| Quick Answer Ransomware puts executive teams through a sequence of high-stakes decisions under time pressure, imperfect information, and significant legal and financial consequence. Most executives have never made these decisions before. A facilitated ransomware tabletop exercise simulates the actual decision logic, surfaces the gaps in authority and process, and builds the shared experience that allows a team to respond more effectively when the real event occurs. |
Key Takeaways
- Ransomware response requires executive decisions, not just IT decisions. The choice to shut down operations, engage a ransom negotiator, notify customers, or brief the board cannot be delegated to the IT team.
- The decisions made in the first two hours of a ransomware event have disproportionate consequences for recovery time, legal exposure, and insurance coverage.
- Most executive teams have never worked through a ransomware decision sequence together. The first time they do it during a real incident, under pressure, without preparation, is the worst possible context.
- Ransomware scenarios in tabletop exercises are designed to surface the specific decision points that break down under pressure: ransom authority, backup integrity confirmation, and communications timing.
- Organizations whose executive teams have rehearsed ransomware response make faster containment decisions, communicate more consistently, and recover with less business disruption.
A ransomware tabletop exercise for executives exists because ransomware is not, in the moment that matters, a technical problem. It is a sequence of business decisions with legal and financial weight, made by people who have usually never made them before. Ransomware appears in 44 percent of all breaches, and in 88 percent of breaches at small and mid-sized businesses, in Verizon’s 2025 Data Breach Investigations Report, so this is not a rare scenario to rehearse. The exercise puts the leadership team through the real decision sequence, and the output is an independent incident response readout of exactly where the team hesitated.
| By the NumbersRansomware appears in 44% of all breaches and 88% of breaches at small and mid-sized businesses, with a median ransom demand near $115,000. Source: Verizon 2025 Data Breach Investigations Report.Faster containment lowers breach cost. The global average breach cost $4.44M ($10.22M in the US), and rehearsed teams contain faster. Source: IBM Cost of a Data Breach Report 2025.Carriers require documented evidence of IR plan testing, including tabletop exercises, as part of underwriting. Source: 2025 to 2026 carrier underwriting guidance. |
What Decisions Does Ransomware Actually Force on Leadership?
Ransomware is not primarily a technical problem for most organizations. It becomes a technical problem after it has already become a leadership problem. The moment ransomware is confirmed, a cascade of decisions with executive-level consequences begins, and these decisions need to be made by people who have authority, context, and some framework for thinking through the trade-offs.
The operational shutdown decision
Ransomware propagates laterally through connected systems. Stopping propagation requires isolating affected systems, which may mean taking business-critical operations offline. The decision to shut down systems that generate revenue, serve customers, or support essential operations cannot be made by the IT team alone. It requires executive authorization because it is a business decision with immediate financial consequences. The organization that has never discussed this decision in advance typically loses thirty to sixty minutes confirming who has authority to make it while the ransomware continues to spread.
The backup integrity question
Recovery from ransomware depends on having intact backups that were not encrypted before the attack was detected. This is not a given. Sophisticated ransomware operators compromise backup systems before executing the encryption payload, specifically to eliminate the option of recovering without paying. The question of whether backups are intact needs a definitive answer before the recovery strategy is set, and that answer requires coordination between IT, who needs time to verify, and leadership, who needs the information to make the next decision. Without a pre-established process, this coordination is improvised and slow.
The ransom decision
Whether to engage a ransom negotiator, and ultimately whether to pay a ransom demand, is one of the most consequential decisions an organization makes in a ransomware event. It involves legal counsel, because ransom payments may have sanctions implications depending on the threat actor. It involves the cyber insurance carrier, because coverage conditions may affect the decision. It involves the board, because the financial and reputational implications are material. It requires a documented decision authority framework, because the decision needs to happen within a defined window, not after days of internal deliberation.
The communications timing decision
When to tell customers, partners, and regulators about a ransomware event, and what to say, is a decision that intersects legal obligations, reputational judgment, and the state of the investigation. Saying too much too early creates liability if the initial characterization turns out to be wrong. Saying too little for too long creates the appearance of concealment. Most organizations do not have pre-approved communications templates for ransomware, which means the first external statement is drafted under pressure by people who are also managing the operational response, and then reviewed by lawyers who are working from a standing start on a new engagement.

What Does a Ransomware Tabletop Scenario Look Like?
A well-designed ransomware tabletop scenario walks the executive team through the actual decision sequence, using injects that introduce new information and escalate the situation at realistic intervals. It is the live-fire complement to a breach readiness assessment, which diagnoses the same capability on paper before the scenario stress-tests it.
The scenario opens with a detection event: the IT team reports that a small number of endpoints are showing unusual behavior consistent with ransomware early-stage activity. The first decision point is how seriously to treat this, given that it might be a false positive and taking action has operational costs. This opening inject tests whether the team has a threshold for escalating from investigation to formal incident response.
Subsequent injects escalate the situation. The ransomware has executed on multiple systems. Business-critical applications are down. A ransom note has appeared. An employee has posted to social media. The backup verification is taking longer than expected. Each inject introduces a new decision point with real trade-offs: operational disruption versus containment speed, communications transparency versus legal caution, recovery self-reliance versus engaging outside support.
The facilitator captures how the team responds to each decision point: who speaks first, who defers, whether authority is clear, whether the decision is made with appropriate speed, and what rationale is offered. These observations become the material for the after-action report and the improvement roadmap.

