Exercise kit

Ransomware Tabletop Exercise Kit

Run a 90-minute exercise covering stolen administrator access, backup deletion, business disruption, and recovery decisions.

Ransomware Tabletop Exercise Kit visual for DefendArm Security guidance
Preview before download

Plan the exercise

A fictional scenario for a facilitated discussion, not a live attack simulation. Success means named decisions, visible dependencies, and testable follow-up work.

Sample decisions
  • Who can revoke a compromised administrator's access when the primary owner is unavailable?
  • What evidence supports a recovery estimate after backup deletion?
  • What can leadership say when data theft is alleged but not confirmed?
Common mistakes
  • Treating a discussion as proof that recovery works.
  • Letting one technical participant answer for every business owner.
  • Closing actions without a repeatable test.
What is inside

Ransomware Tabletop Exercise Kit

Run a 90-minute exercise covering stolen administrator access, backup deletion, business disruption, and recovery decisions. Includes a fillable PDF with worked examples and decision records.

Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.

  • Plan the exercise: A fictional scenario for a facilitated discussion, not a live attack simulation. Success means named decisions, visible dependencies, and testable follow-up work.
  • Release the scenario in stages: Facilitator-only prompts. Read one development at a time; do not reveal the next one until the team has recorded a decision.
  • Decision log: Use one sheet per scenario development. Capture what the team actually decided, including disagreements and unresolved questions.
  • Debrief and retest: Suggested follow-up: circulate the decision log within two working days and agree a retest date before closing the exercise.

References

Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.

Questions teams ask

Practical questions before you decide.

Who should use the Ransomware Tabletop Exercise Kit?

This resource is built for incident commanders, IT leaders, executives, and business owners who need a clear way to turn security guidance into owners, evidence, and next actions.

What should a team prepare before using it?

Prepare current system owners, relevant policies, available logs or configuration evidence, and any known exceptions that affect the control area.

When should this turn into a deeper review?

Bring in the relevant specialist when the work exposes missing evidence, unclear authority, or controls your team cannot validate. Keep the unresolved issue, owner, and next decision recorded.