Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Tabletop Exercises Won't Save You From RansomwareRisk Analysis and Quantification
5 min readFor CISOs

Tabletop Exercises Won't Save You From Ransomware

The Conventional Wisdom

You've heard it at every security conference and read it in every vendor white paper: to combat rising ransomware threats, you need better preparation. Run tabletop exercises, document your incident response procedures, and test your backup restoration process. Build muscle memory so when the attack comes, your team executes flawlessly.

NCC Group's latest report shows 1,073 organizations fell victim to ransomware in August 2026 alone, with groups like Qilin (164 incidents) and The Gentlemen (116 incidents) leading the charge. The recommended response? Organizations should "have a defense plan in place" and "engage in tabletop exercises to help prepare for real-world incidents."

This advice isn't wrong. It's incomplete. And that incompleteness is costing you.

Why It's Incomplete

The tabletop-and-playbook approach treats ransomware as an inevitable natural disaster you can only prepare to weather. It's like earthquake preparedness for your network: you can't stop the quake, but you can bolt the servers to the floor and know where the emergency exits are.

Here's the problem: ransomware isn't a natural disaster. It's a business decision made by rational actors who've calculated that your organization offers an acceptable risk-reward ratio. When the industrial sector accounts for 31% of August's incidents and healthcare takes 12%, that's not random. That's target selection based on operational dependencies and payment likelihood.

Your tabletop exercise teaches your team how to execute a playbook after you've already lost. It doesn't address why you became a target in the first place or how to become an unattractive one.

Consider what happens when you focus exclusively on response preparation. You're essentially building a better emergency room while ignoring the conditions that keep sending patients through your doors. Your incident response team gets faster at containment. Your communications team polishes the breach notification template. Your legal counsel knows exactly which regulators to call. And next quarter, you're hit again, because nothing in your preparation made you harder to compromise or less profitable to extort.

The Evidence

The data reveals a targeting pattern that preparation alone can't address. North America represented 44% of August's incidents, Europe 26%, and Asia 13%. These aren't random acts. They're campaigns optimized for maximum return on criminal investment.

Groups like Qilin don't waste resources on hardened targets. They scan for specific vulnerability signatures, test for defensive gaps, and move to the next candidate when they encounter friction. The 164 organizations Qilin hit in August shared something in common, and it wasn't inadequate tabletop training.

Look at the industrial sector's 31% share of incidents. These organizations often run legacy operational technology that can't be easily patched, maintain connections between IT and OT networks that create lateral movement opportunities, and face operational continuity pressures that make them more likely to pay. The vulnerability isn't in their Incident Response Structure; it's in their attack surface and economic profile.

When NCC Group cites "rapid advancements in AI and ongoing geopolitical volatility" as drivers of increased activity, they're describing a threat landscape where attackers are getting better at initial access and target selection faster than defenders are getting better at response execution. Your tabletop exercise doesn't address this capability gap.

What to Do Instead

Shift your investment from response preparation to attack surface reduction and economic deterrence.

Make initial access expensive. The groups hitting over 1,000 organizations monthly aren't using zero-days. They're exploiting unpatched VPNs, credential stuffing against accounts without MFA, and social engineering users who haven't seen a phishing simulation in six months. Implement detection rules that flag reconnaissance activity and lateral movement attempts before encryption starts. Deploy deception technology that makes your network topology ambiguous to attackers who've gained a foothold.

Reduce your economic attractiveness. If you're in the industrial sector, you're already on the target list. Your job is to become the target that's more expensive to compromise than the expected payout justifies. That means air-gapping critical OT systems, implementing network segmentation that forces attackers to burn multiple exploit chains to reach crown jewels, and maintaining offline backups that eliminate the encryption leverage.

Automate the basics. Groups like Clop (89 attributions in August) and Dire Wolf (43) rely on volume. They're not spending weeks on custom tooling for each victim. They're running automated scans and deploying commodity malware. Your defensive automation should match their offensive automation. Patch management, configuration drift detection, and privileged access reviews shouldn't require human decision-making for every instance.

Understand your threat actor's business model. The Gentlemen and Qilin have different operational patterns and different victim profiles. Generic preparation doesn't account for these distinctions. Subscribe to threat intelligence that maps which groups target your sector, what their typical dwell time looks like, and what initial access vectors they prefer. Use that intelligence to prioritize control implementation.

Measure deterrence, not just response time. Your security metrics probably track mean time to detect and mean time to respond. Start tracking mean time to initial access attempt and percentage of reconnaissance activity that abandons your network. If you're seeing the same scanning patterns month after month without adaptation, your defenses aren't creating enough friction.

When the Conventional Wisdom Is Right

Tabletop exercises and incident response planning matter once you've addressed the fundamentals. If you've reduced your attack surface, implemented strong access controls, and segmented your network, then yes, you need to prepare for the sophisticated attacker who gets through anyway.

The playbook becomes critical when you're facing a determined adversary who's willing to invest significant resources in compromising specifically your organization. State-sponsored actors and advanced persistent threats don't abandon targets just because you've implemented MFA.

Response preparation also matters when you operate in sectors with regulatory notification requirements. Your tabletop should cover your Form 8-K obligations if you're a public company, your HIPAA breach notification timeline if you're in healthcare, and your state law requirements regardless of sector.

But here's the distinction: these scenarios represent the tail of the distribution, not the bulk. The 1,073 organizations hit in August weren't all facing nation-state actors. Most were facing volume operators who moved on when they encountered resistance.

Run your tabletops. Document your playbooks. Test your backups. But do it after you've made yourself an unattractive target, not instead of it. The best incident response is the one you never have to execute.

Cybersecurity Framework

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like