Incident readiness

Ransomware tabletop: what leadership must decide

A tabletop is not useful if it only confirms that a document exists. It is useful when it forces uncomfortable decisions before the real crisis.

Decisions to rehearse

  • Who declares a severe incident.
  • Who decides to shut systems down or isolate segments.
  • Who communicates with customers, providers, insurer and authorities.
  • What evidence is preserved before cleaning.
  • How the company operates if email, ERP or identity are down.
  • When legal, forensics and communications are involved.
Expected result: RACI, playbooks, alternate channels, provider list, backlog and pending decisions.

Back to resources

Kronixial

Need to turn this into evidence for a real decision?

We can define a scoped sprint to review scope, evidence, red flags and a 30/60/90 plan.

Talk to Kronixial