
If your incident response plan hasn’t been tested in the last year, schedule a facilitated ransomware tabletop exercise within the next 90 days. That single action does more to surface real gaps in decision authority, communications, and recovery capability than any policy review or compliance audit. CISA Tabletop Exercise Packages and NIST SP 800-61r2 give you free, authoritative starting points. NetFusion Designs Inc’s emergency ransomware recovery service is there if you need hands-on support before or after.
Your three immediate tasks:
A facilitated ransomware tabletop exercise is the single most effective way to surface decision, communications, and recovery gaps before a real incident forces you to find them under pressure.
| Point | Details |
|---|---|
| Schedule within 90 days | Block 90–180 minutes and appoint a neutral facilitator before anything else. |
| Focus on three objectives | Decision authority, backup recovery time, and communications ownership cover the highest-risk gaps. |
| Use free authoritative templates | CISA Tabletop Exercise Packages and NIST SP 800-61r2 give you ready-to-run scenarios at no cost. |
| AAR drives real improvement | Every gap needs a named owner and a deadline; re-run a focused exercise within six months to verify fixes. |
| NetFusion Designs Inc | Provides end-to-end facilitation, custom scenario design, AAR delivery, and follow-on remediation support across Ontario and Canada. |
A ransomware tabletop exercise is a discussion-based, facilitated simulation. Participants talk through a realistic ransomware scenario, make decisions in real time, and expose gaps in their plans without touching a single production system. No failover is triggered. No backups are restored. No alerts fire. The value is in the conversation, not the technology.
It sits in a distinct category from two other testing methods:
Use a tabletop when you want to test decision-making, communications, and coordination under pressure. The right moments include: after a significant infrastructure change, following a real incident (yours or a peer organisation’s), during an annual IR plan review, or when new executives join who haven’t lived through a cyber crisis. For Canadian businesses facing an evolving threat environment, annual exercises are a minimum; twice yearly is better when staff turnover is high.
Vague goals produce vague exercises. Before you design a single inject, define what you actually need to learn. Most objectives fall into five categories:
Pick one to three of these for a single session. Trying to test all five at once produces a shallow exercise that covers everything and validates nothing.
Example success metrics to track:
Statistic callout: The DNI’s situational report on global ransomware activity through mid-2024 confirms that ransomware attack patterns remained consistent with prior years, meaning the scenarios you design today reflect the same tactics, double-extortion demands, and exfiltration claims that real threat actors are using right now.
Getting the participant mix right is where most exercises succeed or fail before they start. CISA’s tabletop exercise packages consistently identify legal, communications, and finance as the roles most frequently absent from exercises and most frequently implicated in real incident failures.
| Role | Responsibility in the exercise | One-line pre-work prompt |
|---|---|---|
| Executive sponsor | Authorises decisions, models leadership tone | Review your cyber insurance policy limits and coverage triggers |
| CISO / security lead | Drives technical containment decisions | Know your current backup state and last tested RTO |
| IT director / SOC analyst | Executes technical actions, reports system status | Confirm which systems are in scope and their dependencies |
| Legal counsel | Advises on notification thresholds and privilege | Know your provincial and federal breach notification timelines |
| Communications / PR lead | Manages internal and external messaging | Draft a holding statement template before the session |
| CFO / finance | Approves emergency spend, advises on ransom payment authority | Know your cyber insurance deductible and payment approval process |
| Operations / business owner | Represents operational impact and recovery priorities | List your top five revenue-critical processes |
| Vendor / MSP contact | Advises on third-party dependencies and recovery support | Confirm SLA response times and escalation contacts |
| Scribe / observer | Records decisions, gaps, and action items | Prepare an AAR template and a decision log |
Observers attend silently and feed findings into the after-action review. They should not participate in discussion during the session; their job is to capture what the active participants miss.
Good planning takes two to three weeks for a 90-minute session. Rushing it produces a session where participants don’t know their roles, materials aren’t ready, and the facilitator is improvising.
Scope decisions to make first:
Timeline template:
Materials checklist:
NIST SP 800-84 provides detailed guidance on structuring test plans and exercise programmes that support consistent validation of IR capabilities across sessions.

