen.
Who calls your largest customer, what do they say, and who approves the wording.
This section usually produces the most valuable findings, because it is the part IT plans never cover and the part that determines whether the business survives.
The next fifteen: recovery and legal
Where is the most recent backup, when was it verified, and how long does a restore actually take. Ask for the measured number, not the target.
Assume data was taken as well as encrypted, which is now standard. What data would that be, and whose.
Arizona's breach notification statute has requirements and timelines. Who determines whether they are triggered, and who tells the affected people.
Do you have a lawyer's cell number, right now, in a place you can reach without your systems.
The last fifteen: the honest wrap-up
Go around the room. Each person names the single thing they did not know that they should have.
Write everything down. Assign an owner and a date to each gap, no more than three per person, and put the review on the calendar for 30 days out. An exercise with no assigned follow-up is an entertaining hour that changes nothing.
What you will probably find
Across the tabletops we have facilitated, four gaps come up almost every time.
The response plan exists only in electronic form on a system that would be encrypted. Print it and keep copies off site.
Nobody has an out-of-band communication method agreed in advance. A group text thread with everyone's personal number, set up before the incident, solves this for free.
The insurance policy has requirements nobody has read.
The measured restore time is significantly longer than the assumed one, and often nobody has measured it at all.
None of those four cost money to fix. They cost an hour of attention.
Get the kit
The Tabletop Exercise Kit includes the facilitator script with timing, three scenarios at increasing difficulty, timed injects to drop into the conversation, a scoring rubric, the note-taking template, an after-action report format, and the gap tracker.
Run it once a year. The first one will be uncomfortable, which is the point of doing it in a conference room rather than at 6:40 on a Monday.
Frequently asked questions
What is a cybersecurity tabletop exercise?
A structured discussion of a hypothetical incident where no systems are touched and nothing is at risk. Participants talk through what they would actually do, and the value comes from finding the questions nobody can answer. A useful version for a small business takes one hour and needs no consultant.
Who should attend a ransomware tabletop exercise?
Six to eight people maximum: the owner or CEO, whoever runs finance, whoever runs operations, your IT lead or provider representative, someone who speaks to customers, and counsel or HR if you have them. One person facilitates and does not participate.
What gaps do tabletop exercises usually find?
Four recur almost every time: the response plan exists only on a system that would be encrypted, no out-of-band communication method was agreed in advance, the insurance policy has requirements nobody has read, and the measured restore time is far longer than the assumed one. None cost money to fix.
How often should we run a tabletop exercise?
Annually is sufficient for most small businesses, with a 30-day follow-up review after each one to confirm the assigned gaps were closed. An exercise with no assigned follow-up is an entertaining hour that changes nothing.
