Call or Text - 
Orlando & Central Florida:
407-554-5534
Naples & Southwest Florida:
239-653-0252
Schedule a Free Consultation

Could Your Business Handle a Ransomware Morning? Run This Tabletop Exercise Before an Attack

10/07/2026
2149445127(1)

A Plan on Paper Is Not the Same as a Practiced Plan

Imagine arriving at work and discovering that employees cannot open shared files. A message on one computer demands payment. Your scheduling system is unavailable, email access is uncertain, and customers are already calling.

Who makes the first decision?

Who contacts IT? Should employees turn off their computers? Can the business keep operating? Are the backups usable? Who speaks with customers, vendors, the insurance company, or law enforcement?

Those questions are easier to answer around a conference table than during an actual emergency.

For Cybersecurity Awareness Month, Nacha’s Payments Innovation Alliance released an updated ransomware tabletop exercise kit for small and midsized businesses. The kit uses an evolving scenario, participant materials, and leadership questions to help companies discuss how they would respond. The complete exercise is designed to take approximately two to three hours, but even a shorter internal discussion can reveal important gaps. (Nacha)

What Is a Ransomware Tabletop Exercise?

A tabletop exercise is a guided conversation about a simulated incident. Nobody attacks your systems, shuts down the network, or sends a real ransom demand.

Instead, a facilitator describes a realistic situation and asks the people responsible for the business to explain what they would do next.

The purpose is not to test technical knowledge. It is to find unanswered business questions while there is still time to fix them.

A useful exercise might include the owner, office manager, IT provider, operations lead, finance representative, and anyone responsible for customer communication. Businesses with legal, regulatory, or insurance requirements should also identify the qualified professionals they would contact during a real incident.

Questions the Exercise Should Answer

Start with a simple scenario: an employee reports that shared files will not open, and a suspicious message appears on a workstation.

Work through questions such as:

  • Who should the employee contact first?
  • Who has authority to disconnect systems or pause operations?
  • How will the business communicate if normal email is unavailable?
  • Which systems must be restored first?
  • When were the backups last tested?
  • Can backups be reached using the same compromised accounts?
  • How will staff continue serving customers?
  • Where are insurance, legal, banking, vendor, and law-enforcement contacts stored?
  • Who will document decisions and preserve important information?
  • Who is authorized to communicate with employees and customers?

The goal is not to produce perfect answers during the meeting. The goal is to discover which answers are missing.

Pay Attention to Operational Dependencies

A ransomware exercise often reveals that the business depends on more systems than expected.

A company may have backups but no tested method for restoring its scheduling software. The emergency contact list may be stored in the email system that just became unavailable. Employees may know the IT provider’s name but not the correct phone number. A cloud application may work, but nobody may know whether compromised accounts should continue using it.

List the systems the business needs to perform essential work, including:

  • Email and Microsoft 365
  • Accounting and payroll
  • Customer records
  • Shared files
  • Scheduling or practice-management software
  • Payment and point-of-sale systems
  • Business phones
  • Vendor portals
  • Websites and online ordering
  • Backups and recovery tools

This list helps establish a sensible recovery order instead of letting the loudest problem control the response.

Test the Human Side of the Plan

Technology is only part of ransomware response. People must know what they are authorized to do.

Employees should understand how to report a suspected incident without feeling blamed. Managers should know who can make operational decisions. The IT provider should have current contact information for authorized leaders. Important contacts should be available somewhere other than the affected computers.

The exercise should also confirm that nobody will negotiate, pay, delete evidence, or make public statements without appropriate professional guidance. Legal, insurance, regulatory, and notification obligations vary, so those decisions require qualified advice.

Turn the Discussion Into Action

At the end of the exercise, write down the most important gaps and assign an owner and deadline to each one.

Common follow-up work may include:

  • Testing a backup restoration
  • Creating an offline emergency contact list
  • Updating the incident-response plan
  • Identifying critical systems and recovery priorities
  • Separating backup access from everyday employee accounts
  • Confirming cyber-insurance contact procedures
  • Giving employees a clear way to report suspicious activity
  • Scheduling another exercise after improvements are completed

The Federal Trade Commission recommends that small businesses maintain and regularly test incident-response, disaster-recovery, and business-continuity plans. CISA also provides tabletop resources that organizations can use to discuss ransomware and other threat scenarios. (FTC, CISA)

Preparation Makes a Difficult Day More Manageable

A tabletop exercise cannot prevent every attack, but it can reduce hesitation, confusion, and avoidable downtime. It gives business leaders a clearer understanding of what they depend on and what still needs attention.

Cybernetic Networks helps Orlando and Central Florida businesses review ransomware readiness, test backups, document response procedures, and protect the systems employees rely on every day. A calm planning session now can make the difference between an organized response and a prolonged business interruption later.

Source Links

Quotes from our Customers

Posted on Google Google
Lori Hall Patel profile picture
Lori Hall Patel
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Fantastic service!
Posted on Google Google
Yaritza Quintero Luis profile picture
Yaritza Quintero Luis
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks Inc. provides excellent tech support for the office. Himala is always responsive, knowledgeable, and quick to resolve any issues I run into. I truly appreciate his reliability and professionalism—highly recommended!
Posted on Google Google
Carlos Villoch profile picture
Carlos Villoch
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
From the very first call to Cybernetic, the team was responsive, knowledgeable, and genuinely committed to solving my issues. Their proactive approach and genuine care are what really stood out above any other IT Support Businesses. If you’re looking for IT support that’s dependable, friendly, and truly invested in keeping your technology running smoothly, this is the team you want. I can’t recommend them highly enough.
Posted on Google Google
KIMBERLY profile picture
KIMBERLY
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I would highly recommend Cybernetic Networks Inc. to anyone looking for reliable and trustworthy tech support.
Posted on Google Google
Tom moore profile picture
Tom moore
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day.
Posted on Google Google
Daniel Fusco profile picture
Daniel Fusco
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety.
Posted on Google Google
Beth Wolff profile picture
Beth Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.
Posted on Google Google
Brian Wolff profile picture
Brian Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!
Posted on Google Google
Patti Muzzonigro profile picture
Patti Muzzonigro
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.
Posted on Google Google
sue myhelic profile picture
sue myhelic
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.