Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Activates for requests involving ransomware tabletop, incident response exercise, or ransomware readiness drill.
Testing organizational ransomware response procedures annually or after major infrastructure changes
Validating decision-making processes for ransom payment, regulatory notification, and public disclosure
Training executives, IT, legal, PR, and operations teams on their roles during a ransomware incident
Meeting cyber insurance policy requirements for documented incident response testing
Identifying gaps in recovery playbooks, communication plans, and backup procedures
Do not use as a substitute for technical controls testing. Tabletop exercises validate procedures and decision-making, not technical detection or prevention capabilities.
Common Misconfigurations & Verification
Scenario doesn't stress the recovery assumptions: the most common gap is an inject set that never tests what happens when backups are also hit. Build at least one branch where primary backups are encrypted and only the immutable/air-gapped copy survives — that forces the team to confront real RTO and whether vssadmin delete shadows-style backup destruction was anticipated.
No OFAC / payment-legality decision point: teams often discover mid-incident they have no framework for whether paying is even legal. Include an inject requiring an OFAC sanctions check against the threat actor's wallet and a documented payment-authorization chain.
Out-of-band comms untested: if the scenario assumes email/AD is up, you never learn that the contact list lives on the encrypted file server. Add an inject that takes down primary comms and verify the team has a real out-of-band channel and a current call tree.
Tech team dominates, legal/PR/exec stay passive: assign a facilitator independent of IR and use probing questions per role so notification timelines (GDPR 72h, HIPAA, SEC) are actually exercised.
Verification: confirm the exercise produces a dated AAR within ~5 business days with gaps rated and owners/deadlines assigned, then verify at the NEXT exercise that prior remediation items were actually closed — an AAR with no follow-up is the failure mode that negates the whole exercise. Where possible, validate one claim for real (e.g. trigger a test restore of a Tier 1 system) rather than assuming the documented RTO holds.
Prerequisites
Documented incident response plan (IRP) that participants should have read before the exercise
Facilitator who is independent from the IR team (to provide objective evaluation)
Ransomware scenario designed with injects that escalate over multiple rounds
Evaluation criteria aligned to NIST CSF Respond/Recover functions
Conference room or virtual meeting for 2-4 hours with no interruptions
Workflow
Step 1: Design the Exercise Scenario
Build a realistic scenario based on current threat actor TTPs:
Scenario Structure:
Phase 1: Initial Detection (30 min)
- SOC receives alert for suspicious process execution on file server
- EDR detects Cobalt Strike beacon on 3 workstations
- Inject: External threat intel report links C2 IP to LockBit affiliate
Phase 2: Escalation (30 min)
- Ransomware executes on 40% of servers during overnight hours
- Ransom note demands $2M in Bitcoin with 72-hour deadline
- Inject: Attackers contact media claiming data theft of customer PII
Phase 3: Decision Points (45 min)
- Backup assessment reveals immutable copies are intact but primary backups encrypted
- Legal advises on breach notification timeline (72 hours GDPR, varies by US state)
- Inject: Threat actor publishes sample of stolen data on leak site
Phase 4: Recovery and Communication (45 min)
- Recovery time estimate: 5-7 days from immutable backups
- Insurance carrier engages negotiation firm
- Inject: Major customer threatens contract termination without update within 24 hours
Scenario Variables to Customize:
Threat actor group and known TTPs
Percentage of infrastructure encrypted
Whether backups are intact, partially compromised, or fully destroyed
Type of data exfiltrated (PII, PHI, financial, trade secrets)
Tabletop Scenarios (from NCSC UK): Exercise in a Box tool providing free guided tabletop exercises
Ransomware Readiness Assessment (CISA): Self-assessment tool for evaluating ransomware preparedness
Common Scenarios
Scenario: Healthcare System Double Extortion Exercise
Context: A 5-hospital healthcare system conducts an annual ransomware tabletop. Previous exercise revealed gaps in HIPAA breach notification and clinical system recovery priority. This year's scenario simulates a double extortion attack targeting the EMR system.
Approach:
Design scenario based on Cl0p MOO (Managed Operations Operator) TTPs: exploitation of MOVEit vulnerability for initial access, data exfiltration of 500,000 patient records, followed by encryption of EMR database servers
Participants: CISO, CIO, CMO (Chief Medical Officer), General Counsel, VP Communications, Director of Clinical Operations, Privacy Officer, External IR firm representative
Phase 1 inject: EMR system down, emergency department diverting patients to neighboring hospital
Phase 2 inject: HHS OCR (Office for Civil Rights) contacts organization about reports of patient data on dark web