Back to Blog
Incident Response
8 min read

Ransomware Tabletop Exercises That Actually Improve Response Times

A tabletop where everyone agrees the plan would work has taught nothing. Designing exercises that surface real failures, with the clinical staff who would actually be involved.

GuardsArm Team

Security Experts

November 24, 2025

Tabletop exercise

A tabletop that finishes on schedule with everyone agreeing the plan would work has produced a compliance artefact and no learning. A good exercise is uncomfortable: it surfaces the decision nobody is authorised to make, the dependency nobody documented, and the contact list that is two years stale.

Find failures
An exercise that surfaces nothing was designed to surface nothing
Clinical presence
Without clinical leadership in the room it is an IT rehearsal
Output is a list
The deliverable is tracked remediation, not a report

Who has to be there

The common failure is running it with IT and security only. The decisions in a real hospital ransomware incident are overwhelmingly clinical and executive.

RoleWhy they must attend
Chief medical / nursing officerDiversion, cancellation and patient safety decisions
Executive on callDeclaration, external communication, ransom position
Clinical service leadsWhat their service does without systems
IT and securityTechnical response
CommunicationsStaff, patients, media
Legal and privacyNotification obligations
FinanceInsurance, emergency procurement
FacilitiesPhysical dependencies — doors, HVAC, nurse call

Facilities is the one most often omitted and most often surprising. Building systems are networked, and a scenario that takes out access control has immediate clinical consequences.


Scenario design that produces learning

Make it specific to your estate and uncomfortable:

  • Name real systems. "The EHR is encrypted" lands differently from "a clinical system is unavailable."
  • Time it badly. Friday evening of a holiday weekend, key staff away.
  • Remove the easy answers. The backups are also encrypted. The incident lead is unreachable. Email is compromised.
  • Run past the first hour. Most exercises stop at containment. The interesting decisions — diversion, cancellation, backfill, notification — are at hour twelve and day three.
A ransomware tabletop that runs past containmentA ransomware tabletop that runs past containment1Inject 1: detectionHour 0Clinicians report the EHR is unresponsive. What happens in the next ten minutes?2Inject 2: scopeHour 2It is ransomware and it has reached the imaging archive. Who decides on diversion?3Inject 3: backupsHour 6The backup catalogue is encrypted too. What is the recovery position now?4Inject 4: pressureHour 12A journalist calls. A ransom note names a leak-site deadline.5Inject 5: the long tailDay 3Systems return. Three days of paper records exist. Who enters them?
Inject 5 is where most organisations discover they have no plan at all.
Do not let people solve it with a product
When someone answers "our EDR would have stopped that", accept it and move the scenario forward: it did not. The exercise tests decisions and process, not tooling. Litigating whether the scenario is realistic is the most common way a tabletop avoids learning anything.

Facilitation

  • An independent facilitator — someone whose job is not to defend the plan
  • A scribe capturing decisions, assumptions and gaps verbatim
  • No laptops except for the scribe; the point is the discussion
  • Two to three hours, not a full day, which is how attendance is achieved
  • A rule that "we would check the plan" is not an answer — check it, live, and time how long it takes to find

The output

The deliverable is a tracked list, not a report:

FindingOwnerDue
Nobody could state who declares a downtimeCMO30 days
Downtime viewer shares infrastructure with the EHRIT90 days
No out-of-band communications channel existsSecurity30 days
Backfill process undefinedHealth records60 days
Insurer notification requirement unknownFinance14 days

Then re-exercise in six to twelve months and check the previous findings are closed. An organisation that runs one tabletop learns something; one that runs them on a cycle and tracks the findings gets measurably faster.

For the plans an exercise tests, see the 72-hour continuity plan and incident communications.

GuardsArm facilitates healthcare ransomware tabletops with clinical and executive participation. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.