Cybersecurity / Ransomware Tabletop

Ransomware Tabletop Exercise for Boards and Executive Teams

Ransomware is a business decision problem long before it is a technical one. Who authorises shutting down production? Do we pay? What do we tell customers, and when? We put your leadership team through those decisions in a facilitated workshop, and document what the organisation learns.

Designed for boards, C-suite and senior management Real decisions under realistic time pressure Documented readiness report for the board pack
Overview

The decisions leadership will have to make, rehearsed in advance

What it is

A ransomware tabletop exercise is a facilitated workshop in which your executive team works through a ransomware scenario as it unfolds. There are no computers and no technical tooling. There is a scenario, a facilitator, a timed sequence of developments, and a room of people who have to decide what the organisation does next.

The scenario is built around your business. If you are a manufacturer, production stops. If you are a hospital group, appointment systems and patient records are inaccessible. If you are a financial services firm, you are weighing a regulatory notification against a customer-facing outage. The injects escalate: the backup restore is slower than expected, a journalist has been contacted, the attackers publish a sample of stolen data, and a major client demands a written assurance by end of day.

Exercises run for half a day or a full day depending on depth and the number of functions involved. Typical participants are the CEO or managing director, CFO, COO, head of IT, legal counsel, head of HR, communications lead and, increasingly, a board member or audit committee chair.

Why organisations need it

Ransomware has changed shape. Modern operations steal data before encrypting it, so an organisation with perfect backups still faces an extortion demand over publication. That reframes the problem entirely: restoring systems solves the outage but not the disclosure, and the disclosure is what creates the regulatory exposure and the customer damage.

Under the amended PDPA, an incident where personal data has been exfiltrated engages the notification duty to the Commissioner, and to affected individuals where significant harm is likely. That means a decision about whether to notify has to be made under time pressure, in parallel with restoring operations, while an extortion clock is running. Making that decision for the first time during a live event goes badly.

The payment question deserves particular attention. Whether to pay is not a technical judgement. It involves legal exposure, insurance policy conditions, sanctions considerations where the attacker's affiliation is unknown, the reliability of any decryption promise, and the reputational consequences of the decision becoming public. Boards that have never discussed it will discuss it for the first time at their worst moment, unless they rehearse.

Key features

What the workshop covers

The exercise is structured around six themes, each surfacing a decision that is genuinely difficult and genuinely the leadership team's to make.

Executive decision workshop

The core of the session. Leadership works the scenario with incomplete information and a moving clock, which is how these events actually feel. The facilitator presses on who has authority for each decision and whether that authority is documented anywhere.

Business continuity scenarios

What the organisation does while systems are unavailable: manual workarounds, which functions can operate on paper, how long the business can run in degraded mode, and at what point revenue, safety or contractual commitments are materially affected.

Decision-making under pressure

The specific hard calls: shut down production or contain in place, engage the attackers or refuse contact, pay or do not pay, notify early or wait for certainty. We do not tell you the right answer. We make sure the organisation has an answer and knows who owns it.

Crisis communication

Drafting and testing what you would actually say to staff, customers, suppliers, regulators, the board and the press, with the timing of each. Participants usually discover the internal message is the hardest and the most urgent, because staff will talk to customers regardless of whether you have briefed them.

Recovery planning

The realistic sequence and timeline for restoring operations: which systems come back first, what the dependencies are, how you verify the environment is clean before reconnecting, and who signs off that it is safe to resume.

Regulatory and contractual obligations

The obligations that engage during the incident: personal data breach notification under the PDPA, sector-specific regulatory reporting, contractual notification duties to enterprise clients, and cyber insurance policy conditions that can be voided by acting without the insurer.

Benefits

What the business gets out of it

The exercise produces decisions, owners and documents. It is one of the few security activities where the board itself is the primary beneficiary.

