Simulate decisions, not malicious code
A tabletop exercise asks what people would do if an incident occurred. It does not need real ransomware, a test infection or access to a live customer's files. Use a fictional scenario and dummy system names so participants can focus on responsibilities and dependencies.
Choose a realistic but bounded situation: one work computer displays a ransom note and a shared folder is unavailable. The exercise should expose practical gaps without claiming that the organisation passed a technical penetration test.
Walk through the first decisions
- Describe the initial observation and ask who receives the report. Check whether that person can be reached if business email is unavailable.
- Ask who can authorise isolation and which critical workflow would be interrupted. Record the proposed containment method and what evidence it would change.
- Introduce a recovery question: the newest backup is available, but its administrator normally signs in from the affected computer. Identify a trusted access route and who can approve restoration.
- Ask how the team would communicate progress, preserve an incident record and decide which services return first. Record unresolved questions rather than inventing an answer under pressure.
Verify one preparation gap afterwards
Pick a harmless action from the findings, such as confirming the backup administrator can access the genuine portal from a separate trusted device. Keep the live check within approved permissions and avoid restoring over production data.
Include data and identity
Recovery is more than copying files. Ask which credentials may need rotation, how restored systems will be checked and whether suspicious mailbox or remote-access activity should be investigated. A clean-looking desktop does not demonstrate that every account is secure.
Measure decisions usefully
Record how quickly the team found the correct contact and whether responsibilities were clear. Do not award a security score merely because participants completed the meeting. Assign an owner and completion date to each actual improvement.
Repeat after meaningful changes
Update the scenario when replacing backup tools, moving services or changing staff. Keep a private exercise record and share only an appropriate summary. The strongest result is an improved response route that somebody verifies, not a dramatic scenario or a claim that the business can withstand every attack.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.