Ransomware tabletop exercise for non-technical teams: a facilitator guide

Run a ransomware tabletop for non-technical teams with fictional injects, clear roles, escalation decisions, continuity questions and a downloadable facilitator pack.

CyberPlay editorial team · Published · Updated · 8 min read

Guide and exercises in English

Scene from Ransomware Reaction.

Expand image

From the CyberPlay Ransomware Reaction gallery. Illustrative game scene; any interface text shown is in English.

A ransomware tabletop exercise is a facilitated discussion in which a team works through a fictional incident and explains what it would do. For non-technical participants, the useful questions concern reporting, authority, business priorities, customer communication and coordination. The exercise can expose a missing contact or an unapproved workaround before those gaps matter during an actual disruption.

This guide provides an original 60-minute scenario and a downloadable facilitator pack. The duration is a suggested agenda, not a validated standard. Nothing is encrypted, disconnected or sent to customers. Participants discuss decisions using fictional events and their real approved plans. Technical containment, investigation and recovery remain with the authorised response team.

What you’ll take away

  • Practise escalation, coordination and continuity decisions within defined roles.
  • Keep the exercise fictional and separate from operational systems.
  • Record assumptions and unresolved questions instead of inventing capabilities.
  • Finish with owned improvement actions and a follow-up date.

1. Set three objectives before the session

Choose a manageable scope: recognise when to escalate, coordinate when the normal communication channel is unavailable, and authorise a temporary business workflow. Write what successful discussion would demonstrate for each objective. Avoid trying to test the entire recovery architecture and every regulatory obligation in one introductory meeting.

NIST SP 800-61 Rev. 3 places incident response within broader cybersecurity risk management. Use the tabletop to connect ordinary team decisions with that response structure. CISA also publishes cybersecurity exercise scenarios, including ransomware. Those resources are useful for a more formal exercise programme after the team has rehearsed these basic coordination questions.

Ransomware Reaction gameplay: preparing a useful incident report.

Expand image · Game screenshot · English interface

  1. Include time and device

    Report the observed symptoms, when they appeared, and the affected device through the organisation's approved reporting route.

  2. Distinguish observation from diagnosis

    Separate direct observations from suspected causes so responders can investigate without treating an early guess as fact.

Ransomware Reaction gameplay: preparing a useful incident report.

Section sources: Incident Response Recommendations and Considerations, SP 800-61 Rev. 3 · Cybersecurity Scenarios

2. Assign roles and decision authority

Invite a facilitator, a note-taker, the incident contact, a business operations representative, a customer-communications owner and an appropriate manager. Include the people who own privacy, legal or sector-specific obligations where the scenario requires them. One person can represent more than one role in a small organisation, but the responsibilities should remain explicit.

2. Assign roles and decision authority
RoleExercise responsibility
FacilitatorPresent fictional facts, manage time and keep discussion inside scope.
Note-takerRecord decisions, assumptions, gaps, owners and follow-up dates.
Incident coordinatorExplain escalation and coordinate the authorised response process.
Business operations ownerIdentify critical work and permitted continuity options.
Communications ownerDefine internal and external messaging approval routes.
Management and specialist ownersResolve authority questions and identify obligations requiring assessment.

3. Prepare the room and the exercise rules

Bring the current incident contact list, reporting instructions, continuity plan and communication approval process. Use offline copies where appropriate so the discussion can explore an unavailable normal system. Check contact details through an agreed preparation step; do not surprise real responders by placing an unannounced exercise call. Mark all materials clearly as an exercise.

State the rules aloud: participants describe actions rather than execute them; no production changes, account resets or customer notifications take place; a real incident stops the exercise. Unknowns should be recorded, not filled with convenient assumptions. If someone says “IT will restore everything”, ask which approved plan and owner support that expectation.

4. Follow the suggested 60-minute agenda

The fictional organisation is a small services company with a shared document workspace, a customer support queue and scheduled work due that afternoon. Replace those details with comparable fictional business functions if needed. Avoid using a real customer’s name or actual sensitive records. The facilitator releases information gradually so the group has to make decisions with uncertainty.

4. Follow the suggested 60-minute agenda
TimeStageQuestion to resolve
0–10 minutesBriefing and rolesWhat can each person decide, and how will gaps be recorded?
10–20 minutesInject 1: files unavailableHow is the concern reported and escalated?
20–30 minutesInject 2: normal chat unreliableHow do teams coordinate through the approved fallback?
30–40 minutesInject 3: customers need answersWho approves the message and a temporary workflow?
40–50 minutesInject 4: recovery uncertaintyWhich business priorities and information guide the response?
50–60 minutesDebriefWhich improvements need owners, deadlines and verification?
Signal: A colleague cannot access shared files. Escalate: Notify the designated incident contact. Coordinate: Clarify decisions, roles and communications. Improve: Assign owners to gaps found in the debrief.

Expand image

Practise the conversation before the incident. Discussion exercise: use your organisation's authorised response plan. Original CyberPlay explanatory diagram.

