NetFusion Designs logo
Heart icon
Support
Email
info@nfd.ca
Phone
289 212-3930(Canada)
IT Services
Icon dropdown arrow

Infrastructure Implementation

Project PlanningHardware Voice over IP (VoIP)Application DevelopmentCloud DesktopSecurity Cameras

Managed IT Services

IT Support24/7 HelpDeskCyber Security & AntivirusData Backups & Disaster
Recovery
Co-Managed ITComplianceEmergency Ransomware
Recovery
Penetration & Vulnerability
Assessment

Optimization of Processes

Microsoft 365 OptimizationVirtual CIO ServicesPenetration TestingInventory Lifecycle
Management
Transforming SMEs with AI
Industries
Icon dropdown arrow
Dental Managed IT Services
Construction
Hotels & Hospitality
Franchises
Financial & Insurance Services
Government
Health Care & PharmaceuticalLegal & Professional Services
Local Small & Medium Businesses
Manufacturing
Non-profit
Real Estate
Retail
Transportation & Logistics
Enterprise & Consulting
Publicly Traded Companies
Our Story
Icon dropdown arrow
About UsTestimonials
Partners
Sponsorship
BlogContact Us
Open menuClose menu
Icon chevron up
Browse Blog:
Business
Insight
Advice
Insight

Ransomware tabletop exercise: a ready-to-run playbook

If your incident response plan hasn’t been tested in the last year, schedule a facilitated ransomware tabletop exercise within the next 90 days. That single action does more to surface real gaps in decision authority, communications, and recovery capability than any policy review or compliance audit. CISA Tabletop Exercise Packages and NIST SP 800-61r2 give you free, authoritative starting points. NetFusion Designs Inc’s emergency ransomware recovery service is there if you need hands-on support before or after.

Your three immediate tasks:

  • Schedule the session within 90 days, blocking 90–180 minutes on calendars now.
  • Appoint a facilitator who is neutral, prepared, and not the person who wrote your IR plan.
  • Invite core participants today: CISO or security lead, legal counsel, communications lead, CFO, and at least one technical responder.

Key takeaways

A facilitated ransomware tabletop exercise is the single most effective way to surface decision, communications, and recovery gaps before a real incident forces you to find them under pressure.

Point Details
Schedule within 90 days Block 90–180 minutes and appoint a neutral facilitator before anything else.
Focus on three objectives Decision authority, backup recovery time, and communications ownership cover the highest-risk gaps.
Use free authoritative templates CISA Tabletop Exercise Packages and NIST SP 800-61r2 give you ready-to-run scenarios at no cost.
AAR drives real improvement Every gap needs a named owner and a deadline; re-run a focused exercise within six months to verify fixes.
NetFusion Designs Inc Provides end-to-end facilitation, custom scenario design, AAR delivery, and follow-on remediation support across Ontario and Canada.

Table of Contents

  • What is a ransomware tabletop exercise, and when should you use one?
  • How do you set clear objectives and measure success?
  • Who belongs in the room, and what does each person need to prepare?
  • What does pre-exercise planning actually look like?
  • A ready-to-run ransomware scenario with timed injects
  • How should the facilitator run the session?
  • How do you turn exercise findings into real improvements?
  • Which authoritative templates should you download?
  • What NetFusion Designs has learned from facilitating these exercises
  • What most organisations get wrong about tabletop exercises
  • NetFusion Designs Inc can facilitate your next exercise
  • Sources
  • FAQ

What is a ransomware tabletop exercise, and when should you use one?

A ransomware tabletop exercise is a discussion-based, facilitated simulation. Participants talk through a realistic ransomware scenario, make decisions in real time, and expose gaps in their plans without touching a single production system. No failover is triggered. No backups are restored. No alerts fire. The value is in the conversation, not the technology.

