CRISISTABLETOP
Incident response participants collaborating around laptops
← Exercise library

CISA.GOV CTEP · CYBER INCIDENT RESPONSE

CISA Ransomware Tabletop Exercise

A threat actor uses a phishing attachment to enter the environment, exfiltrates sensitive data, encrypts systems, demands cryptocurrency, publishes proof of stolen PII, and triggers public scrutiny.

3 HRSuggested duration10Participant roles9Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Examine the organization’s cyber resilience and coordinated response to a significant ransomware and data-breach incident.

Ransomware following phishing, unsupported systems, device loss, and data exfiltration

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

What evidence turns a suspicious event into a declared incident?

02

Which systems should be disconnected and what business impact follows?

03

How will the team validate stolen-data claims and identify affected populations?

04

Who controls attacker communications and any payment decision?

05

What can be said to employees, customers, regulators, and media while scope changes?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Day 1
    Module 1

    CISA ransomware alert

    CISA issues an alert about a new ransomware variant targeting state, local, tribal, and territorial governments and private-sector organizations.

  2. Day 2
    Module 1

    Unsupported operating system

    A year has passed since the developer announced the end of security patches for the organization’s operating system. The final patch was installed last week, and the exposure appears in the annual risk assessment.

  3. Day 4
    Module 1

    Employee laptop stolen

    An employee reports that a work laptop containing sensitive organizational information was stolen from a car overnight.

  4. Day 6
    Module 1

    Vendor invoice phishing email

    Finance staff receive an email that appears to come from their vice president and directs them to open a PDF about an unpaid third-party vendor bill. The vice president denies sending it, but some employees already opened the PDF.

  5. Day 7
    Module 2

    After-hours data exfiltration

    An intrusion-detection alert shows abnormal after-hours DNS traffic. Log review finds a large volume of data moving from known HR employee addresses to external IP addresses.

  6. Day 9
    Module 2

    Ransomware executes

    Computers across the organization display a red screen and a cryptocurrency demand. The attacker says the decryption key will expire in 48 hours.

  7. Day 10
    Module 2

    Stolen PII offered for sale

    A security researcher reports credible dark-web posts from a known group. The actors publish sample records containing employee PII and threaten to sell the full dataset.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadGeneral CounselPrivacy OfficerBusiness Continuity LeadCommunications LeadFinance or HR RepresentativeLaw Enforcement LiaisonExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • A cross-functional escalation model
  • Defined technical and legal workstreams
  • Notice decisions based on changing facts
  • Recovery priorities tested against operations
  • A documented hotwash and improvement plan
Start with this exerciseRead the facilitator guide