Scene-setting brief (read aloud at the start):
It is 7:42 AM on a Tuesday. Your IT helpdesk begins receiving calls from employees unable to access shared drives. Within minutes, a ransom note appears on affected workstations demanding payment in cryptocurrency. Initial indicators suggest the compromise began three days ago. A threat actor claims to have exfiltrated 40 GB of data and threatens to publish it on a leak site within 72 hours.
Timed injects and facilitator prompts:
T+0 (Detection — 0:00–0:20): The helpdesk escalates to the security team. Three servers are unresponsive. The ransom note references a specific file server by name.
T+1 (Confirmation — 0:20–0:40): Your SOC analyst confirms ransomware on 12 endpoints. The affected systems include your ERP platform. Backups for the ERP server haven’t been tested in six months.
T+2 (Ransom demand — 0:40–0:55): The threat actor sends a direct email to your CEO with a payment portal link and a 72-hour deadline. Your cyber insurer requires notification before any payment decision.
T+3 (Media contact — 0:55–1:05): A journalist contacts your communications team asking about a “major outage.” A post on social media from an employee mentions the ransomware note.
T+4 (Backup integrity problem — 1:05–1:20): Your IT director reports that the most recent clean backup is 11 days old. Restoring from it means losing 11 days of transactions.
T+5 (Law enforcement contact — 1:20–1:30): Your legal counsel recommends contacting the RCMP’s National Cybercrime Coordination Centre (NC3) and potentially INTERPOL given indicators of a cross-border actor.
T+6 (Data leak — 1:30–1:40): The threat actor posts a sample of what appears to be customer PII on a dark web leak site. You now have a confirmed data breach under PIPEDA.
Inject bank for future exercises:
The facilitator’s job is to surface gaps, not to teach. A facilitator who lectures, corrects, or leads participants toward the “right” answer turns the exercise into a compliance checkbox. CISA’s facilitation guidance frames the facilitator as a discovery tool, not an instructor.
Ground rules to state at the start:
Facilitation techniques that work:
Pro Tip: Pre-brief your executive sponsor privately before the session. Executives who understand the exercise’s purpose tend to model honest engagement rather than defensive posturing, which sets the tone for the whole room.
Disputes about the “right” answer are often the most valuable moments in the exercise. They reveal where your IR plan is ambiguous or where two teams have incompatible assumptions. Record them verbatim.
The after-action review (AAR) is where the exercise pays off. Without a structured AAR, findings evaporate within a week. With one, you have a remediation roadmap tied to named owners and deadlines.
AAR structure:
POA&M example:
| Gap identified | Risk rating | Recommended action | Owner | Deadline | Verification |
|---|---|---|---|---|---|
| No named decision owner for containment | High | Update IR plan with named authority matrix | CISO | 30 days | IR plan review sign-off |
| ERP backup untested for 6 months | High | Schedule and document full restore test | IT director | 45 days | Restore test report |
| Legal notification timeline unknown | Medium | Brief legal on PIPEDA obligations and draft notification template | Legal counsel | 30 days | Template approved by legal |
| No holding statement for media | Medium | Draft and approve communications template | Comms lead | 21 days | Template approved by CEO |
Map each POA&M item to a NIST Cybersecurity Framework control category (Identify, Protect, Detect, Respond, Recover) so findings connect directly to your risk register and audit evidence. For organisations subject to regulatory frameworks, tools like Sentrix’s NIST SP 800-53 compliance resources can help map exercise outcomes to control baselines efficiently.
Report progress to leadership at 30, 60, and 90 days. Re-run a focused exercise on the highest-risk gaps within six months to validate that remediations actually work.

You don’t need to build a scenario from scratch. Several authoritative packages are freely available and designed for exactly this purpose.
CISA Tabletop Exercise Packages: The most comprehensive free resource for North American organisations. Includes facilitator guides, inject banks, and sector-specific scenarios covering ransomware and other cyber incidents. Start here if you’re running your first exercise or need a defensible template for a regulated industry client.
CISA resources — tabletop exercise packages: A broader library of cross-sector exercise packages and playbooks. Useful when you need sector-specific variants (healthcare, critical infrastructure, financial services) or want to build a multi-year exercise programme.
