Free · complete · nothing held back
When did you last test the plan?
It is the question insurers ask on the application form and auditors ask in the room, and for most small Canadian organisations the honest answer is that they have not. A tabletop exercise is the cheapest way to change that: ninety minutes, a printed deck, and no system touched.
What a tabletop actually is
Eight events are read aloud in sequence. The group decides what it would do. Nobody logs into anything, nothing is switched off, and no technical knowledge is needed by anyone in the room — including whoever is running it.
What it produces is a record of what your organisation would decide, and a list of what it does not yet know. The second list is the point. An exercise that raises no findings was facilitated too gently.
- It is not an assessment, an audit, or a certification of anything. It tells you how people would decide, not whether your backups restore.
- It is a discussion, not a test of individuals. The plan is being tested. Saying “I don't know” is the most useful thing anyone does all morning.
- You do not need us in the room. The materials are written so that one person who is not a specialist can run it, having read them once the day before.
The ransomware exercise, free
One Monday morning that goes wrong in the order these things actually go wrong: a slow file share at 07:14, a ransom note at 07:41, an IT provider whose first free engineer is at 14:00, and backups that stopped nineteen days ago without telling anyone. By the afternoon it has stopped being a technical problem and become a privacy one, with clocks attached.
Ransomware tabletop
The complete pack. Print it, cut it up, run it. No email address, no form, no follow-up.
- The deck — 22 print-and-play cards on six sheets. Ground rules, six role cards, eight timed injects and six complications, for when the room is finding it too easy.
- Facilitator’s guide — the running order, the three ways a tabletop fails, and what the finding behind each inject actually is.
- Decision log — the note-taker’s page, including the register of every question the room could not answer.
- After-action report — findings, owners and dates, written within two days while it is still fresh.
- Evidence of exercise — one page to hand an insurer or an auditor, with an honest statement of what it does and does not evidence.
Free
Download the deckPDF and Word · published in full · nothing held back
Three more scenarios
The same structure applied to the three incidents that reach small organisations after ransomware, and are harder to think about cold.
- Supplier compromise — the breach is not yours, but your clients’ data is in it and your name is on the contract.
- Insider departure — someone leaves for a competitor and the access review has never been run.
- An AI tool leaks a client list — nobody did anything malicious, and the data is now somewhere you cannot reach.
- Each with its own deck, facilitator’s guide and complications. The three Word forms are shared.
CAD $145
Buy the three-scenario pack — $145Secure checkout by Stripe · emailed within one working day
Available in French Canadian on enquiry. If that is what you need, tell us and we will say honestly how long it would take.
Where the line falls
An exercise tests preparedness. It does not fix anything, and it does not certify anything.
A tabletop tells you how your people would decide under pressure and where the plan is thin. It cannot tell you whether your backups actually restore, whether your logging would show you anything useful, or whether your provider would pick up the phone. Those need testing separately, and if the exercise makes you want to test one of them, it has done its job. Where a form asks whether your controls have been tested, an exercise record is not the answer to that question — and we say so on the evidence page itself.
Running this yourself, from these materials, keeps you entirely independent of us. Buying the paid scenarios does not stop us carrying out an independent assessment of your organisation later, because an exercise is not a management system. We say which side of that line a purchase falls on before you buy, not after.
If you already have our runbooks
This is the other half of them. A runbook says what to do; an exercise finds out whether anyone would. The ransomware exercise is built to be run against the first-hour checklist and the incident response runbook, though it works perfectly well with whatever plan you already have — or with none, which is itself a finding.
The operating runbooksThe insurance application companionFree templates and tools