Six injects, and the question each one is really asking
An abbreviated ransomware scenario. Each inject is released to the room in turn, and the discussion it forces is the deliverable, not whether anyone gets the answer right.
Built from what actually threatens you
The scenario is written against your sector, your architecture and your regulator, using current adversary behaviour rather than a generic template. Nobody rehearses well for an attack they do not believe in.
Six findings we raise in almost every first exercise
None of these are technology problems, which is exactly why no tool would have surfaced them.
Nobody could name who declares an incident
Authority is assumed rather than assigned, so the first hour is spent finding a decision-maker.
The plan referenced people who had left
Contact lists age faster than plans do, and nobody owns keeping them current.
No agreed position on paying a ransom
A decision made under duress at midnight is not a decision, it is a reaction.
Legal and communications were not in the room
They get involved late, and then everything already said has to be walked back.
Restore had never been tested at scale
Backups existed. The recovery time nobody had measured turned out to be days.
The technical team never escalated upward
They believed they could contain it, and leadership learned about it from outside.
Readiness work that surrounds it
Incident response retainer
Retainer clients get two exercises a year, and the responder in the room is the one who would take the call.
Red teaming
A tabletop tests the decisions. A red team tests whether anyone would notice in the first place.
Root cause analysis
After a real incident, the same discipline applied to why it was possible.
