Cybersecurity
Ransomware Readiness & Tabletop Exercises
Facilitated crisis exercises for management and IT, plus a review of backups, response plans and reporting duties.
Scope
What the programme includes
When ransomware hits, the first hours decide how much it costs. Teams that have practised know who decides, who calls whom and which systems to restore first. We run realistic crisis exercises for management and IT, and check that your backups and plans work in practice.
Executive tabletop
A guided crisis scenario for management and communications.
Technical drill
IT and security teams work through detection and containment.
Backup and recovery review
Whether backups are isolated, tested and fast to restore.
Response plan review
Roles, contacts and decisions written down and up to date.
Reporting duties
NIS2, GDPR and insurer notification deadlines.
Crisis communication
Messages for staff, clients, media and authorities.
A realistic exercise in five steps
Scenarios are based on current attacks against organisations like yours.
-
1
Preparation
Interviews and a review of your plans.
-
2
Scenario
A tailored attack story with realistic injects.
-
3
Exercise
A facilitated session with decisions under time pressure.
-
4
Lessons
What went well, what slowed you down.
-
5
Action plan
Concrete improvements with owners and dates.
What you receive
- 01 Tailored scenario and exercise materials
- 02 Facilitated tabletop session
- 03 Backup and recovery findings
- 04 Updated response plan and contact list
- 05 Action plan for management
Questions we often hear
Who should take part?
Management, IT, communications and legal or compliance. A good exercise involves the people who would make decisions in a real incident.
Do you touch our live systems?
No. The tabletop is a discussion exercise. Backup checks are agreed in advance and done together with your IT team.
How often should we practise?
At least once a year, and after major changes to your organisation or systems. NIS2 and DORA both expect regular exercises.
Related
Web Application Penetration Testing
OWASP-aligned manual and automated testing of web apps, APIs and authentication flows.
Learn moreNetwork & Infrastructure Testing
Internal and external network assessments, Active Directory and cloud perimeter reviews.
Learn moreMobile Application Security
iOS and Android testing based on OWASP MASVS, including reverse engineering.
Learn more