NCSC Exercise in a Box (UK): The UK National Cyber Security Centre’s free self-service exercise tool includes ransomware scenarios and facilitator materials. While designed for UK organisations, the scenario structures and inject formats adapt well to Canadian contexts. Use it when you want a second scenario design perspective or when running executive-only drills.
NIST SP 800-61r2: The foundational incident response lifecycle guide. Use it to align your exercise objectives to the Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident phases. Every AAR finding should map back to one of these phases.
NIST SP 800-84: Guidance on designing test, training, and exercise programmes. Particularly useful for building a multi-year exercise cadence and documenting your testing methodology for auditors.
Which to use when: Small businesses running their first exercise should start with CISA’s packages and NIST SP 800-61r2. Regulated industries (financial services, healthcare) benefit from CISA’s sector-specific variants. Executive-only drills work well with NCSC Exercise in a Box’s shorter formats. Organisations needing to evidence regular testing for compliance purposes should reference NIST SP 800-84 for programme design and Sentrix’s CAN/DGSI 104 compliance automation for Canadian regulatory evidence requirements.
Running tabletop exercises with small and mid-sized businesses across Ontario reveals a consistent pattern. Before an exercise, most organisations believe their IR plan is adequate. After one, the most common findings are:
After a well-facilitated exercise, those same organisations leave with a named decision authority matrix, a scheduled backup restore test, a drafted notification template, and a confirmed vendor escalation path. The layered cybersecurity strategy that looks solid on paper becomes a tested, credible plan.
NetFusion Designs Inc is SOC 2 Type II certified, which means the security controls we bring to facilitation and remediation engagements have been independently verified. For publicly traded or regulated clients, that matters when you’re presenting exercise outcomes to a board or auditor.
The most common failure isn’t a bad scenario. It’s a facilitator who doesn’t push back.
When a participant says “we’d escalate to the CISO,” a passive facilitator moves on. A good facilitator asks: “Your CISO is travelling and unreachable. Who has authority now?” That one follow-up question surfaces a gap that no policy document would have caught.
The second most common failure is running the exercise without the CFO and legal counsel in the room. Technical teams can talk through containment for 90 minutes and feel productive. But the decisions that actually determine whether a ransomware incident becomes a manageable disruption or a regulatory and reputational crisis are financial and legal. Payment authority, notification timing, media response — none of those are IT decisions.
My advice when time is limited: focus the first exercise entirely on three things. Who can authorise containment? Are your backups tested and timed? Who speaks externally and when? Get those three questions answered with named owners and you’ve done more than most organisations accomplish in years of policy writing.
Leadership commitment to remediation ownership is the final piece. An AAR with no assigned owners is a document. An AAR with named owners, deadlines, and a 30-day check-in is a security improvement.
Knowing your IR plan has gaps is one thing. Running a session that surfaces exactly where those gaps are, and turning the findings into a remediation plan with named owners, is another. NetFusion Designs Inc delivers end-to-end tabletop facilitation for small and mid-sized businesses across Ontario and Canada.

What’s included in a NetFusion facilitation engagement:
If a real incident hits before you’ve run your exercise, emergency IT support is available 24/7. Schedule a discovery call today to confirm your exercise date and facilitator.
A ransomware tabletop exercise is a discussion-based simulation where participants work through a realistic ransomware scenario to test decision-making, communications, and recovery coordination without affecting live systems.
A focused session runs 90–180 minutes. Longer cross-functional exercises covering multiple attack phases can run up to a full day, but most organisations get strong results from a well-structured 90-minute session.
Run a full cross-functional exercise at least once a year. After major infrastructure changes, staff turnover, or a real incident, a shorter focused drill within 30–60 days is advisable, as recommended in NIST SP 800-84.
CISA Tabletop Exercise Packages are the most comprehensive free resource for North American organisations, including facilitator guides and ransomware-specific inject banks.
Conduct a structured after-action review promptly, produce a POA&M with named owners and deadlines for every gap, and schedule a follow-up exercise within six months to verify that remediations are effective.