← All guides

Ransomware tabletop exercise for the board: a step-by-step guide

October 5, 2026 · 7 min read · Also in Spanish

How to prepare and run a one-hour ransomware exercise with your executive team: scenario, roles, the hard calls, and what evidence to keep.

A ransomware attack stops being a technical problem within the first hour. From then on, the decisions that matter are business decisions: do we stop operations? Do we pay? Who do we notify, and when? What do we tell customers? Those calls belong to the executive team, not to IT. That's why the exercise has to happen with them.

This guide explains how to prepare and run a one-hour ransomware exercise with your executive team, without consultants and without a script nobody believes.

Before you start: one goal, five seats, three rules

One goal, not ten. For example: "Confirm we know who decides to stop operations, and how fast we notify the authorities." A concrete goal makes the debrief useful.

Five seats. At minimum:

  • Chief Executive: the business call and the board.
  • CISO: containment and technical scope.
  • CFO: liquidity, cyber insurance, pending payments.
  • General Counsel: notification duties and liability.
  • Head of Communications: customers, press and employees.

If someone can't attend, decide beforehand who covers their role. In a real crisis people are missing too.

A facilitator who doesn't decide. Their job is to present events, keep time and ask questions. If the facilitator is the CISO, someone else takes the security seat.

Three rules: no blame, a time limit per decision, and private decisions before discussion. The last one changes the outcome most. When everyone answers out loud, the room follows whoever speaks first, usually the most senior person. When each leader decides alone and all the answers are revealed at once, the real disagreements show up.

The scenario in three events

A good exercise doesn't tell everything at once. Information arrives in pieces, as in a real incident.

Event 1 · Encrypted at dawn. At 6:10 a.m., ERP and warehouse systems are encrypted across two regions. Shipping has stopped. A note claims 400 GB were exfiltrated before encryption.

  • CISO: do you isolate every site, only the affected regions, or keep running while you investigate?
  • CEO: do you convene the crisis committee now, or wait for more facts?
  • CFO: do you notify the insurer now?

Event 2 · The extortion. The attackers publish a sample of customer data and demand a ransom within 72 hours.

  • General Counsel: is personal data involved? Which notification clocks are running from now?
  • CFO and CEO: is payment on the table? Who has the final word?
  • Communications: what do you tell customers before they find out on social media?

Event 3 · The outside pressure. A journalist asks about the leak, and a key customer threatens to terminate the contract.

  • Communications: public statement, one-to-one answers, or silence?
  • CEO: do you call the customer yourself?

The hard calls, with no easy answers

To pay or not to pay. Paying doesn't guarantee you get the data back or that it stays unpublished. In the United States, the Treasury (OFAC) warns that paying sanctioned groups may violate sanctions, and your insurer may have its own conditions. The exercise doesn't have to settle the question, but it must make clear who decides, and with what information.

Notifying on time. The clocks start sooner than most executives think:

  • GDPR: 72 hours to notify the authority of a personal data breach.
  • NIS2: early warning within 24 hours, notification within 72 hours and a final report within a month, if your company is in scope.
  • SEC (US-listed companies): four business days from determining the incident is material.

If nobody asks about deadlines until the third event, that's your finding.

Stopping operations. Isolating everything protects systems but halts sales. Isolating too little keeps the business running but risks the attacker staying in. What matters is that the decision has an owner and a criterion agreed in advance.

How to run the hour

  1. Five minutes of context: the goal, the rules and the roles.
  2. For each event: present the situation, each executive decides privately against a time limit, all answers are revealed at once, and the differences are discussed. About 15 minutes per event.
  3. Fifteen minutes of debrief: what worked, where people disagreed, which decision nobody wanted to make.

Keep a record as it happens, not from memory afterwards.

What evidence to keep

Auditors and boards ask for proof that the response plan was tested. Keep:

  • who attended and in which role;
  • each decision, its rationale and the time;
  • the decisions that weren't made or came late;
  • the gaps found, each with an owner and a date.

Meeting notes that say "the plan was discussed" aren't evidence. A time-stamped decision log is.

Common mistakes

  • A generic scenario. Use your systems, your regions and your regulators.
  • No time pressure. Without a clock, everyone decides well.
  • The boss answers first. Decide privately, reveal at once.
  • No follow-up. If gaps have no owner, the next exercise will find them again.

Critios runs this kind of exercise: each executive decides privately against the clock, the crisis escalates from what the team chose, and you leave with a report of the decisions, the timings and the control coverage. Try the 5-minute demo or simulate your crises with us.

Run this exercise with your team, free.

We facilitate the first session with your executives and send you the report.