Skip to content
Kodvalley

Cybersecurity

Ransomware Readiness & Tabletop Exercises

Facilitated crisis exercises for management and IT, plus a review of backups, response plans and reporting duties.

24 h NIS2 early warning practised
2 to 4 h per tabletop session
Board and IT together

Scope

What the programme includes

When ransomware hits, the first hours decide how much it costs. Teams that have practised know who decides, who calls whom and which systems to restore first. We run realistic crisis exercises for management and IT, and check that your backups and plans work in practice.

Executive tabletop

A guided crisis scenario for management and communications.

Technical drill

IT and security teams work through detection and containment.

Backup and recovery review

Whether backups are isolated, tested and fast to restore.

Response plan review

Roles, contacts and decisions written down and up to date.

Reporting duties

NIS2, GDPR and insurer notification deadlines.

Crisis communication

Messages for staff, clients, media and authorities.

A realistic exercise in five steps

Scenarios are based on current attacks against organisations like yours.

  1. 1

    Preparation

    Interviews and a review of your plans.

  2. 2

    Scenario

    A tailored attack story with realistic injects.

  3. 3

    Exercise

    A facilitated session with decisions under time pressure.

  4. 4

    Lessons

    What went well, what slowed you down.

  5. 5

    Action plan

    Concrete improvements with owners and dates.

What you receive

  1. 01 Tailored scenario and exercise materials
  2. 02 Facilitated tabletop session
  3. 03 Backup and recovery findings
  4. 04 Updated response plan and contact list
  5. 05 Action plan for management

Questions we often hear

Who should take part?

Management, IT, communications and legal or compliance. A good exercise involves the people who would make decisions in a real incident.

Do you touch our live systems?

No. The tabletop is a discussion exercise. Backup checks are agreed in advance and done together with your IT team.

How often should we practise?

At least once a year, and after major changes to your organisation or systems. NIS2 and DORA both expect regular exercises.