Performing Ransomware Tabletop Exercise
Overview
Cybersecurity skill for performing ransomware tabletop exercise. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing ransomware tabletop exercise"
"Plans and facilitates tabletop exercises simulating ransomware incidents to test"
Testing organizational ransomware response procedures annually or after major infrastructure changes
Validating decision-making processes for ransom payment, regulatory notification, and public disclosure
Training executives, IT, legal, PR, and operations teams on their roles during a ransomware incident
Meeting cyber insurance policy requirements for documented incident response testing
Identifying gaps in recovery playbooks, communication plans, and backup procedures
Do not use as a substitute for technical controls testing. Tabletop exercises validate procedures and decision-making, not technical detection or prevention capabilities.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Documented incident response plan (IRP) that participants should have read before the exercise
- Identified exercise participants from: executive leadership, IT/security, legal, communications/PR, HR, operations, and external counsel
- Facilitator who is independent from the IR team (to provide objective evaluation)
- Ransomware scenario designed with injects that escalate over multiple rounds
- Evaluation criteria aligned to NIST CSF Respond/Recover functions
- Conference room or virtual meeting for 2-4 hours with no interruptions
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for ransomware tabletop exercise operations.
- Prepare Environment — Set up tools, access, and data sources required for ransomware tabletop exercise.
- Execute Core Workflow — Perform the ransomware tabletop exercise operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-ransomware-tabletop-exercise3description: Use when plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making, and communication procedures. Designs realistic scenarios based on current ransomware threat actors (LockBit, ALPHV/BlackCat, Cl0p), injects covering double extortion, backup destruction, and regulatory notification requirements. Evaluates participant responses against NIST CSF and CISA guidelines. Use when working with performing ransomware tabletop exercise.4license: Apache-2.05---67# Performing Ransomware Tabletop Exercise89## Overview1011Cybersecurity skill for performing ransomware tabletop exercise. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing ransomware tabletop exercise"16- "Plans and facilitates tabletop exercises simulating ransomware incidents to test"171819- Testing organizational ransomware response procedures annually or after major infrastructure changes20- Validating decision-making processes for ransom payment, regulatory notification, and public disclosure21- Training executives, IT, legal, PR, and operations teams on their roles during a ransomware incident22- Meeting cyber insurance policy requirements for documented incident response testing23- Identifying gaps in recovery playbooks, communication plans, and backup procedures2425**Do not use** as a substitute for technical controls testing. Tabletop exercises validate procedures and decision-making, not technical detection or prevention capabilities.262728## When NOT to Use2930- When you lack proper authorization for testing31- For production systems without change management32- When the task requires legal or compliance expertise beyond technical scope333435## Prerequisites3637- Documented incident response plan (IRP) that participants should have read before the exercise38- Identified exercise participants from: executive leadership, IT/security, legal, communications/PR, HR, operations, and external counsel39- Facilitator who is independent from the IR team (to provide objective evaluation)40- Ransomware scenario designed with injects that escalate over multiple rounds41- Evaluation criteria aligned to NIST CSF Respond/Recover functions42- Conference room or virtual meeting for 2-4 hours with no interruptions4344## Workflow4546```python47# Example: IOC detection48import re4950IOC_PATTERNS = {51 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",52 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",53 "hash_md5": r"\b[a-f0-9]{32}\b",54 "hash_sha256": r"\b[a-f0-9]{64}\b",55}5657def extract_iocs(text: str) -> dict:58 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}59```60611. **Plan Operations** — Define objectives, scope, and success criteria for ransomware tabletop exercise operations.622. **Prepare Environment** — Set up tools, access, and data sources required for ransomware tabletop exercise.633. **Execute Core Workflow** — Perform the ransomware tabletop exercise operations following established procedures.644. **Validate Results** — Verify that results meet quality standards and objectives.655. **Report Findings** — Document results, observations, and recommendations.666. **Follow Up** — Track remediation actions and verify fixes where applicable.6768## Tools6970- **Analysis Platform** — Data processing and visualization71- **Collaboration Tools** — Team coordination and knowledge sharing727374## Process75761. **Design** — Define interface, identify patterns, plan implementation771. **Implement** — Write code following existing conventions, add tests781. **Verify** — Run tests, check integration, validate behavior7980## Verification8182- [ ] All ransomware tabletop exercise procedures executed completely and documented83- [ ] Findings validated against multiple data sources84- [ ] False positives identified and filtered85- [ ] Results documented with evidence and timestamps86- [ ] Recommendations provided with risk-based prioritization8788## Anti-Rationalization Table8990| Rationalization | Reality |91|---|---|92| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |93| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |94| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |