Most ransomware tabletops fail before anyone reads the first inject. The reason is simple. The person running the room has never sat in the chair they are testing. If you are hiring a ransomware tabletop exercise facilitator, hire the one who has led the real thing, not the one who has only read about it. The exercise is only as good as the person asking the questions, and the best questions come from someone who has lived the answer.

I have facilitated more than 150 executive tabletops across banks, hospitals, manufacturers, utilities, schools, and government. Same script every time. The plan looks solid on paper. Then the first inject lands, and the room goes quiet. That silence is the whole point of the exercise. A good facilitator makes it happen on purpose, in a conference room, instead of by accident at 2 a.m. during a real attack.

Why most ransomware tabletops are theater

Walk into the average tabletop and you will see a slide deck, a moderator reading a scenario, and a room of executives nodding along. Everyone leaves feeling prepared. Nobody was tested. That is not an exercise. That is a briefing with snacks.

The tell is the questions. A weak facilitator asks "what would you do here" and accepts the first confident answer. A strong one asks "who has the authority to approve that at 11 p.m. on a Saturday, and what is their cell number." The first question tests the plan. The second tests reality. Ransomware does not care about your plan. It cares about your gaps.

The numbers back this up. IBM's 2025 Cost of a Data Breach report puts the average extortion and ransomware incident at $5.08 million, and the global average breach at $4.44 million. Those are averages across companies that mostly had plans. The plan is not the protection. Testing the plan under pressure is.

What a real facilitator does differently

The job is not to run a smooth exercise. The job is to break the plan on purpose and show the room where it splits.

That means pushing when it gets uncomfortable. It means following the decision to the person who actually has to make it, not the title on the org chart. It means injecting the second problem before the first one is solved, because that is how real incidents arrive. The attacker does not wait for you to finish your last conversation.

A facilitator who has led incidents knows where the cracks are, because they have fallen through them. The legal call that nobody wants to own. The insurer notification clock that started an hour ago and nobody noticed. The backup everyone assumed was clean. These are not hypotheticals. They are the same three failures that show up in almost every room, at almost every company, regardless of size or budget.

The first hour is where plans die

Ransomware plans read well in the daylight. They fall apart in the first hour of the real event, because the first hour is chaos, and chaos does not follow a document.

Here is what changes between the plan and the moment.

The plan saysThe first hour brings
"Notify the incident commander"The incident commander is on a plane and their backup was never named
"Isolate affected systems"Nobody agrees on what "affected" means yet, and isolating the wrong system stops payroll
"Engage legal and the insurer"The policy has a notification window that already started, and no one has the contact
"Restore from backups"The backups are encrypted too, or nobody has tested a restore in a year
"Decide on the ransom"The decision has no owner, and the clock is public

None of these are exotic. They are the ordinary ways a good plan becomes a bad hour. A facilitator who has been in that hour knows to steer the room straight into it, early, while the stakes are still just a whiteboard.

What to look for when you hire a facilitator

Not all tabletops are equal, and not all facilitators are worth their fee. Before you book one, look for a few concrete things.

Operating experience, not just credentials

Ask if they have actually led a live incident, not only studied them. The difference shows up in the room within ten minutes.

A track record of volume

One or two exercises is a sample size of nothing. Ask how many they have run and across which industries.

Executive fluency

The exercise has to work for the board and the C-suite, not only the security team. A facilitator who can only speak to engineers will lose the room that actually decides.

Findings that outlive the day

A real exercise ends with a written set of gaps and owners, not a thank-you email. If you cannot act on it Monday, it was theater.

The willingness to make people uncomfortable

If everyone leaves feeling good, the facilitator did not do the job.

Why the operator seat is the whole difference

I am a 5x CIO and CISO. I have sat in the chair on the worst day, when the systems are down and the board wants an answer and there is no clean one to give. That seat is why the tabletops I run go where they need to go. I am not guessing where the plan breaks. I have watched it break, in real companies, on real days.

That experience is also why I wrote Cyber War: One Scenario, a book that walks through a critical-infrastructure attack the way it actually unfolds, decision by decision, hour by hour. The tabletop and the book do the same thing. They put you in the hour before it happens, so the hour is not the first time you have thought about it.

The good news from that same IBM report is that preparation pays. Organizations that build resilience through planning, testing, and crisis simulation consistently spend less when the real event comes. The tabletop is one of the cheapest, highest-return security investments you can make. A day in a conference room against a seven-figure incident is not a hard math problem.

The question your board should be asking

Stop asking whether you have a ransomware plan. Everyone has a plan. Ask whether anyone in the building has ever tested it under pressure, with someone in the room who has run the real thing and will not let you off easy.

If the answer is no, that is the gap. And the attacker already knows it.

If you want a ransomware tabletop that finds the cracks before an attacker does, book a tabletop exercise facilitator here or bring me in to speak on ransomware and incident response. The book that pairs with it, Cyber War: One Scenario, is on the books page.