Ransomware Tabletop Exercise — WOM Technology Management Group — +1 (888) 966-7228
Run a Ransomware Tabletop Exercise in 45 Minutes
An incident response plan nobody has run isn't a plan, it's a document. The gap between the two is where businesses lose their first hour - and the first hour is the one that decides how the rest goes.
A tabletop exercise closes that gap cheaply. No systems are touched and nothing is simulated technically. You put the people who would actually be involved in a room, describe a bad day, and work through what each of them would do. It takes about 45 minutes, it costs nothing, and it produces the one thing a cyber insurance application asks for that most businesses don't have: a dated record that the plan was tested.
What you need
Four things: 45 minutes, a printed copy of this page, someone to keep time, and the people who would actually be involved - owner or executive, whoever handles operations, whoever handles IT or your provider's contact, and whoever would talk to customers. Missing one is fine and worth noting; the gaps are part of the finding.
One rule: nobody looks anything up during the exercise. If a phone number isn't known, that's a result. Write it down and keep going.
The scenario
Read this out loud to start.
It's Tuesday, 8:40am. Your operations lead calls: nobody can open anything. Files that opened yesterday now have an extension nobody recognizes, and there's a text file on the desktop demanding payment in cryptocurrency for a key. The shared drive is affected. So is the accounting system.
The provider you'd normally call hasn't answered yet. Two customers have already emailed asking why their appointment confirmations didn't arrive. Your operations lead mentions, in passing, that someone in billing opened an invoice attachment yesterday afternoon that looked like it came from a vendor.
That's what you know. Nothing else is available.
Round 1 - the first fifteen minutes (10 min)
Work through these out loud, in order. Assign each answer to a named person.
- Who makes the call on what happens next, and who decides if that person is unreachable?
- What is the very first action taken, and by whom?
- Which systems get disconnected, who does it physically, and does anyone need building access they don't have right now?
- Who calls the IT provider, and what number do they use - not the general one, the after-hours one?
- Does anyone tell staff to stop working? Who says it, and how, if email is down?
Round 2 - the first day (15 min)
- Who contacts your cyber insurance carrier? Where is the policy number, and does the carrier require notification before you engage anyone else? (Many do, and using an unapproved vendor can affect coverage.)
- Who contacts a lawyer, and do you already have one who handles this?
- What do you tell customers, when, and who signs off on the wording?
- Are backups reachable, when was the last one verified by an actual restore, and does anyone in this room know for certain?
- What can the business still do manually? Which functions stop entirely?
- Who is paying attention to whether this is still spreading?
Round 3 - the hard questions (10 min)
- Do you pay? Decide the principle now, calmly, rather than at 3am under pressure - and note that this decision belongs with counsel and your carrier, not with whoever is most frightened.
- If regulated data was involved, who determines what notification obligations apply and on what clock?
- Who talks to press or posts publicly, and who is explicitly told not to?
- It's day four and you're still down. What's the plan for payroll, for customers, and for staff?
Round 4 - write it down (10 min)
This is the part that counts. Capture, on paper:
- The date you ran this and everyone who attended
- Every question the room couldn't answer
- Every phone number nobody knew
- Every assumption that turned out to be wrong ("I thought the backups covered that")
- Three things to fix, each with a name and a date
The list of what you couldn't answer is more valuable than the list of what you could. The exercise is the deliverable, and so is the record of it - keep it somewhere you can produce it, because your insurance application will ask whether your incident response plan has been tested, and this is what "yes" looks like.
How often?
Annually at minimum, and again after anything material changes - new systems, new provider, meaningful turnover in the room. Carriers commonly ask for annual testing. So does most framework guidance.
Where to go next
- Incident first-hour guidance - what to do if this is real.
- DFIR - who handles containment, investigation, and recovery.
- Cyber Insurance Readiness - the controls carriers ask about before renewal does.
- Security Self-Check - where the rest of the program stands.
Common questions
Do we need our IT provider in the room?
It's better if they're there, and still worth doing if they're not. If your provider can't join, run it without them and treat every unanswered technical question as an agenda item for your next conversation with them. That list is often the most useful thing the exercise produces.
What if we don't have an incident response plan yet?
Then run this anyway. A tabletop without a plan is how most businesses discover what their plan needs to contain, and the notes from Round 4 are a serviceable first draft.
Is this enough to satisfy an insurance application asking whether we've tested our plan?
It's a real tabletop exercise and a dated record of one, which is what the question is asking about. What we can't tell you is how your specific carrier evaluates it - their application and their underwriter govern. Keep the record, be accurate on the form, and don't describe it as more than it was.
What if something like this is happening right now?
Stop reading this page. Go to our incident first-hour guidance, or call +1 (888) 966-7228 - a human answers 24 hours a day.
The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.