The payment question gets answered in advance

Deciding a position on ransom payment while calm, with legal and insurance input, is a fundamentally different exercise from deciding it at midnight with an extortion deadline. Most boards leave the workshop with a documented position and the conditions attached to it.

Decision authority becomes explicit

Exercises consistently reveal that nobody is certain who can authorise halting production, engaging an incident response firm at short notice, or approving emergency spend. Those authorities get defined and delegated during the session.

Continuity assumptions get stress-tested

Business continuity plans routinely assume systems return within twenty-four hours. A realistic ransomware timeline is days to weeks. Confronting that gap tends to change both the plan and the backup investment.

Communications are drafted before they are needed

Holding statements, customer notifications and internal briefings drafted calmly are better than anything written in a crisis, and having them ready removes hours from the response.

Board-level evidence of oversight

Directors carry governance responsibility for cyber risk. A documented exercise, with attendance, findings and closed actions, is concrete evidence that oversight was exercised rather than assumed.

Security investment conversations get easier

Nothing shifts a budget discussion like an executive team spending three hours discovering what a fourteen-day outage would do to the business. The follow-on conversation about backup and segmentation spend tends to be short.

Process

How Orbix runs a ransomware tabletop exercise

Three to four weeks from first conversation to the readiness report, with a half or full day required from the leadership team.

01

Business and impact discovery

We start with what would actually hurt: your revenue-generating systems, your operational dependencies, your regulatory obligations and your key contractual commitments. A scenario that halts a system nobody depends on wastes everybody's morning.

02

Scenario and inject design

We construct the scenario and its inject timeline around your business, then review the design with your sponsor. Injects are sequenced so that pressure compounds, because the interesting failures occur when three decisions are due at once.

03

Pre-read and framing

Participants receive a short pre-read covering the format and the ground rules, most importantly that the session is not an assessment of individuals. Executive exercises fail when senior people feel examined, so the framing matters more here than in a technical exercise.

04

Facilitated exercise

The session runs with a facilitator managing the injects and a second observer recording decisions, timings and points of disagreement. We deliberately let the room reach a deadlock rather than rescuing it, because the deadlock is the finding.

05

Structured debrief

Immediately after, we walk back through the decision points: what was decided, what the basis was, what information was missing and what would have made it easier. Participants identify most of the substantive findings themselves in this session.

06

Readiness report and follow-through

You receive the readiness report with prioritised actions and draft artefacts. We recommend pairing the executive exercise with an operational incident response exercise so the technical and leadership layers are both tested, and repeating annually.

Deliverables

What you receive

Deliverables are written for a board audience and are designed to go straight into the board pack and the risk register.

Ransomware readiness report

The organisation's readiness position across decision-making, continuity, communication, recovery and regulatory response, with the evidence from the exercise behind each judgement.

Decision log and analysis

Every decision point from the exercise recorded with what was decided, how long it took, who made it and what information was missing at the time.

Executive decision framework

A one-page framework covering the ransom position, escalation thresholds, delegated authorities and the conditions attached to each, ready for board adoption.

Crisis communication pack

Draft holding statements, internal staff briefings, customer notifications and a media response framework, with the sequencing and approval route for each.

Business continuity gap analysis

Where the current continuity plan assumes a recovery timeline the organisation cannot meet, with the specific dependencies that need addressing.

Board and audit committee summary

A short summary suitable for tabling, covering readiness, material gaps, agreed actions and the date of the next exercise.

Suitable for

Who a ransomware tabletop exercise is built for

This is a leadership exercise. It suits organisations where an extended outage would cause material financial, operational or reputational damage.

Industries

Sectors where downtime directly halts revenue or delivery of an essential service get the clearest value, as do organisations holding large volumes of personal data.

Manufacturing and industrial Healthcare and hospital groups Financial services Logistics and supply chain Retail and e-commerce Property and construction Education institutions Government-linked companies Professional services Utilities and energy

Company sizes

The exercise scales by participant seniority rather than headcount, so it works for a founder-led company as readily as for a listed group.

