Ransomware Tabletop Exercises That Actually Improve Response Times
A tabletop where everyone agrees the plan would work has taught nothing. Designing exercises that surface real failures, with the clinical staff who would actually be involved.
GuardsArm Team
Security Experts
A tabletop that finishes on schedule with everyone agreeing the plan would work has produced a compliance artefact and no learning. A good exercise is uncomfortable: it surfaces the decision nobody is authorised to make, the dependency nobody documented, and the contact list that is two years stale.
Who has to be there
The common failure is running it with IT and security only. The decisions in a real hospital ransomware incident are overwhelmingly clinical and executive.
| Role | Why they must attend |
|---|---|
| Chief medical / nursing officer | Diversion, cancellation and patient safety decisions |
| Executive on call | Declaration, external communication, ransom position |
| Clinical service leads | What their service does without systems |
| IT and security | Technical response |
| Communications | Staff, patients, media |
| Legal and privacy | Notification obligations |
| Finance | Insurance, emergency procurement |
| Facilities | Physical dependencies — doors, HVAC, nurse call |
Facilities is the one most often omitted and most often surprising. Building systems are networked, and a scenario that takes out access control has immediate clinical consequences.
Scenario design that produces learning
Make it specific to your estate and uncomfortable:
- Name real systems. "The EHR is encrypted" lands differently from "a clinical system is unavailable."
- Time it badly. Friday evening of a holiday weekend, key staff away.
- Remove the easy answers. The backups are also encrypted. The incident lead is unreachable. Email is compromised.
- Run past the first hour. Most exercises stop at containment. The interesting decisions — diversion, cancellation, backfill, notification — are at hour twelve and day three.
Facilitation
- An independent facilitator — someone whose job is not to defend the plan
- A scribe capturing decisions, assumptions and gaps verbatim
- No laptops except for the scribe; the point is the discussion
- Two to three hours, not a full day, which is how attendance is achieved
- A rule that "we would check the plan" is not an answer — check it, live, and time how long it takes to find
The output
The deliverable is a tracked list, not a report:
| Finding | Owner | Due |
|---|---|---|
| Nobody could state who declares a downtime | CMO | 30 days |
| Downtime viewer shares infrastructure with the EHR | IT | 90 days |
| No out-of-band communications channel exists | Security | 30 days |
| Backfill process undefined | Health records | 60 days |
| Insurer notification requirement unknown | Finance | 14 days |
Then re-exercise in six to twelve months and check the previous findings are closed. An organisation that runs one tabletop learns something; one that runs them on a cycle and tracks the findings gets measurably faster.
For the plans an exercise tests, see the 72-hour continuity plan and incident communications.
GuardsArm facilitates healthcare ransomware tabletops with clinical and executive participation. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


