CRISISTABLETOP
Cross-functional response team working together around a conference table
← Exercise library

CRISIS TABLETOP ORIGINAL · CYBER INCIDENT RESPONSE

Ransomware & Data Exfiltration

A help-desk compromise gives an attacker privileged access. Critical systems are encrypted, sensitive patient and employee records are stolen, backups become suspect, and the organization must make containment, payment, notification, continuity, and public-communications decisions under escalating pressure.

2.5 HRSuggested duration10Participant roles12Scenario stages
Stock photography via Unsplash

EXERCISE PURPOSE

Exercise the legal, security, operational, privacy, financial, and communications decisions required during a ransomware and data-extortion event.

A credential-based intrusion develops into ransomware, data extortion, service disruption, and a multi-jurisdiction privacy incident

DECISION PRESSURE

Questions the team must answer together

The facilitator releases facts in stages. Participants should identify the decision owner, the authority being used, the information still needed, the immediate action, and the next escalation point.

01

Who has authority to isolate systems and interrupt critical services?

02

Can the organization trust its backups and identity environment?

03

What facts are sufficient to begin notification and disclosure analysis?

04

Who can authorize negotiation or payment and what external approvals are required?

05

How will legal, security, operations, customers, regulators, and the board receive consistent updates?

INSIDE THE EXERCISE

A scenario that changes as the response develops

The template is already populated with public injects, facilitator-only context, discussion prompts, private role messages, and a final hotwash.

  1. Monday · 08:10
    Module 1 · Detection and containment

    Unusual help-desk activity

    The security team identifies a successful help-desk password reset for a remote employee followed by a new multifactor-authentication enrollment. The employee says they did not request either action.

  2. Monday · 09:05
    Module 1 · Detection and containment

    Privileged access expands

    Investigators find that the compromised account approved an emergency administrator request. The attacker may have accessed virtualization management, directory services, backup consoles, and a cloud file repository.

  3. Monday · 10:20
    Module 1 · Detection and containment

    Sensitive archive accessed

    Cloud logs show bulk downloads from HR, customer-support, and legal repositories. The team cannot yet determine whether files left the environment or were only staged internally.

  4. Monday · 11:40
    Module 1 · Detection and containment

    Encryption begins

    Users across multiple offices report locked screens and inaccessible file shares. A ransom note demands cryptocurrency within 48 hours and claims that 420 gigabytes of data were stolen.

  5. Monday · 13:30
    Module 1 · Detection and containment

    Backups cannot yet be trusted

    The backup administrator reports that online recovery points were deleted. Offline copies exist, but the most recent verified clean set is six days old and restoration testing has not covered every critical dependency.

  6. Monday · 15:00
    Module 2 · Extortion and external response

    Attacker provides proof

    The attacker posts a small sample of employee and patient records and sends a private link containing additional files. The demand increases if payment is not initiated within six hours.

  7. Monday · 16:10
    Module 2 · Extortion and external response

    Patient care and payroll deteriorate

    Manual scheduling queues are failing, a regional clinic cannot retrieve current care instructions, and the payroll file due today is unavailable. Department leaders begin using personal email and consumer file-sharing tools.

PARTICIPANTS

Bring the decision-makers who would own the real event

Assign people to functions, not titles alone. If one person owns several functions, keep the roles distinct during discussion so conflicts and handoffs remain visible.

Incident CommanderChief Information Security OfficerIT Operations LeadGeneral CounselPrivacy OfficerBusiness Continuity LeadCommunications LeadFinance and Insurance LeadLaw Enforcement LiaisonExecutive Sponsor

REAL-WORLD INCIDENTS

Ground the exercise in events teams can recognize

Use these cases during planning or the prebrief. They are factual anchors, not scripts. Adapt the scenario to the organization’s technology, industry, geography, contracts, regulators, and risk profile.

LEGAL, REGULATORY & STANDARDS LENS

Authorities worth testing against the scenario

Applicability depends on the organization and facts. Use counsel and subject-matter owners to tailor deadlines, thresholds, privileges, preservation, reporting, and communications.

PRACTITIONER PERSPECTIVES

Law-firm and security-professional guidance

External perspectives help the design team challenge internal assumptions. They do not replace organization-specific legal or technical advice.

EXPECTED OUTPUT

Finish with an improvement plan, not a score.

  • A rehearsed ransomware command structure
  • A defensible payment and sanctions-review path
  • Mapped notice and disclosure decision points
  • Priority restoration and continuity actions
  • An owned, dated after-action improvement plan
Start with this exerciseRead the facilitator guide