Run a ransomware tabletop exercise in 30 minutes
"Is your incident response plan tested?" is now a scored question on cyber-insurance applications. A tabletop exercise is the cheapest way to make the answer yes, and it's the fastest way to find out your plan has blank phone numbers in it.
Who and what
The people named in your plan's roles table: owner or decision maker, whoever runs the response, the office manager, and your IT provider if they'll join. One person reads the scenario; everyone else answers "what do I actually do right now?" Nobody touches a computer. Thirty minutes, then stop.
The four scenarios (rotate, one per exercise)
- Monday 8 a.m., every file on the shared drive has a strange extension and there's a text file demanding payment. Who notices first? What do they do in the first five minutes? Who has the insurer's hotline number, and where is it if the network is down?
- A supplier calls to say they paid your "new bank account" last week. Whose mailbox was compromised? How would you know? Who calls the bank, and what's the number? Who phones every other supplier that mailbox emailed?
- The office manager's laptop, with browser-saved passwords, was stolen from a car. Was it encrypted? Can you wipe it remotely, and who has the console login? Which accounts get reset first?
- Your cloud accounting provider announces a breach of customer data. What of yours did they hold? Do you have to notify anyone? Who decides, and who drafts the message?
The questions to ask at every step
- Who does this? Is there a backup if they're on holiday?
- What do they need (a phone number, a login, a document), and where is it right now?
- How long does it take? Is that acceptable?
- What would we say to staff? To customers?
- Do we call the insurer before or after doing that? (Check your policy; many require first.)
What to record
Date, attendees, scenario, gaps found, and actions agreed with an owner and a due date. That one-page record is the evidence. Typical first-exercise findings: nobody knows the insurer hotline, the backup has never been restored, the IT provider's after-hours number is wrong, and two people both think the other one calls the bank. Fix those, and the second exercise six months later is boring, which is the goal.
Frequency
Twice a year, plus after any real incident or a major change (new systems, new IT provider). Insurers accept annual; six-monthly costs one extra hour a year and catches the roster going stale.