Ready to Run Exercise Package

Ransomware Attack
Tabletop Exercise

Detection. Containment. The ransom decision. Recovery. The scenarios your IT, leadership, and operations teams need to work through before ransomware forces them to.

Ransomware Detection Containment The Ransom Decision Business Continuity Recovery Planning

Instant download. Everything included. No facilitator experience required.

Built by a U.S. Army combat veteran and paramedic and EMS supervisor with 20+ years in emergency healthcare who understands what incident response looks like under real operational pressure.  ·  SDVOSB Pending  ·  SAM.gov Registered  ·  CAGE: 1AFL4

The Problem

Ransomware gives you hours to make decisions
that take most teams days to figure out.

According to the FBI’s 2025 Internet Crime Report, ransomware hit 14 of 16 critical infrastructure sectors last year. Healthcare was the most targeted. The organizations that recover fastest are the ones that practiced what to do before it happened.

The Detection Gap
Most organizations don’t know they’ve been hit until systems are already locked. This exercise forces your team to practice recognizing the early indicators before the ransom note appears.
The Ransom Decision
Pay or don’t pay. Most leadership teams have never discussed this before it’s a live question with a countdown clock. This exercise makes it a conference room conversation, not a crisis decision.
Business Continuity
What do you do while systems are down? Most organizations find out they don’t have a good answer to that question during the incident. This exercise surfaces that before it matters.
Who Does What
IT, legal, leadership, communications, and operations all have a role during a ransomware incident. Most organizations have never mapped that out. This exercise does it for them.
What You Get

Everything needed to run the exercise
and document what you find.

One download. Ready to run.

📋
Facilitator Guide
Step-by-step instructions for every inject, timing guidance, discussion prompts, and facilitator notes covering detection through recovery. Includes a pre-exercise checklist and hot wash structure.
📓
Participant Workbook
Scenario materials and worksheets for every participant. Includes a ransomware response quick reference, ransom decision framework, containment checklist, and communication log template.
📊
After Action Report Template
Structured template to capture findings right after the hot wash, including objective performance ratings, documented gaps, and corrective action fields.
🎯
Improvement Plan
Corrective actions with owners, due dates, and 30/60/90-day review checkpoints. Designed to go directly to leadership as a deliverable, not sit in a folder.
📄
Executive Summary Template
One-page leadership brief covering overall readiness, top strengths, priority gaps, and recommended next steps. Everything a decision-maker needs without reading the full report.
🗂️
Scenario Inject Pack
Realistic situation reports and inject cards covering initial alerts, encryption spread, ransom demand, stakeholder pressure, business continuity decisions, and recovery actions.
How the Exercise Works

3 phases. 10 injects. 2 to 4 hours.

A realistic ransomware attack unfolds from first alert through recovery decision. Each inject creates a new decision your team has to work through under pressure.

Phase Inject / Scenario What It Tests Time
1Initial AlertFirst detection, early indicator recognition15 min
2Ransomware ConfirmedIncident declaration, initial escalation15 min
3Containment DecisionWhat to isolate, shutdown procedures, scope20 min
4Spread and ScopeLateral movement assessment, backup status20 min
5The Ransom DemandPay or not pay decision, legal and insurance20 min
6Business ContinuityManual operations, workarounds, patient safety20 min
7CommunicationInternal staff, customers, regulators, media15 min
8Law Enforcement and ReportingFBI, CISA, cyber insurance, breach notification15 min
9Recovery PlanningRestoration priority, timeline, vendor engagement15 min
10Hot Wash and ImprovementLessons learned, owned action items, next steps30–45 min
Who This Is For

Any organization that depends on its systems to operate.

Hospitals
Healthcare was the most targeted critical infrastructure sector for ransomware in 2025. This exercise prepares your team for the decision chain the FBI says organizations are unprepared for.
SaaS and Tech Companies
Customer data, uptime commitments, and SOC 2 requirements make ransomware response a board-level issue. This exercise surfaces the gaps before an auditor or attacker does.
MSPs
Managed service providers are high-value ransomware targets because a single compromise can reach their entire client base. This exercise helps MSPs and their clients practice together.
Municipal Government
City governments face ransomware with limited IT resources and high public impact. This exercise addresses the specific continuity and communication challenges they face.
Financial Services
Banks, credit unions, and financial firms with regulatory reporting obligations need a practiced incident response. This exercise builds it.
Manufacturing
Operational technology and supply chain dependencies make ransomware uniquely disruptive for manufacturers. This exercise addresses OT-adjacent continuity decisions.
Get the Package

Practice the decisions ransomware
forces you to make in hours.

Six documents, 10 injects, 2 to 4 hours. Everything your team needs to walk through a realistic ransomware attack, find the gaps, and leave with a real improvement plan.

Get the Ransomware Package – $499

Instant download  ·  Customize with your organization’s name  ·  No facilitator experience required

Questions? michael@forwardsecuritylabs.com

Forward Security Labs  ·  ForwardSecurityLabs.com  ·  Built by a combat veteran and paramedic with 20+ years in emergency healthcare. Protect. Prepare. Move Forward.