MYTHOSAI

Incident recovery / PRACTICAL GUIDE

Run a small ransomware tabletop exercise

Practise decisions and recovery dependencies without encrypting files or deploying malware.

Before you start

Two or more relevant staff, a private worksheet and a fictional incident scenario.

Simulate decisions, not malicious code

A tabletop exercise asks what people would do if an incident occurred. It does not need real ransomware, a test infection or access to a live customer's files. Use a fictional scenario and dummy system names so participants can focus on responsibilities and dependencies.

Choose a realistic but bounded situation: one work computer displays a ransom note and a shared folder is unavailable. The exercise should expose practical gaps without claiming that the organisation passed a technical penetration test.

Walk through the first decisions

  1. Describe the initial observation and ask who receives the report. Check whether that person can be reached if business email is unavailable.
  2. Ask who can authorise isolation and which critical workflow would be interrupted. Record the proposed containment method and what evidence it would change.
  3. Introduce a recovery question: the newest backup is available, but its administrator normally signs in from the affected computer. Identify a trusted access route and who can approve restoration.
  4. Ask how the team would communicate progress, preserve an incident record and decide which services return first. Record unresolved questions rather than inventing an answer under pressure.

Verify one preparation gap afterwards

Pick a harmless action from the findings, such as confirming the backup administrator can access the genuine portal from a separate trusted device. Keep the live check within approved permissions and avoid restoring over production data.

Include data and identity

Recovery is more than copying files. Ask which credentials may need rotation, how restored systems will be checked and whether suspicious mailbox or remote-access activity should be investigated. A clean-looking desktop does not demonstrate that every account is secure.

Measure decisions usefully

Record how quickly the team found the correct contact and whether responsibilities were clear. Do not award a security score merely because participants completed the meeting. Assign an owner and completion date to each actual improvement.

Repeat after meaningful changes

Update the scenario when replacing backup tools, moving services or changing staff. Keep a private exercise record and share only an appropriate summary. The strongest result is an improved response route that somebody verifies, not a dramatic scenario or a claim that the business can withstand every attack.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.