C3SA FIELD GUIDE

RANSOMWARE TABLETOP EXERCISE GUIDE

A planning guide for executive and technical ransomware exercises that test decisions, communications, recovery and business continuity, not just technical response.

THE GUIDE

SIX STEPS TO A USEFUL RANSOMWARE EXERCISE.

The most useful ransomware exercises test business decisions and recovery, not just the security team's technical response.

01

Set realistic objectives and scenario scope

Decide what the exercise must test, such as decision rights, recovery priorities or communications, and build a scenario based on how ransomware groups currently operate, including data theft before encryption.

Questions to ask

  • What are the two or three things this exercise must test?
  • Which systems and business services does the scenario affect?
  • Does the scenario include data theft and extortion?
02

Include executive, legal, privacy, communications and operations

Ransomware is a business crisis. The people who decide on shutdowns, notifications, public statements and payment questions must be in the room.

Questions to ask

  • Who has authority to take critical systems offline?
  • Are legal, privacy and communications leads participating?
  • Do we need insurers, external counsel or key suppliers involved?
03

Inject business and technical uncertainty

Real incidents arrive with incomplete information. Injects should add pressure: a media enquiry, a ransom note with a deadline, a supplier asking questions, or evidence that backups are affected.

Questions to ask

  • What will participants not know at each stage?
  • Which injects test decisions under time pressure?
  • How will we simulate external pressure?
04

Test backup and recovery assumptions

Many recovery plans assume backups are intact and restoration is fast. The exercise should test whether backups are isolated, how long restoration takes and which services come back first.

Questions to ask

  • Would our backups survive an attacker with administrator access?
  • How long would restoring critical services actually take?
  • What is the restoration order, and who decided it?
05

Capture decisions and unresolved dependencies

Assign an observer to record each decision, who made it, what information it was based on and what could not be answered.

Questions to ask

  • Who is recording decisions and timings?
  • Which questions could nobody answer?
  • Which dependencies on people, suppliers or systems surfaced?
06

Turn lessons into accountable improvements

An exercise is only valuable if something changes. Convert observations into owned actions with dates, and schedule a follow-up exercise to test the fixes.

Questions to ask

  • Does every finding have an owner and a date?
  • Which plans or playbooks need updating?
  • When is the follow-up exercise?

Last reviewed September 24, 2026. This guide is general information, not legal advice. Print or save this page to use it as a workshop handout or pre-engagement checklist.

NEXT STEP

MOVE FROM CHECKLIST TO EVIDENCE.

C3SA can help validate the current state, identify material gaps, define the target state and support implementation, testing and readiness.

UNDER ATTACK? CYBERFIRE →