It sits in a distinct category from two other testing methods:

  • Full restore test: Verifies that backups actually recover to a usable state within your recovery time objective. A tabletop assumes backups exist; a restore test proves they work.
  • Red team or penetration test: Technical adversary simulation that finds exploitable vulnerabilities in your environment. A penetration and vulnerability assessment tells you where attackers can get in; a tabletop tells you what your team will do when they do.

Use a tabletop when you want to test decision-making, communications, and coordination under pressure. The right moments include: after a significant infrastructure change, following a real incident (yours or a peer organisation’s), during an annual IR plan review, or when new executives join who haven’t lived through a cyber crisis. For Canadian businesses facing an evolving threat environment, annual exercises are a minimum; twice yearly is better when staff turnover is high.


How do you set clear objectives and measure success?

Vague goals produce vague exercises. Before you design a single inject, define what you actually need to learn. Most objectives fall into five categories:

  • Decision authority: Who can authorise containment actions, ransom payment consideration, or external communications?
  • Containment and recovery prioritisation: Which systems get isolated first, and in what order does recovery happen?
  • Communications: Who speaks to the board, regulators, customers, and media, and when?
  • Legal and compliance sequencing: What are your notification obligations, and who triggers them?
  • Third-party coordination: Can you reach your cyber insurer, forensic vendor, and critical suppliers within the first two hours?

Pick one to three of these for a single session. Trying to test all five at once produces a shallow exercise that covers everything and validates nothing.

Example success metrics to track:

  • Time-to-decision for initial containment (target: under 30 minutes from detection)
  • Named decision owner for each critical action (aim for all decisions to have an owner by the end of the session)
  • Percentage of systems recoverable from tested backups (establish a baseline before the exercise where possible)
  • Number of AAR remediations with assigned owners and deadlines (aim for all gaps to be assigned owners promptly after the exercise)

Statistic callout: The DNI’s situational report on global ransomware activity through mid-2024 confirms that ransomware attack patterns remained consistent with prior years, meaning the scenarios you design today reflect the same tactics, double-extortion demands, and exfiltration claims that real threat actors are using right now.


Who belongs in the room, and what does each person need to prepare?

Getting the participant mix right is where most exercises succeed or fail before they start. CISA’s tabletop exercise packages consistently identify legal, communications, and finance as the roles most frequently absent from exercises and most frequently implicated in real incident failures.

Role Responsibility in the exercise One-line pre-work prompt
Executive sponsor Authorises decisions, models leadership tone Review your cyber insurance policy limits and coverage triggers
CISO / security lead Drives technical containment decisions Know your current backup state and last tested RTO
IT director / SOC analyst Executes technical actions, reports system status Confirm which systems are in scope and their dependencies
Legal counsel Advises on notification thresholds and privilege Know your provincial and federal breach notification timelines
Communications / PR lead Manages internal and external messaging Draft a holding statement template before the session
CFO / finance Approves emergency spend, advises on ransom payment authority Know your cyber insurance deductible and payment approval process
Operations / business owner Represents operational impact and recovery priorities List your top five revenue-critical processes
Vendor / MSP contact Advises on third-party dependencies and recovery support Confirm SLA response times and escalation contacts
Scribe / observer Records decisions, gaps, and action items Prepare an AAR template and a decision log

Observers attend silently and feed findings into the after-action review. They should not participate in discussion during the session; their job is to capture what the active participants miss.


What does pre-exercise planning actually look like?

Good planning takes two to three weeks for a 90-minute session. Rushing it produces a session where participants don’t know their roles, materials aren’t ready, and the facilitator is improvising.

Scope decisions to make first:

  • Which systems and business units are in scope (don’t try to cover everything in one session)
  • Which attack vector to simulate (phishing, RDP exploit, supply chain compromise, cloud credential theft)
  • Whether to include third-party vendors or run an internal-only session
  • Virtual vs. in-person (in-person produces richer discussion; virtual works well for geographically distributed teams)

Timeline template:

  1. Weeks 1–2: Finalise scope, confirm participants, assign facilitator, gather materials (backup metrics, SLA documents, IR plan, contact lists).
  2. Week 3: Distribute pre-read materials. Send role-specific prompts (not the scenario script). Confirm logistics.
  3. Day of: Facilitator arrives 30 minutes early. Scribe template and inject packets ready. No scenario details shared in advance.

