Bitweb
Guide · Incident response

Run a ransomware tabletop exercise in 30 minutes

"Is your incident response plan tested?" is now a scored question on cyber-insurance applications. A tabletop exercise is the cheapest way to make the answer yes, and it's the fastest way to find out your plan has blank phone numbers in it.

By a working IT technician supporting 400+ users · Updated September 2026 · 5 min read

Who and what

The people named in your plan's roles table: owner or decision maker, whoever runs the response, the office manager, and your IT provider if they'll join. One person reads the scenario; everyone else answers "what do I actually do right now?" Nobody touches a computer. Thirty minutes, then stop.

The four scenarios (rotate, one per exercise)

  1. Monday 8 a.m., every file on the shared drive has a strange extension and there's a text file demanding payment. Who notices first? What do they do in the first five minutes? Who has the insurer's hotline number, and where is it if the network is down?
  2. A supplier calls to say they paid your "new bank account" last week. Whose mailbox was compromised? How would you know? Who calls the bank, and what's the number? Who phones every other supplier that mailbox emailed?
  3. The office manager's laptop, with browser-saved passwords, was stolen from a car. Was it encrypted? Can you wipe it remotely, and who has the console login? Which accounts get reset first?
  4. Your cloud accounting provider announces a breach of customer data. What of yours did they hold? Do you have to notify anyone? Who decides, and who drafts the message?

The questions to ask at every step

What to record

Date, attendees, scenario, gaps found, and actions agreed with an owner and a due date. That one-page record is the evidence. Typical first-exercise findings: nobody knows the insurer hotline, the backup has never been restored, the IT provider's after-hours number is wrong, and two people both think the other one calls the bank. Fix those, and the second exercise six months later is boring, which is the goal.

Frequency

Twice a year, plus after any real incident or a major change (new systems, new IT provider). Insurers accept annual; six-monthly costs one extra hour a year and catches the roster going stale.

Want the documents done for you?The Cyber Incident Response Plan & Ransomware Playbook (with a Tabletop Scenarios tab in the companion workbook) is the written policy set, incident response plan and asset register described here, as editable Word and Excel files: CA$19 on its own, or CA$39 in the full kit, instant download. Get the incident response plan
The cyber-insurance questionnaire, question by question12 questions, what "yes" needs, which document proves itAn incident response plan a small business will actually useRoles, severity levels, first-hour checklist, three playbooksWhat an IT asset inventory needs to track (and what it can skip)The columns insurers and auditors look for