We Run Tabletop Ransomware Drills with Clients. The First One Is Always Ugly

A ransomware tabletop exercise is a 90-minute meeting where we walk a leadership team through a simulated attack, hour by hour, and nobody touches a computer. We have run these with Nashville businesses of every size. The first one is always ugly, and that is exactly why we run it. How the Drill Works Everyone […]

A ransomware tabletop exercise is a 90-minute meeting where we walk a leadership team through a simulated attack, hour by hour, and nobody touches a computer. We have run these with Nashville businesses of every size. The first one is always ugly, and that is exactly why we run it.

How the Drill Works

Everyone who would matter in a real incident sits at one table: owner, operations, finance, whoever runs IT. We read the scenario. It is 7:40 on a Tuesday morning, the file server is encrypted, and there is a note. Then we ask questions and let the room answer. Who declares this an incident? Who calls the insurance carrier, and does anyone know the number? What do we tell the staff arriving at 8? Can we take payroll offline safely? Who talks to clients, and what do they say?

Where the First Drill Falls Apart

The same five gaps surface almost every time:

  • Nobody owns the first decision. Ten minutes pass while the room debates who has authority to declare an incident and disconnect systems.
  • The insurance details live in someone’s email. The carrier’s incident hotline, the policy number, and the approved forensics vendor all need finding while the clock runs.
  • Backup confidence is theoretical. The room believes backups exist. Nobody can say when a restore was last tested or how long a full restore takes.
  • Email is the communication plan, and email is down. No out-of-band channel exists for reaching staff.
  • Client communication is improvised. Who says what, to whom, and when has never been decided, which is how panicked messages get sent.

Ugly Is the Point

Every one of those gaps is cheap to fix in a conference room and brutally expensive to discover live. The drill’s output is a one-page runbook: named decision-makers, a printed contact tree, the insurance numbers, backup restore times from an actual test, and a client communication script. Most of it is documentation work, the same discipline we described in Every New SNS Client Gets a Documentation Audit in Week One, pointed at the worst day instead of the average one.

What Happens After

We turn the findings into fixes: the runbook gets written, the backup restore gets tested for real, and the gaps feed into the client’s business continuity plan. Six months later we run the drill again. The second one is faster, quieter, and a little boring, which is the goal. If you want to know how your team would score before drilling, a security assessment shows the technical half of the picture, and our managed IT services clients get the drill as part of the standard rhythm.

A ransomware tabletop is a 90-minute simulated attack run around a table. First drills reliably expose five gaps: unclear authority, buried insurance details, untested backups, no out-of-band communications, and improvised client messaging. Fix them on paper, test the restore, drill again. Boring is the win condition.

Would Your Team Pass the 7:40 a.m. Test?

If you cannot name who declares the incident and what the first three phone calls are, the honest answer is not yet. We will run the drill with your leadership team and hand you the runbook that comes out of it.

You can also find us on Google to read what other Nashville businesses say about working with us. Call us at (615) 639-6326 any time.

Book a Tabletop Drill

Frequently Asked Questions About Ransomware Tabletop Exercises

What is a ransomware tabletop exercise?

A discussion-based simulation where leadership walks through a ransomware scenario step by step, making the decisions they would make in a real incident: declaring the incident, isolating systems, contacting insurance, communicating with staff and clients. No systems are touched. The output is a documented response plan and a list of gaps to fix.

How often should a small business run a tabletop exercise?

Annually at minimum, and again after major changes: new leadership, new systems, a new insurance policy, or an actual incident. The first drill finds the big gaps; the repeat confirms the fixes stuck and keeps the muscle memory current as people and systems change.

Who should participate in a ransomware tabletop drill?

The people who would decide things during a real incident, not just IT: the owner or CEO, operations, finance (they talk to the bank and the insurer), and whoever handles client communication. If a decision-maker is missing from the drill, the plan has a hole exactly where that person sits.