Materials checklist:

  • Facilitator script with timed injects and discussion prompts
  • Inject packets (printed or shared screen, not emailed in advance)
  • Scribe template with decision log, gap log, and action item fields
  • AAR template
  • Current backup recovery metrics and RTO/RPO targets
  • Contact list: cyber insurer, forensic vendor, legal counsel, law enforcement contacts
  • Reference copy of your IR plan (participants should not rely on memory)

NIST SP 800-84 provides detailed guidance on structuring test plans and exercise programmes that support consistent validation of IR capabilities across sessions.


A ready-to-run ransomware scenario with timed injects

A ready-to-run ransomware scenario with timed injects — overview diagram

Scene-setting brief (read aloud at the start):

It is 7:42 AM on a Tuesday. Your IT helpdesk begins receiving calls from employees unable to access shared drives. Within minutes, a ransom note appears on affected workstations demanding payment in cryptocurrency. Initial indicators suggest the compromise began three days ago. A threat actor claims to have exfiltrated 40 GB of data and threatens to publish it on a leak site within 72 hours.

Timed injects and facilitator prompts:

  1. T+0 (Detection — 0:00–0:20): The helpdesk escalates to the security team. Three servers are unresponsive. The ransom note references a specific file server by name.

    • Who declares an incident? What is the first containment action? Who gets called in the next 10 minutes?
  2. T+1 (Confirmation — 0:20–0:40): Your SOC analyst confirms ransomware on 12 endpoints. The affected systems include your ERP platform. Backups for the ERP server haven’t been tested in six months.

    • Do you isolate the ERP server now, knowing it will halt operations? Who authorises that call?
  3. T+2 (Ransom demand — 0:40–0:55): The threat actor sends a direct email to your CEO with a payment portal link and a 72-hour deadline. Your cyber insurer requires notification before any payment decision.

    • Who contacts the insurer? Does legal counsel need to be on that call? What is your payment authority threshold?
  4. T+3 (Media contact — 0:55–1:05): A journalist contacts your communications team asking about a “major outage.” A post on social media from an employee mentions the ransomware note.

    • What is your holding statement? Who is the authorised spokesperson? Do you notify customers before the media story runs?
  5. T+4 (Backup integrity problem — 1:05–1:20): Your IT director reports that the most recent clean backup is 11 days old. Restoring from it means losing 11 days of transactions.

    • Do you continue recovery from the 11-day backup, or negotiate time with the threat actor? Who makes that call?
  6. T+5 (Law enforcement contact — 1:20–1:30): Your legal counsel recommends contacting the RCMP’s National Cybercrime Coordination Centre (NC3) and potentially INTERPOL given indicators of a cross-border actor.

    • Who makes the law enforcement call? What information do you share? Does reporting affect your insurance claim?
  7. T+6 (Data leak — 1:30–1:40): The threat actor posts a sample of what appears to be customer PII on a dark web leak site. You now have a confirmed data breach under PIPEDA.

    • What are your notification obligations? Who notifies the Office of the Privacy Commissioner? What is your timeline?

Inject bank for future exercises:

  • Supply chain compromise via a managed service provider’s remote access tool
  • Cloud credential theft leading to Microsoft 365 mailbox exfiltration
  • Insider-assisted exfiltration combined with ransomware deployment
  • Simultaneous attack on a subsidiary or affiliated organisation

How should the facilitator run the session?

The facilitator’s job is to surface gaps, not to teach. A facilitator who lectures, corrects, or leads participants toward the “right” answer turns the exercise into a compliance checkbox. CISA’s facilitation guidance frames the facilitator as a discovery tool, not an instructor.