100 to 500 employees 500 to 2,000 employees 2,000+ employees Listed companies and GLCs Family-owned groups with a board

Departments

The room should contain everyone who would make or approve a decision during a real event, and nobody who would not.

Board and audit committee CEO and managing director Chief financial officer Chief operating officer IT and information security leadership Legal and compliance Human resources Corporate communications
Why choose Orbix

Why organisations choose Orbix for ransomware tabletop exercises

Facilitating an exercise for a board requires knowing when to press and when to let the room work, and knowing which questions a regulator would ask afterwards.

A governance approach, not a tool sale

We facilitate from a governance perspective rather than a technical one. The questions we press are the ones a regulator, an auditor or a plaintiff's lawyer would ask afterwards: who decided, on what basis, when, and where is that recorded. That framing is what makes the output useful in a board pack.

Recommendations you can actually implement

Every finding becomes a document you can adopt: a delegated authority, a draft holding statement, a decision framework. We would rather leave you with six artefacts your company secretary can circulate than a report describing what a good response would look like.

Consultants who have sat on your side of the table

Our consultants have run compliance, data protection and security functions inside Malaysian organisations, not only advised on them from outside. That shows up in the advice: we know what a lean IT team can absorb in a quarter, and we know which recommendations get quietly shelved.

Built for the Malaysian operating context

Scenarios use Malaysian references your staff will recognise, from DuitNow payment requests and e-invoice notices to LHDN and EPF correspondence. Reporting is framed against the obligations your regulators and auditors actually cite, including the 72-hour personal data breach notification duty introduced by the 2024 amendments to the PDPA.

HRD Corp expertise where it applies

Executive and board cybersecurity briefings can be delivered as HRD Corp claimable programmes for levy-contributing employers, including our cybersecurity for executives and board course, subject to grant approval before delivery.

FAQ

Ransomware tabletop questions we get asked

Audience and subject matter. An incident response exercise tests the operational team working the incident: escalation, triage, containment and evidence handling. A ransomware tabletop tests the leadership team making business decisions: continuity, payment, communication, regulatory notification and recovery sequencing. Organisations with mature programmes run both, often three to six months apart.

You do not have to, but almost every board that runs the exercise chooses to establish a position, because the alternative is deciding under duress. A useful position is usually conditional rather than absolute: a default not to pay, with defined circumstances under which it would be revisited, and a stated requirement to involve legal counsel and the cyber insurer before any contact with attackers. We facilitate that discussion; we do not make the decision for you.

At least one, and ideally the audit committee chair. Directors carry oversight responsibility for cyber risk, and a director who has sat through the exercise asks materially better questions of management afterwards. Where the full board cannot attend, we run a shortened session for the board separately.

A half day covers a single scenario with a focused leadership group and works well as a first exercise. A full day allows a deeper scenario, a second escalation branch and more time on communications and recovery. Most clients start with a half day and move to a full day the following year.

That is common before the session and rare afterwards. Scepticism usually reflects an expectation of a training lecture. The exercise is not a lecture: within twenty minutes the room is arguing about whether to halt production, and the value becomes self-evident. We keep the pre-read short deliberately, so people arrive without a prepared position.

Yes, and group structures produce some of the most valuable findings, because the scenario surfaces questions about which entity decides, how a shared services function is prioritised between subsidiaries, and whether a subsidiary can commit the group to a public statement. Those questions rarely have documented answers.

The facilitated exercise is a consulting engagement. Executive and board cybersecurity briefings delivered alongside it can be structured as HRD Corp claimable programmes under SBL-Khas for levy-contributing employers, subject to grant approval before delivery. See HRD Corp claimable cybersecurity training.
Get started

Put the decisions on the table before the attackers do

Tell us your headcount, your industry and what triggered the interest, whether that is an audit finding, a near miss, a board question or a regulator letter. We will come back with scope, timeline and a fixed quotation. No obligation, and we will say so if you do not need us yet.