Incident response training

Ransomware training should rehearse the first hour, not just explain the threat.

When a real incident starts, the business may have minutes to make decisions about accounts, devices, payments, communications and recovery. That is the wrong time to discover nobody knows who is in charge.

Ransomware awareness is useful, but an incident-response exercise is more valuable because it asks the organisation to act. Who isolates the laptop? Who contacts the IT provider? Who decides whether Microsoft 365 accounts should be disabled? Who checks backups? Who communicates with staff and customers? Those questions need answers before an incident.

Containment comes before panic

The first objective is to limit further damage without destroying useful evidence. Depending on the incident, that can mean isolating affected devices, securing compromised accounts, blocking malicious access and stopping users from continuing a risky action.

Preserve evidence while you respond

Logs, suspicious emails, screenshots, timestamps and affected device information can help determine what happened. Staff should know not to tidy away the evidence or wipe a machine simply because it looks infected.

Know who has authority to make decisions

A technical team can advise, but business decisions about shutting systems down, communicating externally, invoking insurance or dealing with regulatory obligations often sit with directors and managers. A tabletop exercise should expose any uncertainty in those roles.

Backups are only useful if recovery is understood

Having backup software is not the same as having a recovery plan. Businesses should know which systems are backed up, how quickly they can be restored, whether backup credentials are protected and how restoration will be prioritised.

Communication can reduce secondary damage

Staff need clear instructions during an incident. Customers, suppliers, insurers and other parties may also need appropriate communication. Confused or contradictory messages can create additional risk while the technical response is still underway.

A tabletop exercise turns policy into behaviour

Working through a ransomware scenario shows whether contact details are current, escalation paths are clear and decision-makers understand their responsibilities. The lessons can then feed a practical improvement plan before the next real incident occurs.

Frequently asked questions

What is a cyber incident tabletop exercise?

It is a structured scenario in which participants talk through the decisions and actions they would take during a simulated incident without disrupting live systems.

Should small businesses have an incident response plan?

Yes. Even a short plan covering contacts, escalation, containment, communication, evidence and recovery is better than trying to design the process during an emergency.

Does an incident response course replace technical incident response?

No. Training prepares people to recognise and coordinate an incident; actual containment, investigation and recovery may require specialist technical support.

Practical cyber security training

Take the next step with a 39Security training day.

Work through phishing, payment fraud, Microsoft 365, device security, backups, incident response and a prioritised 90-day action plan.

View and book