Ground rules to state at the start:

  • No system changes, no real alerts, no live credentials during the session.
  • All discussion is confidential and protected under legal privilege where applicable.
  • Decisions made in the exercise are recorded but do not bind the organisation.
  • Silent observers do not participate; they observe and record.
  • The facilitator can pause, rewind, or skip an inject to keep discussion productive.

Facilitation techniques that work:

  • Timebox each inject to 10–15 minutes. If discussion stalls, inject the next complication.
  • When a participant says “we’d just follow the playbook,” ask: “Walk me through exactly what that looks like. Who calls whom first?”
  • When executives defer to technical staff, redirect: “This is a business decision. What does the business need to decide here?”
  • When disagreement surfaces, don’t resolve it. Record it as a gap and move on.

Pro Tip: Pre-brief your executive sponsor privately before the session. Executives who understand the exercise’s purpose tend to model honest engagement rather than defensive posturing, which sets the tone for the whole room.

Disputes about the “right” answer are often the most valuable moments in the exercise. They reveal where your IR plan is ambiguous or where two teams have incompatible assumptions. Record them verbatim.


How do you turn exercise findings into real improvements?

The after-action review (AAR) is where the exercise pays off. Without a structured AAR, findings evaporate within a week. With one, you have a remediation roadmap tied to named owners and deadlines.

AAR structure:

  • Executive summary: One page. What was tested, what worked, what didn’t, and the top three priorities.
  • Decision timeline: Chronological log of every decision made, who made it, and how long it took.
  • Gaps identified: Each gap rated by likelihood and impact (high/medium/low).
  • Recommended remediations: Specific, actionable fixes with suggested owners.

POA&M example:

Gap identified Risk rating Recommended action Owner Deadline Verification
No named decision owner for containment High Update IR plan with named authority matrix CISO 30 days IR plan review sign-off
ERP backup untested for 6 months High Schedule and document full restore test IT director 45 days Restore test report
Legal notification timeline unknown Medium Brief legal on PIPEDA obligations and draft notification template Legal counsel 30 days Template approved by legal
No holding statement for media Medium Draft and approve communications template Comms lead 21 days Template approved by CEO

Map each POA&M item to a NIST Cybersecurity Framework control category (Identify, Protect, Detect, Respond, Recover) so findings connect directly to your risk register and audit evidence. For organisations subject to regulatory frameworks, tools like Sentrix’s NIST SP 800-53 compliance resources can help map exercise outcomes to control baselines efficiently.

Report progress to leadership at 30, 60, and 90 days. Re-run a focused exercise on the highest-risk gaps within six months to validate that remediations actually work.


How do you turn exercise findings into real improvements? — overview diagram

Which authoritative templates should you download?

You don’t need to build a scenario from scratch. Several authoritative packages are freely available and designed for exactly this purpose.

  • CISA Tabletop Exercise Packages: The most comprehensive free resource for North American organisations. Includes facilitator guides, inject banks, and sector-specific scenarios covering ransomware and other cyber incidents. Start here if you’re running your first exercise or need a defensible template for a regulated industry client.

  • CISA resources — tabletop exercise packages: A broader library of cross-sector exercise packages and playbooks. Useful when you need sector-specific variants (healthcare, critical infrastructure, financial services) or want to build a multi-year exercise programme.

  • NCSC Exercise in a Box (UK): The UK National Cyber Security Centre’s free self-service exercise tool includes ransomware scenarios and facilitator materials. While designed for UK organisations, the scenario structures and inject formats adapt well to Canadian contexts. Use it when you want a second scenario design perspective or when running executive-only drills.

  • NIST SP 800-61r2: The foundational incident response lifecycle guide. Use it to align your exercise objectives to the Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident phases. Every AAR finding should map back to one of these phases.

  • NIST SP 800-84: Guidance on designing test, training, and exercise programmes. Particularly useful for building a multi-year exercise cadence and documenting your testing methodology for auditors.

