P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Resilience

Incident Readiness and Ransomware Resilience

Tabletop exercises, response plan hardening, and ransomware-specific resilience work that turn your incident response from a document into a capability.

Most incident response plans have never been exercised against a realistic scenario. Detection and containment have improved across the industry; recovery assumptions have not. The first live test of your decision chain, communications, and restore capability should not be an actual ransomware event.

What gets tested

Decision chain

Who decides, who is informed, and how fast that happens at 3am

Recovery capability

Restore throughput at scale, with identity assumed compromised

Communications

Customers, regulators, insurers, and staff, under real time pressure

NIST CSF and NCSC guidance

Response and recovery functions assessed against recognised practice

How the engagement runs

  1. 1

    Plan and capability review

    The existing response plan read the way an attacker would: where the assumptions are, who is named, and what has never been tested.

  2. 2

    Scenario design

    A ransomware scenario built on current tradecraft and your actual architecture, not a generic template with your name inserted.

  3. 3

    Facilitated tabletop

    A two-hour exercise with staged injects, run with the people who would genuinely be in the room, including executives.

  4. 4

    Recovery assumption testing

    The numbers behind the plan interrogated: restore throughput at scale, dependency order, and what happens when the identity platform is in scope.

  5. 5

    Improvement plan and re-test

    A structured debrief turned into owners and dates, with an optional re-test to confirm the gaps actually closed.

What you walk away with

  • Response plan gap assessment
  • Bespoke ransomware scenario with staged injects
  • Facilitated exercise and structured debrief
  • Recovery time findings with the assumptions stated
  • Improvement plan with owners and dates
  • Board-ready summary of residual exposure

How this plays out

Example scenario

A firm had told its board it could recover in seventy-two hours, a figure derived from a single-system restore test on a quiet afternoon.

The work: Tabletop with the identity platform assumed encrypted, then interrogation of restore throughput and dependency order at real scale.

The realistic figure was closer to three weeks. The board was given the true number and funded the fix.

Example scenario

An executive team had never rehearsed the ransom decision, the regulator notification, or who speaks to customers.

The work: Injects designed to force those exact decisions under time pressure, with legal and communications in the room.

Decision rights and notification thresholds were agreed and documented before any incident, not during one.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Test your readiness

Share this

Send it to whoever owns the budget or the risk.

← All services

The problem

Most incident response plans have never been exercised against a realistic scenario. The first live test of your decision chain, communications, and recovery assumptions should not be an actual ransomware event.

What you get

  • A facilitated tabletop exercise built on current ransomware tradecraft
  • A gap assessment of your response plan, roles, and escalation paths
  • Ransomware-specific resilience review: backups, identity, segmentation, recovery time
  • An improvement plan with owners and dates, plus a re-test option

Proof point

Exercises are designed and facilitated personally, drawing on sector-tested incident advisory experience under CCISO-level leadership.