5. Inject 1: an employee cannot open shared files

Read this fictional update: “At 09:10, a team member says several shared files have unusual names and cannot be opened. Another employee reports a message demanding payment on their work screen. The normal reporting service is still available.” Ask the group to describe the first report, who receives it and how the business owner learns that work may be affected.

The employee’s job is to follow the approved reporting and immediate-response instructions, providing accurate observations. The group should not improvise technical containment. CISA’s ransomware guidance includes coordinated isolation and evidence considerations; actions such as disconnecting or powering down systems have operational consequences and belong to the authorised procedure and response team.

  • What facts are known, and which are assumptions?
  • Who can declare or coordinate an incident?
  • What should the reporting employee do while waiting for instructions?
  • How is the report handled if the primary contact does not respond?
Ransomware Reaction gameplay: inspecting an unexpected file change.

Expand image · Game screenshot · English interface

  1. Look for wider patterns

    Look for additional unusual changes; one file error alone does not establish the cause or diagnosis.

  2. Follow the incident process

    Use the approved incident process and response contacts; technical containment belongs to the authorised team and procedure.

Ransomware Reaction gameplay: inspecting an unexpected file change.

Section sources: #StopRansomware Guide

6. Inject 2: the usual chat channel becomes unreliable

Read this fictional update: “At 09:25, some employees cannot use the normal chat service. A message in an existing group claims to be from support and asks everyone to use a new public chat room for recovery instructions.” Ask how participants verify that instruction and where the approved fallback channel is documented.

Do not assume that a familiar group conversation makes every new instruction trustworthy. The incident coordinator should explain the established alternative and how the team will recognise authorised directions. If no fallback exists, record that gap and discuss who should define it. Avoid creating a real emergency group during the exercise without following the organisation’s normal approval and access process.

7. Inject 3: customer pressure encourages a workaround

Read this fictional update: “At 09:40, a customer requests an urgent status update. A team member proposes moving yesterday’s customer export to a personal cloud account so work can continue. The export may contain information that is not current.” Ask who can authorise continuity, what information is safe to use and how the external message is approved.

8. Inject 4: recovery timing and data exposure are uncertain

Read this fictional update: “At 10:00, the response team has not confirmed when the shared workspace will return. A claimant alleges that company information was copied. The claim has not been verified. Management asks which services should be restored first and what can be said to customers.” Ask the group to separate verified facts, claims and unknowns in its decision log.

The business owner can explain dependencies and priorities; the technical team evaluates recovery options. Designated specialist owners assess notification duties and other legal or contractual requirements. Do not invent a universal reporting deadline or have ordinary employees negotiate with the claimant. The exercise should establish who owns those decisions and what information they need.

9. Debrief with a decision log and improvement actions

Ask what worked, where the team relied on assumptions and which missing process made a decision difficult. Record each gap in a form that can be resolved. “Communication was unclear” is too vague. “Publish and verify the incident fallback contact route, owned by the incident coordinator, before the next exercise” provides a concrete action.

9. Debrief with a decision log and improvement actions
Log fieldWhat to write
ObservationThe specific point where a decision or handoff became difficult.
ConsequenceWhat business or response activity could be delayed or mishandled.
ActionThe practical change required to resolve the gap.
Owner and due dateThe person accountable for completing the change and the agreed date.
VerificationHow the team will check that the new process works.

10. Verify improvements and connect individual practice

Send the decision log through the organisation’s agreed internal process and schedule a review of the actions. Keep exercise notes only as detailed as necessary for that purpose. In a later session, change one dependency—such as the unavailable contact or affected service—and see whether the revised process still works. A tabletop discussion does not by itself prove that backups restore correctly or that a technical recovery plan has been tested.

CyberPlay’s ransomware scenarios can provide individual practice before or after the team discussion. Use the topic directory to select an appropriate game, then connect one decision to the real escalation process. Keep the distinction clear: a game practises choices, the tabletop rehearses coordination, and operational recovery needs its own authorised validation.

Ransomware Survival gameplay: reviewing fictional results; all scores, hours and costs are scenario values.

Expand image · Game screenshot · English interface

  1. Review what can recover

    Identify which work may be recoverable and which dependencies or missing information still need an authorised assessment.

  2. Verify restores through testing

    Test restores through an authorised process; the game's recovery numbers illustrate a scenario and are not operational evidence.

Ransomware Survival gameplay: reviewing fictional results; all scores, hours and costs are scenario values.

Take it with you

Put the decision into practice

Explore ransomware scenarios and practise recognising the point where an employee should escalate to the authorised response team.

Explore ransomware games

Sources and further reading

  1. Incident Response Recommendations and Considerations, SP 800-61 Rev. 3 — NIST. Accessed 2026-09-13
  2. Cybersecurity Scenarios — CISA. Accessed 2026-09-13
  3. #StopRansomware Guide — CISA and partner agencies. Accessed 2026-09-13

Keep exploring

All articles

Contact · About