The exercise is for the executives, not IT
Technical teams rehearse constantly. The decisions that determine how badly a ransomware event hurts are commercial: whether to shut down production, what to tell customers, and who is authorised to speak publicly.
Run the exercise with the CEO, CFO, operations lead, legal or compliance, and communications in the room. IT plays the technical responder.
Scenario
Friday 4:45pm. A file server is encrypting. A note claims 400GB of customer records were exfiltrated 11 days ago, with a 72-hour deadline. Backups exist but restoration time is untested.
Introduce injects every 15 minutes: a journalist calls, a major customer asks whether their data is affected, the finance system is confirmed encrypted, an employee posts about it on LinkedIn.
Debrief honestly
Capture every moment the room did not know who decides. Those are your real findings — not the technical gaps.
The checklist
Preparation
- Book 90 minutes with all decision-makers, devices away
- Appoint a facilitator and a scribe
- Print the scenario and injects — assume no systems are available
Decision points to force
- Who authorises shutting down production systems?
- At what point do you notify the OAIC and affected individuals?
- What is your position on paying a ransom, decided in advance?
- Who is the single public spokesperson?
- How do you communicate if email and Teams are unavailable?
Scoring
- Time to first containment decision under 15 minutes
- Out-of-band communications channel identified and reachable
- Legal and insurer notification triggers correctly identified
- Customer notification message drafted within the session
Follow-up
- Written findings circulated within 5 business days
- Each gap assigned an owner and due date
- Re-run the exercise within 12 months