| name | performing-ransomware-tabletop-exercise |
| description | Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Use when working with performing ransomware tabletop exercise. |
| domain | cybersecurity |
| tags | ["ransomware","incident-response","tabletop-exercise","defense","preparedness"] |
| subdomain | ransomware-defense |
| version | 1.0.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.DS-11","RS.MA-01","RC.RP-01","PR.IR-01"] |
Performing Ransomware Tabletop Exercise
Overview
Cybersecurity skill for performing ransomware tabletop exercise. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing ransomware tabletop exercise"
-
"Plans and facilitates tabletop exercises simulating ransomware incidents to test"
-
Testing organizational ransomware response procedures annually or after major infrastructure changes
-
Validating decision-making processes for ransom payment, regulatory notification, and public disclosure
-
Training executives, IT, legal, PR, and operations teams on their roles during a ransomware incident
-
Meeting cyber insurance policy requirements for documented incident response testing
-
Identifying gaps in recovery playbooks, communication plans, and backup procedures
Do not use as a substitute for technical controls testing. Tabletop exercises validate procedures and decision-making, not technical detection or prevention capabilities.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Documented incident response plan (IRP) that participants should have read before the exercise
- Identified exercise participants from: executive leadership, IT/security, legal, communications/PR, HR, operations, and external counsel
- Facilitator who is independent from the IR team (to provide objective evaluation)
- Ransomware scenario designed with injects that escalate over multiple rounds
- Evaluation criteria aligned to NIST CSF Respond/Recover functions
- Conference room or virtual meeting for 2-4 hours with no interruptions
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}