What Does a Ransomware Exercise Surface That Nobody Expected?
Experienced tabletop facilitators consistently find the same categories of gaps in ransomware exercises across organizations of different sizes and industries.
The ransom decision authority gap appears in almost every exercise. Organizations have an IR plan that says escalate to the executive team for major decisions, but nobody has documented who specifically makes the ransom decision, what inputs they need, and what the decision process looks like. In the exercise, this gap produces a ten-minute discussion about who should decide instead of a ten-minute discussion about whether to engage a negotiator.
The backup confidence gap surfaces when the exercise asks the team to confirm backup integrity as a prerequisite for choosing a recovery path. Most teams discover that they do not know, with the certainty the decision requires, whether backups are current, isolated, and intact, and whether the forensic evidence needed to understand the attack is being preserved rather than destroyed during recovery. The IT team can check, but the check takes time, and the exercise reveals that the recovery decision timeline was never aligned with the backup verification timeline.
The communications authority gap appears when an inject introduces a media inquiry or a regulatory question and the team needs to respond. The communications lead wants to say something. Legal wants to say nothing until the facts are confirmed. The CEO has not been briefed on the current state. The approval path for an external statement is unclear. The exercise produces a realistic preview of what the first external communications experience will look like if the process is not established in advance.
Armour Cybersecurity’s ransomware cyber simulation exercises are custom-designed around the organization’s actual systems, backup architecture, regulatory environment, and business continuity options. The exercise tests the decisions that matter for the organization, not a generic scenario. The after-action report documents the gaps found and the specific improvements that will close them.

Where Ransomware Exercises Fit in Armour’s Managed Services
A ransomware tabletop rarely works alone. It is one pillar of Armour’s managed cybersecurity services, operating alongside a managed Security Operations Center that detects the ransomware early, cyber threat intelligence that keeps the scenarios true to current ransomware operators, vCISO leadership to own the ransom and shutdown authority the exercise stress-tests, cyber awareness training to reduce the phishing that delivers most ransomware, and the all-in-one Armour 360 managed program. The exercise finds the gaps. The program keeps them closed.
The Bottom Line
The first time your leadership team decides whether to shut down operations or pay a ransom should not be during a live ransomware attack, with the clock running and the encryption spreading. A ransomware tabletop exercise moves that first time into a room where the stakes are learning, not survival, and where the ten minutes lost to an unclear decision cost nothing. If your executives have never made these decisions together, a ransomware tabletop exercise is the difference between a rehearsed response and an improvised one when it counts.
| Across the 260+ organizations Armour runs exercises for in 52+ industries, the ransomware decision that stalls executive teams most is not whether to pay. It is who is even allowed to decide, a gap that costs real minutes while the encryption spreads. |
Frequently Asked Questions
What is a ransomware tabletop exercise for executives?
A ransomware tabletop exercise for executives is a facilitated session that walks the leadership team through a realistic ransomware event and the decisions it forces: whether to shut down operations to stop propagation, whether to engage a ransom negotiator or pay, when to notify customers and regulators, and when to brief the board. A facilitator escalates the scenario through timed injects while participants make the real decisions under time pressure. It targets executive decision-making rather than technical response, and it produces an independent after-action report showing where authority, process, or communications broke down.
Should the board participate in a ransomware tabletop exercise?
A board observer or board member participant in an executive tabletop exercise is valuable, particularly for organizations where board notification is a material part of the incident response protocol. Board members who have participated in a tabletop exercise have a baseline understanding of what a ransomware response involves, which improves the quality of governance oversight during a real event. Many boards request an annual tabletop briefing as part of their cyber risk oversight program. At minimum, the board should receive the after-action report and executive summary from each exercise.
What is the difference between an executive tabletop and an operational tabletop?
An executive tabletop focuses on strategic decision-making: when to shut down operations, whether to pay a ransom, when to notify the board and regulators, and what to communicate externally. Participants are the CEO, CFO, general counsel, communications lead, and CISO. An operational tabletop focuses on technical and procedural response: containment steps, forensic evidence preservation, system recovery sequencing, and inter-team coordination. Participants are IT security, incident response leads, and business unit representatives. Both are valuable and test different failure modes. Many organizations run both formats in the same program.
What should we do with the ransom decision before we run the exercise?
Document the decision authority framework before the exercise so the exercise can test it. Who has authority to engage a ransom negotiator? Who has authority to authorize a payment, subject to carrier and legal approval? What are the inputs that decision-maker needs before deciding? What is the process for getting breach counsel and the cyber insurance carrier engaged before the decision is made? Having these questions answered in writing, even preliminarily, makes the exercise more productive because the team can test the framework rather than inventing it in the room.
How does a ransomware tabletop help with cyber insurance?
Cyber insurance carriers increasingly require documented evidence of IR plan testing, including tabletop exercises, as part of underwriting. The formal independent security assessor report produced after an Armour Cybersecurity tabletop exercise is structured for direct submission to carriers as evidence of exercised response capability. The exercise also helps the organization understand its own coverage conditions more clearly, because working through ransom payment decisions in the exercise typically prompts a review of the policy terms that is overdue in most organizations.
What do we do after the tabletop exercise identifies gaps?
The after-action report prioritizes gaps by the impact they would have on real incident response and provides recommended owners and timelines for remediation. Quick wins, clarifying decision authority, documenting the ransom decision process, establishing breach counsel and carrier engagement procedures, can typically be completed within thirty days. Longer-term improvements, rebuilding the IR plan, developing scenario-specific playbooks, running a follow-up exercise to validate the improvements, are sequenced in the roadmap with realistic timelines. Many organizations engage Armour Cybersecurity for follow-on work to develop the artifacts the exercise identified as missing.
About the Author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate.



