Information & Communications Technology

Ransomware Readiness Planning and Tabletop Exercise Design

Builds ransomware readiness assessment, response playbooks and tabletop exercise design so organisations test decisions before a real attack forces them.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Ransomware readiness plans often exist as untested documents, and the first time anyone reads them closely tends to be during the incident itself, when it is too late to fix gaps in authority, backups or communications. This course teaches ransomware readiness planning and tabletop exercise design together, because a plan and a rehearsal of that plan solve different problems. Participants learn to map the ransomware attack lifecycle against current controls, define decision authority for isolation and ransom payment questions in advance, and write playbooks that preserve forensic evidence during containment. Sessions focus heavily on tabletop exercise craft: building realistic scenarios with sequenced injects, facilitating cross-functional participation from legal and communications teams, and running after-action reviews that convert findings into owned action items. Practical exercises include drafting a ransomware scenario for a sample organisation, writing exercise injects that escalate pressure realistically, and facilitating a short tabletop segment. Participants leave with a scenario design template, an inject library structure and an after-action review format.

Expected Learning Outcomes

01

Map the ransomware attack lifecycle to identify which stages current controls fail to interrupt.

02

Test backup immutability and restoration to confirm recovery works before an incident occurs.

03

Define decision authority for system isolation, ransom payment and regulatory notification.

04

Write isolation and recovery playbooks that preserve forensic evidence during containment.

05

Design realistic tabletop scenarios with sequenced injects that force genuine decisions.

06

Facilitate tabletop exercises and convert findings into prioritised, owned action items.

07

Draft crisis communication templates for employees, customers, regulators and media.

Who Should Attend

01

Incident response leads building a ransomware-specific response plan and playbooks.

02

Business continuity and resilience managers responsible for readiness testing.

03

Chief information security officers who must brief executives on ransomware readiness.

04

IT infrastructure teams responsible for backup immutability and restoration testing.

05

Legal, communications and risk staff who participate in ransomware tabletop exercises.

06

Security consultants designing tabletop exercises for client organisations.

Course Modules

Select any module to see its sessions and points.

01

Assessing Ransomware Readiness

2 sessions · 8 points

Session 1Mapping the Ransomware Attack Lifecycle

  • Trace the ransomware attack lifecycle from initial access through lateral movement to extortion.
  • Identify which stage current controls are most likely to interrupt and which stages remain uncovered.
  • Assess backup immutability and offline isolation against realistic ransomware behaviour.
  • Evaluate privileged access exposure that would let an attacker reach backup and domain infrastructure.

Session 2Closing Readiness Gaps Before an Incident

  • Prioritise readiness investments by which gap most shortens attacker dwell time or limits blast radius.
  • Test backup restoration on a schedule that proves recovery works rather than assuming it does.
  • Segment networks so a single compromised segment cannot reach backup and critical infrastructure.
  • Establish a retainer with external incident response and forensics specialists ahead of need.
02

Building the Ransomware-Specific Response Plan

2 sessions · 8 points

Session 1Response Roles, Authority and Escalation

  • Define decision authority for isolating systems, including who can take production offline unapproved.
  • Establish the legal and regulatory considerations that inform any ransom payment decision.
  • Identify mandatory notification obligations to regulators and affected individuals by jurisdiction.
  • Document escalation paths to executive leadership and the board for a confirmed event.

Session 2Isolation, Evidence and Recovery Sequencing

  • Write playbooks for isolating affected network segments while preserving forensic evidence.
  • Sequence system recovery by business criticality and confirmed clean restoration points.
  • Plan for double extortion scenarios where data exfiltration precedes encryption.
  • Coordinate recovery actions with external forensics investigators without destroying evidence.
03

Designing Tabletop Exercises

2 sessions · 8 points

Session 1Building Realistic Exercise Scenarios

  • Design a ransomware scenario grounded in the organisation's actual systems and dependencies.
  • Write sequenced injects that reveal new information and force decisions as the exercise progresses.
  • Calibrate scenario difficulty to test genuine decision points rather than confirm assumptions.
  • Involve legal, communications and executive participants alongside technical responders.

Session 2Facilitating Exercises and Capturing Findings

  • Facilitate a tabletop exercise so every participant engages with their real decision-making authority.
  • Capture decisions, gaps and unresolved questions in real time during the exercise.
  • Run a structured after-action review that separates plan gaps from execution gaps.
  • Convert exercise findings into a prioritised action list with named owners and deadlines.
04

Communications and Continuous Readiness

2 sessions · 8 points

Session 1Planning Crisis Communications

  • Draft communication templates for employees, customers, regulators and media ahead of an incident.
  • Define approval workflows that let communications move quickly without sacrificing accuracy.
  • Plan for scenarios where attackers contact customers or media directly during double extortion.
  • Coordinate messaging with legal counsel to avoid statements that create liability exposure.

Session 2Sustaining Readiness Over Time

  • Schedule recurring tabletop exercises so readiness does not decay as systems and staff change.
  • Update the response plan after every exercise and every real security incident regardless of scale.
  • Track readiness metrics such as backup restoration time and time to isolate a simulated segment.
  • Review cyber insurance policy requirements against the tested response plan for coverage gaps.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course