Scenarios

How to run a ransomware tabletop exercise

Illustration of a padlocked server rack with a countdown, a ransomware readiness drill.

Most ransomware plans look sound on paper and come apart in the first hour of a real event. A tabletop exercise surfaces that failure on a quiet afternoon rather than at two in the morning during an actual attack. What follows is how an organization runs one that produces real decisions rather than agreement.

A scenario that fits the environment

A useful ransomware scenario is specific. "Ransomware hits the company" is too abstract to force a decision. A report that files on the finance share now carry a strange extension, with a ransom note on three desktops, gives the room something to act on.

The scenario should reflect the actual environment. For an organization with a plant floor, the instructive version is ransomware that moves from IT toward the systems that keep production safe. For a hospital, it threatens the systems clinicians rely on during care. It should also reflect how attackers now operate. CISA's StopRansomware Guide, a joint product of CISA, the Multi-State Information Sharing and Analysis Center, the NSA, and the FBI, describes double extortion, in which attackers both encrypt data and steal it, then threaten to publish what they took. A modern scenario has to test both the availability problem and the data-theft problem, because a real one will present both.

The room

A ransomware event is a business event, not an IT event. The room should include the people who will make the actual decisions:

  • An incident lead to run the response and keep time.
  • Security and IT to describe what is happening and what containment costs.
  • Legal or breach counsel to advise on notification, privilege, and the ransom question.
  • Communications to handle employees, customers, and the press.
  • A business owner for the affected unit, to speak to operational impact.
  • An executive who can authorize money and downtime.

Each participant works from an individual view of the exercise and makes independent calls, as they would in a real event.

A sequence of injects

The exercise advances through timed injects, each raising the stakes and forcing a decision. A workable arc moves through the phases any responder would recognize, from detection through containment, recovery, and the post-incident review.

  1. Detection. The first report arrives. Who declares an incident, and how quickly? Many teams lose an hour deciding whether the event is real.
  2. Scope. More systems are affected than first believed, with signs the attacker was present for weeks. Does the organization shut systems down to contain, and who authorizes the outage?
  3. The demand. A ransom note sets a deadline. The room must address payment before it is forced to. This is where legal, finance, and leadership often discover they never agreed on a position.
  4. Exfiltration. The attacker claims stolen data and threatens to publish, the double-extortion move. The event becomes a data-breach matter with notification obligations, not only an availability problem.
  5. Recovery and disclosure. Backups are partial. Regulators and customers are asking questions. What is said, when, and who signs off.

The value of each inject is the decision it forces and the disagreement it surfaces.

The payment decision is a legal decision

The ransom inject deserves particular attention, because the law around payment is where unprepared teams get hurt. Paying a ransom is not itself illegal, but the U.S. Treasury's Office of Foreign Assets Control has made clear that a payment can violate sanctions if it goes to a designated person or an embargoed jurisdiction, and OFAC applies strict liability, meaning liability can attach even when the payer did not know the recipient was sanctioned. OFAC has already sanctioned a cryptocurrency exchange, SUEX, for facilitating ransomware transactions, and its advisories extend the warning to the whole chain, including cyber insurers and the incident-response firms that process payments.

OFAC also describes what reduces that exposure. Strong cybersecurity practices adopted before an attack, and prompt reporting to and cooperation with law enforcement such as the FBI, CISA, and the Secret Service, are treated as mitigating factors in any enforcement response. An exercise should make the room confront this directly. Who owns the payment decision, what conditions would change the answer, whether counsel would run sanctions diligence on the recipient, and whether the organization would report to law enforcement early enough to earn that mitigation.

The decisions that go wrong

A few failures appear in almost every first exercise.

  • No one owns the decision to pay. Whether to pay a ransom cannot be resolved for the first time during an attack, and the sanctions exposure means it is a legal question, not only a financial one. The owner, the position, and the diligence process should be settled in advance.
  • Containment is treated as free. Shutting systems down carries a business cost. An exercise that never assigns a dollar or downtime figure to containment lets the room make an easy call it could not make in reality.
  • Legal arrives late. Notification timelines and privilege decisions begin early. Counsel present from the first inject changes the quality of every later decision.
  • Communications is an afterthought. The first employee message and the first customer statement shape the entire event and are worth drafting during the exercise.

Closing the loop

An exercise earns its value only when it produces a record and a set of owned actions. Every gap should leave the room with an owner and a due date. A note that backups could not be confirmed clean is not a document to file. It is a task with a name attached.

Federal guidance offers a structure for both the scenario and the response. The CISA StopRansomware Guide includes a response checklist that a scenario can be tested against, NIST's incident-response guidance provides the underlying recommendations, and CISA's tabletop exercise packages are a starting point for organizations building from nothing. The exercise is not a niche drill. National governments now run multinational ransomware tabletops of their own, as the Counter Ransomware Initiative did in a 2025 exercise examining how public and private responders coordinate during a major incident. The broader program is covered in the complete guide to cybersecurity tabletop exercises.

Written by

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.