Which to use when: Small businesses running their first exercise should start with CISA’s packages and NIST SP 800-61r2. Regulated industries (financial services, healthcare) benefit from CISA’s sector-specific variants. Executive-only drills work well with NCSC Exercise in a Box’s shorter formats. Organisations needing to evidence regular testing for compliance purposes should reference NIST SP 800-84 for programme design and Sentrix’s CAN/DGSI 104 compliance automation for Canadian regulatory evidence requirements.


What NetFusion Designs has learned from facilitating these exercises

Running tabletop exercises with small and mid-sized businesses across Ontario reveals a consistent pattern. Before an exercise, most organisations believe their IR plan is adequate. After one, the most common findings are:

  • Ambiguous decision authority: No single named person can authorise containment or payment decisions without a committee that can’t assemble quickly enough.
  • Untested backups: Backups exist, but recovery time has never been measured. The first time they discover their ERP restore takes 18 hours is during the exercise, not a real incident.
  • Legal and communications gaps: Legal counsel doesn’t know the PIPEDA notification timeline. The communications lead has no pre-approved holding statement.
  • Third-party blind spots: The organisation assumes their MSP or cloud provider will handle recovery, but no one has confirmed SLAs or tested the escalation path.

After a well-facilitated exercise, those same organisations leave with a named decision authority matrix, a scheduled backup restore test, a drafted notification template, and a confirmed vendor escalation path. The layered cybersecurity strategy that looks solid on paper becomes a tested, credible plan.

NetFusion Designs Inc is SOC 2 Type II certified, which means the security controls we bring to facilitation and remediation engagements have been independently verified. For publicly traded or regulated clients, that matters when you’re presenting exercise outcomes to a board or auditor.


What most organisations get wrong about tabletop exercises

The most common failure isn’t a bad scenario. It’s a facilitator who doesn’t push back.

When a participant says “we’d escalate to the CISO,” a passive facilitator moves on. A good facilitator asks: “Your CISO is travelling and unreachable. Who has authority now?” That one follow-up question surfaces a gap that no policy document would have caught.

The second most common failure is running the exercise without the CFO and legal counsel in the room. Technical teams can talk through containment for 90 minutes and feel productive. But the decisions that actually determine whether a ransomware incident becomes a manageable disruption or a regulatory and reputational crisis are financial and legal. Payment authority, notification timing, media response — none of those are IT decisions.

My advice when time is limited: focus the first exercise entirely on three things. Who can authorise containment? Are your backups tested and timed? Who speaks externally and when? Get those three questions answered with named owners and you’ve done more than most organisations accomplish in years of policy writing.

Leadership commitment to remediation ownership is the final piece. An AAR with no assigned owners is a document. An AAR with named owners, deadlines, and a 30-day check-in is a security improvement.


NetFusion Designs Inc can facilitate your next exercise

Knowing your IR plan has gaps is one thing. Running a session that surfaces exactly where those gaps are, and turning the findings into a remediation plan with named owners, is another. NetFusion Designs Inc delivers end-to-end tabletop facilitation for small and mid-sized businesses across Ontario and Canada.

NetFusion Designs Inc

What’s included in a NetFusion facilitation engagement:

  • Custom scenario design based on your industry, infrastructure, and threat profile
  • Facilitated session delivery with a neutral, experienced facilitator
  • Scribe and decision-log support throughout the session
  • Structured AAR with gap ratings, POA&M, and owner assignments
  • Follow-on remediation project options, including managed cybersecurity services and Microsoft 365 hardening

If a real incident hits before you’ve run your exercise, emergency IT support is available 24/7. Schedule a discovery call today to confirm your exercise date and facilitator.


Sources

  • CISA Tabletop Exercise Packages
  • NIST SP 800-61r2: Computer Security Incident Handling Guide
  • NIST Cybersecurity Framework
  • Worldwide ransomware attacks as of June 2024 (CTIIC)
  • INTERPOL spotlight — organised crime and related notices

FAQ

What is a ransomware tabletop exercise?

