Cyber resilience

Tabletop ransomware exercise: rehearse the attack in one day

The only way to learn how many days your company needs to stand up after ransomware is to live through the attack in advance. A tabletop exercise does it without risk: 3-4 hours, the real team, a stopwatch. The output is measured readiness and a list of gaps found for free.

Published: July 18, 2026 · Author: Evgeny Telenkov · ≈ 6 min read
Tabletop ransomware exercise

Why rehearse if there is a plan

A paper plan is only verified by execution. The first rehearsal reveals the standard set: contacts are outdated, nobody can isolate the segment — the admin is on leave, the backup restores in a day rather than four hours, and management spends half an hour arguing who may stop shipments. Every such finding costs zero in an exercise; in a real attack it costs hours of downtime at a price you already know how to calculate.

The tabletop format

A tabletop is a facilitated game: the facilitator injects events, the team makes decisions in real time, no production systems are touched. Safe, cheap and sufficient — 80% of findings come from decisions and communications, not from technology. The technical layer — restoring a test environment from a real backup — is added as a second stage for the IT team.

The 72-hour scenario by phases

  1. Hour 0-2 (30 game minutes). Morning: files will not open, ransom notes on screens. Who notices, who calls whom, who has the right to cut the network? Testing activation triggers.
  2. Hours 2-8. The scale is clear: ERP and email are down. The crisis team assembles; decisions: pay or not (legal position), what to tell staff and clients — the spokesperson writes a real message against the clock.
  3. Days 1-2. Recovery: system order by cost of downtime, manual workarounds — how to take orders without ERP. Testing whether manual procedures exist beyond words.
  4. Day 3. Return to operations, notifications (clients, the regulator — a duty for financial organizations), debrief: what to fix.

Roles and observers

The players are those who will act for real: the CEO or COO (decisions), IT, finance, communications, legal, HR. The facilitator injects complications («a journalist is already calling», «the backup turned out encrypted»). An observer with a stopwatch logs the time of every decision — that is where the metrics come from.

What we measure

These numbers feed the resilience dashboard and turn «we are ready» from an opinion into a measured fact — the exact thing underwriters and boards want to see.

After the exercise

The output of one day is a short report: measured times, the top-10 findings each with an owner and a deadline, and management decisions on the contested points (ransom policy, team authority limits). In 3-6 months — a repeat run: the delta between timings is your progress. We deliver such exercises as a fixed-scope service — a scenario tailored to your operations, facilitation, measurements and a board-level report.

FAQ

How long does it take? The tabletop — one 3-4 hour block; the technical restore stage — a separate day for IT. Scenario preparation — a week.

Will it scare the team? The opposite: the most common feedback is relief. What frightens people is not a rehearsed attack — it is the unknown.

How often? Twice a year: one cyber scenario, one non-cyber (site accident, supplier loss — see exercise types).