Most organizations discover the gaps in their ransomware response in the middle of an actual ransomware event. The questions below are the ones a crisis management team is typically forced to answer in the first hour — often for the first time, in front of a board or a regulator. If your team can't answer these in a calm room, they won't be able to answer them live.

Activation & Governance

  1. Who has the authority to declare a crisis and activate the executive crisis team? If the answer requires a phone call to find out, that's the first gap.
  2. Who is in the room, and who is explicitly not? Unclear membership slows every decision after it.
  3. What is the decision-making structure once the team is activated — consensus, single decision-maker, or something else? This should be decided before the event, not during it.

The Ransom Decision

  1. Who decides whether to engage with the threat actor at all? Not whether to pay — whether to even open a dialogue.
  2. What is your organization's position on paying a ransom, and who has the authority to approve it if the answer changes under pressure?
  3. Do you have a relationship with a ransomware negotiation firm, or would you be sourcing one for the first time mid-incident?

Notification & Communication

  1. What are your actual regulatory notification deadlines, and who owns tracking them once the clock starts?
  2. What will you tell employees, and when — before or after it's public?
  3. Who is your single point of contact with media, and what have they been authorized to say?

Recovery & Evidence

  1. Which systems get restored first, and who made that priority call — IT, or the business?
  2. Are you preserving evidence in a way that holds up for law enforcement, regulators, and insurance, or are you moving too fast to capture it?
  3. Who is documenting the decisions being made in real time, and where does that record live afterward?

Don't know? Pressure-test it.

A Pressure Test exercise is built to surface exactly which of these twelve your team can actually answer — before a real event asks them for you. Reach out directly to scope one; all inquiries are confidential.

Request a confidential scoping call →

If you'd like a copy of this checklist to circulate internally, email hello@crisisstudio.com and I'll send it over.