AEGITz · Free Resource · Facilitator Kit

Ransomware Tabletop Exercise Kit

A tabletop exercise is a structured conversation about a disaster that has not happened. No systems are touched and nothing is at risk. The entire value comes from discovering, in a conference room on a Tuesday, the questions nobody can answer.

Setup

ElementDetail
ParticipantsSix to eight maximum: owner or CEO, finance lead, operations lead, IT lead or provider representative, someone who speaks to customers, plus counsel and HR if you have them
FacilitatorOne person who presents, asks, and takes notes. They do not participate
Duration60 minutes, hard stop
RulesPhones down. No lookups. The point is to find out what is known, not what is findable
FrequencyAnnually. The first one will be uncomfortable, which is the point of doing it in a conference room rather than at 6:40 on a Monday

Scenario A: the standard opening

It is 6:40 on a Monday morning. Your operations manager arrives early and cannot log in. Neither can anyone else. Every workstation shows the same message: your files are encrypted, and there is a payment demand with a countdown. The file server is unreachable. The phone system, which runs on the same network, is dead. Somebody's personal cell phone is the only working communication in the building.

Read it cold. Start the clock. Do not soften it, and do not answer questions about what "really" happened.

Minutes 0 to 15: response

  1. Who is called first, and how does the person calling reach them without the company phone system or email?
  2. Who has authority to disconnect the network, and are they physically able to reach the equipment?
  3. How do you tell 40 employees not to come in, or not to touch their machines, when your email is encrypted?
  4. Where is the incident response plan stored? (If the answer is on the file server, the room usually goes quiet on its own.)
  5. Who calls the insurance carrier, and what is the policy number? Almost no cyber policy allows you to hire your own forensics firm without approval, and doing so has caused coverage disputes.

Minutes 15 to 30: business continuity

  1. Which operations can continue on paper, and does anyone still remember how?
  2. How do you take orders, book appointments, or dispatch crews today?
  3. Payroll runs Thursday. How does that happen?
  4. Who calls your largest customer, what do they say, and who approves the wording?

This section usually produces the most valuable findings, because it is the part IT plans never cover and the part that determines whether the business survives.

Minutes 30 to 45: recovery and legal

  1. Where is the most recent backup, when was it verified, and how long does a restore actually take? Ask for the measured number, not the target.
  2. Assume data was taken as well as encrypted, which is now standard. What data would that be, and whose?
  3. Arizona's breach notification statute has requirements and timelines. Who determines whether they are triggered, and who tells the affected people?
  4. Do you have a lawyer's mobile number, right now, in a place you can reach without your systems?

Minutes 45 to 60: after-action

Go around the room. Each person names the single thing they did not know that they should have. Write everything down, assign an owner and a date to each gap, no more than three per person, and put the 30-day review on the calendar before anyone leaves.

Injects to drop in mid-exercise

TimingInjectWhat it tests
Minute 8A local reporter has called the main line asking about an outageWhether anyone is authorized to speak publicly
Minute 18Your largest client emails asking why their portal is downCustomer communication under uncertainty
Minute 25An employee mentions they clicked something on FridayWhether reporting is safe, and evidence handling
Minute 33The attacker emails a sample of your client dataShift from encryption to extortion and disclosure
Minute 40The backup restore fails on the first attemptWhether there is a second option or only hope

Scenario B: vendor compromise

Your practice management vendor notifies you at 4:50 on a Friday that they have suffered a security incident. They cannot yet say whether your data was involved. Their system is offline and they have no restoration estimate. Your Monday schedule is inside it.

Tests third-party dependency, contractual notification rights, and whether anyone knows what the contract actually says.

Scenario C: business email compromise

Your controller reports that a $84,000 payment went to a supplier's updated bank details three weeks ago. The supplier has just called asking why they have not been paid. The email requesting the change came from the supplier's real address.

Tests payment controls, recovery speed, insurance coverage for social engineering, and the difference between a technical breach and a procedural one.

The four gaps almost everyone finds

  1. The response plan exists only on a system that would be encrypted. Print it and keep copies offsite.
  2. No out-of-band communication method was agreed in advance. A group text thread with everyone's personal number, set up before the incident, solves this for free.
  3. The insurance policy has requirements nobody has read.
  4. The measured restore time is far longer than the assumed one, and often nobody has measured it at all.

None of those four cost money to fix. They cost an hour of attention.

After-action record

Gap identifiedOwnerDue dateVerified
    
    
    
    

An exercise with no assigned follow-up is an entertaining hour that changes nothing. 30-day review scheduled for: