You already know ransomware is a real threat. You’ve read the headlines about businesses paying six figures, or losing weeks of data, or closing entirely. Maybe you even have a written response plan sitting in a folder somewhere. But has anyone actually tested it out loud, under pressure, with the real people who’d be in the room?
The stakes are high. According to IBM, organizations that extensively use AI-driven security and incident response save an average of $1.9 million per breach compared with those that don’t. One reason is that prepared teams can respond faster and make better decisions when an attack happens. Regular ransomware tabletop exercises help build that preparedness by giving your team a safe environment to practice roles, communication, and response procedures before a real incident occurs.
A ransomware tabletop exercise is how you find out if your plan works before an attacker forces the question for real.
This guide walks IT and operations leaders through running their first one, step by step, without needing a security background to follow along.
What a Ransomware Tabletop Exercise Actually Is
A ransomware tabletop exercise is a structured discussion, not a live drill. Your team sits down, walks through a simulated attack scenario, and talks through exactly how they’d respond. No systems get touched. No one panics for real. The goal is simple: find the gaps in your ransomware response plan while the stakes are still low.
Why Reading Your Plan Isn’t Enough
Plenty of businesses have a ransomware response plan written down somewhere. Far fewer have actually tested it out loud. Reading a plan and acting on it under pressure are two very different skills. A tabletop exercise reveals the difference fast, often in uncomfortable ways.
Quick question: if ransomware hit tonight, would your team know who to call first?
If you hesitated, that’s exactly the kind of gap a tabletop exercise is built to catch.
How to Run Your First Ransomware Tabletop
Running a ransomware tabletop doesn’t need to be complicated. Most first exercises take two to three hours and follow a similar structure from business to business.
Step 1: Build a Realistic Scenario
Start with a believable ransomware scenario based on your actual environment. Maybe it’s an infected email attachment opened by accounting. Maybe it’s a compromised remote login. Keep it specific to your business, not generic, so the discussion feels real to the people in the room.
Step 2: Walk Through the Ransomware Incident Response Steps
Once the scenario is set, walk the team through each decision point in real time. Who isolates affected systems? Who contacts legal or insurance? Who decides whether to pay a ransom, and who actually has that authority? These incident response steps should already exist in your plan. The exercise tests whether people actually know them, not just whether the document exists.
During the exercise, verify whether your IT support SLA clearly defines emergency response times, escalation procedures, and responsibilities during a security incident. If you’re unsure what your agreement should include, our guide explains what an IT support SLA actually guarantees.
Step 3: Document Every Gap You Find
Every ransomware drill surfaces gaps. Maybe backups haven’t been tested recently. Maybe two people both think they’re in charge of communication, or worse, no one does. Write every gap down as it surfaces. This list becomes your improvement roadmap.
While documenting gaps, don’t overlook software visibility. Unknown or unsupported applications can increase ransomware risk and complicate recovery efforts. Performing a software license audit helps identify outdated or unauthorized software before attackers can take advantage of it.
What Good Facilitation Looks Like
Someone needs to run the room. That person keeps the scenario moving, asks follow-up questions, and stops the discussion from drifting into unrelated topics. They should also stay neutral, since the goal is finding gaps, not defending existing decisions. A good facilitator pushes gently when answers feel vague. “We’d handle it” isn’t a real answer. Who handles it, and how, is what the exercise needs to uncover.
Facilitation matters more than most teams expect going in. Without it, exercises tend to drift toward comfortable assumptions instead of honest gaps. With it, even a short session surfaces issues that would otherwise stay hidden until a real incident forces them into the open.
Ransomware Tabletop Exercise Examples Worth Trying
Different scenarios test different weak points in your plan. Mixing these up across multiple exercises gives a fuller picture of where you actually stand.
| Scenario | What It Tests |
|---|---|
| Phishing email opens malware | Email security and user reporting habits |
| Remote desktop compromise | Access controls and monitoring |
| Vendor system breach | Third-party risk and vendor communication |
| After-hours attack | On-call response and escalation paths |
Running a Drill With Limited Internal Resources
Smaller teams often worry they don’t have the staff to run a proper exercise. You don’t need a large team. You need the right people in the room for two hours: leadership, IT, and anyone who handles customer or legal communication.
Quick question: does your current team have the bandwidth to run this exercise without outside help?
Many businesses bring in outside facilitation for their first attempt, simply to keep the discussion objective and moving forward. A responsive IT support team in Boston can run the session for you if your team would rather not facilitate it solo.
Turning Tabletop Results Into a Stronger Plan
A tabletop exercise only helps if the gaps it finds actually get fixed. Treat the output as a working document, not a report that gets filed away and forgotten about.
Updating technical defenses often matters as much as updating the written plan itself. Working with a managed IT team in Boston can help translate tabletop findings into real changes, like tightened access controls or faster backup recovery times.
It’s also worth revisiting your ransomware tabletop on a regular schedule, not just once. Threats change, staff turns over, and systems get added over time. An annual ransomware drill keeps the plan current instead of stale.
If your tabletop exercise reveals that your current provider isn’t keeping pace with these risks, it may be time to look elsewhere. Our guide on questions to ask before switching MSPs walks through exactly what to evaluate next.
Beyond reducing security risk, a well-tested incident response plan helps minimize downtime and prevents the kind of employee productivity loss that often follows major IT disruptions.
In Conclusion
A ransomware tabletop exercise turns a paper plan into a tested one. It shows you, in a low-stakes setting, exactly where your response would break down under real pressure. Running one doesn’t require a massive budget or a dedicated security team, just the right people and a realistic scenario.
BNMC works with growing businesses across Massachusetts, New Hampshire, and Florida to plan and facilitate exercises like these as part of a broader security strategy that holds up under real conditions.
FAQs
1. We’ve never done this before. How long does a first tabletop exercise take?
Plan for two to three hours, including time to debrief and document the gaps you find.
2. Our plan is only one page long. Is that enough to test?
It’s a starting point. The exercise itself will show you exactly where it needs more detail.
3. Should leadership be in the room, or just IT?
Both. Ransomware decisions, like paying a ransom, usually need leadership involved, not just IT.
4. What if the exercise reveals our backups haven’t actually been tested?
That’s a common, notable and fixable finding. Fix it immediately, since untested backups often fail when needed most.
5. Can we run this exercise virtually instead of in person?
Yes, a remote tabletop works well, as long as everyone stays focused and engaged throughout.