EXERCISE PURPOSE
Examine the organization’s cyber resilience and coordinated response to a significant ransomware and data-breach incident.
Ransomware following phishing, unsupported systems, device loss, and data exfiltration
CISA.GOV CTEP · CYBER INCIDENT RESPONSE
A threat actor uses a phishing attachment to enter the environment, exfiltrates sensitive data, encrypts systems, demands cryptocurrency, publishes proof of stolen PII, and triggers public scrutiny.
EXERCISE PURPOSE
Ransomware following phishing, unsupported systems, device loss, and data exfiltration
DECISION PRESSURE
The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.
What evidence turns a suspicious event into a declared incident?
Which systems should be disconnected and what business impact follows?
How will the team validate stolen-data claims and identify affected populations?
Who controls attacker communications and any payment decision?
What can be said to employees, customers, regulators, and media while scope changes?
INSIDE THE EXERCISE
The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.
CISA issues an alert about a new ransomware variant targeting state, local, tribal, and territorial governments and private-sector organizations.
A year has passed since the developer announced the end of security patches for the organization’s operating system. The final patch was installed last week, and the exposure appears in the annual risk assessment.
An employee reports that a work laptop containing sensitive organizational information was stolen from a car overnight.
Finance staff receive an email that appears to come from their vice president and directs them to open a PDF about an unpaid third-party vendor bill. The vice president denies sending it, but some employees already opened the PDF.
An intrusion-detection alert shows abnormal after-hours DNS traffic. Log review finds a large volume of data moving from known HR employee addresses to external IP addresses.
Computers across the organization display a red screen and a cryptocurrency demand. The attacker says the decryption key will expire in 48 hours.
A security researcher reports credible dark-web posts from a known group. The actors publish sample records containing employee PII and threaten to sell the full dataset.
PARTICIPANTS
Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.
REAL-WORLD INCIDENTS
Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.
A software-management platform became the distribution mechanism for ransomware affecting downstream customers and managed service providers.
SEC order involving R.R. Donnelley↗The order describes alert-review, service-provider oversight, internal-control, escalation, and disclosure-control failures around a ransomware incident.
LEGAL, REGULATORY & STANDARDS LENS
Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.
The source collection for CISA Tabletop Exercise Packages covering ransomware, insider threats, phishing, supply-chain compromise, and sector incidents.
CISA #StopRansomware Guide↗Use the response checklist to compare player decisions with current government guidance.
SEC cybersecurity incident disclosure rules↗Public companies must assess materiality and disclose material incidents on Form 8-K Item 1.05 within four business days after the materiality determination, subject to the rule’s limited delay process.
PRACTITIONER PERSPECTIVES
External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.
A practitioner discussion of privilege, information sharing, law-enforcement coordination, payment decisions, and scenario-based preparation.
CrowdStrike tabletop exercise guidance↗Security-practitioner guidance emphasizing realistic injects, tailored scenarios, decision-making, communications, and coordination.
EXPECTED OUTPUT