A ransomware tabletop exercise is a discussion-based simulation where participants work through a realistic ransomware scenario to test decision-making, communications, and recovery coordination without affecting live systems.

How long should a ransomware tabletop exercise take?

A focused session runs 90–180 minutes. Longer cross-functional exercises covering multiple attack phases can run up to a full day, but most organisations get strong results from a well-structured 90-minute session.

How often should you run a ransomware response drill?

Run a full cross-functional exercise at least once a year. After major infrastructure changes, staff turnover, or a real incident, a shorter focused drill within 30–60 days is advisable, as recommended in NIST SP 800-84.

What free templates are available for tabletop security exercises?

CISA Tabletop Exercise Packages are the most comprehensive free resource for North American organisations, including facilitator guides and ransomware-specific inject banks.

What should happen after a ransomware tabletop exercise?

Conduct a structured after-action review promptly, produce a POA&M with named owners and deadlines for every gap, and schedule a follow-up exercise within six months to verify that remediations are effective.

Recommended

  • Ransomware Hit 3 KW Manufacturers Last Year. Is Your Plant Next?Ransomware Hit 3 KW Manufacturers Last Year. Is Your Plant Next? | NFD
  • Emergency ransomware recovery service from NFD
  • 10 Biggest Cybersecurity Threats in Canada (2026 Guide)
  • Penetration & Vulnerability Assessment | NetFusion Designs

Continue Reading

What to Look for in a Kitchener-Waterloo MSP (a Buyer's Checklist)
How Much Does Managed IT Support Cost in Kitchener-Waterloo?
Endpoint detection and response: what IT teams need to know
Role of a 24/7 NOC in IT operations: what IT managers need to know
NetFusion Designs logo
NetFusion Designs is a globally recognized IT service provider and services clients across North America.

We hold a SOC 2 Type 2 report, and maintain internal processes and procedures that keep our clients’ data secure and confidential.
NetFusion Designs IT support team
IT Services Near Me
BurlingtonOakvilleHamiltonMississaugaMiltonBramptonEtobicokeBrantfordGuelphKitchenerWaterlooCambridgeSt CatharinesTorontoMarkhamCaledonNewmarket
Services
Project PlanningHardwareTelephony & VoIPApplication DevelopmentCloud DesktopSecurity CamerasHelpdesk & SupportCyber Security & Anti-VirusData Backups & Disaster RecoveryMicrosoft 365 OptimizationVirtual CIO ServicesPenetration TestingPricingSchedule a MeetingRemote Support
Pricing
Pages
Free Security ScanAbout UsOur Migration ApproachWork CultureOur Core ValuesCode of ConductTestimonialsContactBlogSchedule a MeetingRemote Support
TORONTO
Bank capital office building law
401 Bay St, 16th Floor, Toronto Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
MARKHAM
Bank capital office building law
141 Main Street N, Markham, ON L3P 1Y2
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
TRI-CITY AREA
(Kitchener / Waterloo / Cambridge)
Bank capital office building law
22 Frederick St, Suite 700, Kitchener Ontario
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
PEEL REGION
Bank capital office building law
6700 Century Ave, 3rd floor, Mississauga, ON L5N 1V8
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
DURHAM REGION
Bank capital office building law
1315 Pickering Parkway, Pickering, ON L1V 7G5
Email
info@nfd.ca
MONTREAL
Bank capital office building law
8815 Av du Parc #402, Montréal, QC H2N 1Y7
Email
info@nfd.ca
Phone
647-476-5259 (Canada)
Special Offers
Pie chart piechart stats analytics
IT-Optimization Session
Icon chevron right
Money safe safebox
800% ROI Consultancy Offer (Video)
Icon chevron right
Radio station signal antena tower
Coming Soon!
Icon chevron right
Terms and ConditionsPrivacy PolicyCookie Policy
© 2026 NetFusion Designs Inc.
LinkedInFacebookAlignable logo