IncidentKitBuild Your Exercise

Free Sample

Sample: Ransomware Tabletop Exercise

This is the base template used for a Ransomware exercise, shown here unmodified. A purchased package is fully tailored to your organization by AI and includes complete facilitator instructions for every inject.

Executive Overview

This exercise walks the team through a ransomware event: files across shared systems become inaccessible, a ransom note appears, and the organization must decide how to respond under time pressure. Participants practice detection and escalation, business continuity decisions, stakeholder communication, and the many decisions that surround a ransom demand — without ever discussing payment mechanics or negotiation tactics as facts to rely on.

Exercise Objectives

  • Practice recognizing and escalating early signs of a ransomware event
  • Exercise the decision chain for isolating affected systems and preserving evidence
  • Rehearse internal and external communication under uncertainty
  • Clarify who owns the decision about engaging law enforcement, insurers, and outside counsel
  • Identify gaps in backup, recovery, and business continuity readiness

Initial Scenario Briefing

It is a normal business day. Over the past hour, multiple employees have reported that they cannot open shared files, and several file names now end in an unfamiliar extension. A text file has appeared on shared drives referencing a ransom demand. No one has clicked anything unusual that they recall. IT has not yet confirmed the scope of what is affected.

Sample Injects

Inject 1: First Reports Arrive

~5 min

Two more departments report the same file access problems. The helpdesk queue is filling up. One employee says their screen briefly showed a ransom note before their machine seemed to "restart itself."

Discussion Questions

  • Who needs to be notified right now, and in what order?
  • How will you confirm how many systems are affected without making things worse?
  • What is your threshold for declaring this a formal incident?

Inject 2: Scope Widens

~14 min

IT confirms that the file server and at least one department's shared drive are encrypted. It's unclear whether backups are affected. The finance team needs access to run payroll in two days.

Discussion Questions

  • What is the plan if backups are unavailable or also affected?
  • How does the payroll deadline change your priorities?
  • Who decides whether to isolate additional systems as a precaution?

Inject 3: The Ransom Note

~25 min

The full ransom note is now visible. It includes a dollar amount, a deadline, and a threat to publish stolen data if the deadline passes. It is unclear whether data was actually copied out or if this is a bluff.

Discussion Questions

  • Who has the authority to even consider a payment decision, and what do they need to know first?
  • How will you determine whether data was actually exfiltrated?
  • What does the double-extortion threat mean for your notification obligations?

A purchased package includes all 11 injects for your chosen duration, fully tailored to your organization, plus facilitator instructions, expected actions, and every template listed below.

Also included in every package

Preparation checklist, participant role descriptions, decision log template, observer notes template, after-action report template, remediation tracker, and high-level NIST CSF references.

This material is educational tabletop-exercise content only. It is not legal, regulatory, compliance, or incident-response advice, and it does not guarantee compliance with any law, regulation, contract, or standard. Organizations should consult qualified legal counsel, incident-response professionals, and their own policies when preparing for or responding to real security incidents.