performing-ransomware-tabletop-exercise

Plans and facilitates ransomware tabletop exercises with scenarios, injects, and after-action reports.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill performing-ransomware-tabletop-exercise
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: performing-ransomware-tabletop-exercise
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/ransomware-defense/performing-ransomware-tabletop-exercise
Command: npx skills add https://github.com/xalgord/xalgorix --skill performing-ransomware-tabletop-exercise

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations often have incident response plans that have never been tested under realistic pressure, leaving gaps in decision-making, communication, and recovery procedures undiscovered until a real ransomware attack occurs.

Core Features & Use Cases

  • Scenario Design: Builds multi-phase ransomware scenarios based on current threat actor TTPs (LockBit, ALPHV/BlackCat, Cl0p) with timed injects covering double extortion, backup destruction, and regulatory notification.
  • Facilitation Guidance: Provides probing questions per phase and per role to ensure executives, legal, PR, and IT all participate in decision-making.
  • Evaluation & AAR: Scores responses against NIST CSF and CISA guidelines and produces a structured after-action report with gaps, owners, and remediation deadlines.
  • Use Case: A healthcare system runs its annual ransomware readiness drill simulating a Cl0p double-extortion attack on its EMR, discovering it lacks a documented ransom payment decision framework and OFAC compliance process.

Quick Start

Design a ransomware tabletop exercise scenario for my organization including injects, decision points, and an after-action report template.

Frequently Asked Questions about performing-ransomware-tabletop-exercise

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a ransomware tabletop exercise?

Design a multi-phase scenario based on current threat actor TTPs, prepare SITREPs and inject cards, then facilitate 2-4 hours of guided discussion with executives, IT, legal, and PR. Score responses against NIST CSF criteria and produce an after-action report within 5 business days.

What should a ransomware tabletop exercise scenario include?

Include phases for detection, escalation, decision points, and recovery, with injects covering double extortion, backup destruction, OFAC payment-legality checks, and regulatory notification timelines such as GDPR's 72-hour rule.

Who should participate in a ransomware tabletop exercise?

Participants should include executive leadership, IT and security, legal counsel, communications/PR, HR, operations, and external counsel. A facilitator independent from the incident response team should lead to ensure objective evaluation.

Does a tabletop exercise test technical security controls?

No. Tabletop exercises validate procedures, decision-making, and communication plans, not technical detection or prevention capabilities. Technical controls require separate testing such as penetration tests or backup restore validation.

Why do ransomware tabletop exercises fail to improve readiness?

The most common failure is producing an after-action report with no follow-up, so identified gaps are never remediated. Other pitfalls include unrealistic scenarios, IT dominating discussion, and never testing out-of-band communication channels.