Readiness became the question
Could we handle ransomware? “We have a plan” is not an answer.
A peer company went down for weeks and everyone heard about it.
Response drill / 05
Could we handle ransomware?
Scenario trigger
There is a plan. Nobody has ever run it.
Recommended service
Incident readiness01 scenario_loaded02 decision_owner03 exercise_readyContext behind the pressure
A director, a customer, or your insurer asked the obvious question. There is a plan—approved two years ago, stored in a document library, naming systems since replaced and people who have since left. Nobody has ever run it. The question is whether the response would work with the people, vendors, and cloud services the business actually runs on today.
You are likely here if
The pressure is specific. The answer is not yet.
- 01
The incident response plan predates the current cloud footprint, key vendors, or half the leadership team named in it.
- 02
No one can say—without looking it up—who declares an incident, who calls the insurer, and who is authorized to take systems offline.
- 03
Backups are reported as “in place,” but no one has timed a restore of a system the business cannot operate without.
The decision on the table
Name the decision before choosing the deliverable. It keeps the work tied to the business question that created the pressure.
Decide what standard of ready the business is willing to be held to. Keep the paper plan and accept that its first live test happens during an incident, or practice the response—put leadership through the actual decisions, on the actual org chart, before it counts. Response providers, counsel, and insurer notification obligations either exist and are wired into the plan, or get sorted at the worst possible hour.
Ackatec’s working view
A position before a proposal.
- 01
The first hours are a decision problem, not only a technical problem.
Who declares, who spends, who talks to customers, and who can shut down revenue-generating systems must be known before the pressure arrives.
- 02
A tabletop is the least expensive incident you will have.
The point is to find the broken assumptions—an unreachable vendor, an untested backup, an approval bottleneck—while they cost a finding instead of downtime.
- 03
Readiness decays.
Every migration, vendor change, and reorganization quietly edits the response plan. A plan that is not re-exercised is aging back into a binder.
A representative first artifact
First-24-hours decision map
The single page designed to remove debate from the first hour.
Working structure
- 01
Declaration
What counts as an incident, who declares it, and the threshold that ends the “is this serious?” debate.
- 02
Authority
Who can approve emergency spend, take systems offline, engage the response provider, and speak to customers—with alternates.
- 03
Notifications
Insurer, counsel, response provider, and contractual customer obligations: who calls whom, in what order, with current numbers.
- 04
Continuity
Which systems return first, and what the business does while they are down.
- 05
Scenario walk
The map exercised against ransomware, business email compromise, and a critical vendor outage.
Built in Prepare, tested in Exercise, revised in Strengthen. The map’s job is to remove debate from the first hour.
This is Ackatec’s working structure for the situation—shaped to each organization in the first sessions, not a sample of past client work.
Recommended next step
Get the right help for this moment.
Begin from the situation
