Most organizations discover the gaps in their ransomware response in the middle of an actual ransomware event. The questions below are the ones a crisis management team is typically forced to answer in the first hour — often for the first time, in front of a board or a regulator. If your team can't answer these in a calm room, they won't be able to answer them live.
Activation & Governance
- Who has the authority to declare a crisis and activate the executive crisis team? If the answer requires a phone call to find out, that's the first gap.
- Who is in the room, and who is explicitly not? Unclear membership slows every decision after it.
- What is the decision-making structure once the team is activated — consensus, single decision-maker, or something else? This should be decided before the event, not during it.
The Ransom Decision
- Who decides whether to engage with the threat actor at all? Not whether to pay — whether to even open a dialogue.
- What is your organization's position on paying a ransom, and who has the authority to approve it if the answer changes under pressure?
- Do you have a relationship with a ransomware negotiation firm, or would you be sourcing one for the first time mid-incident?
Notification & Communication
- What are your actual regulatory notification deadlines, and who owns tracking them once the clock starts?
- What will you tell employees, and when — before or after it's public?
- Who is your single point of contact with media, and what have they been authorized to say?
Recovery & Evidence
- Which systems get restored first, and who made that priority call — IT, or the business?
- Are you preserving evidence in a way that holds up for law enforcement, regulators, and insurance, or are you moving too fast to capture it?
- Who is documenting the decisions being made in real time, and where does that record live afterward?
Don't know? Pressure-test it.
A Pressure Test exercise is built to surface exactly which of these twelve your team can actually answer — before a real event asks them for you. Reach out directly to scope one; all inquiries are confidential.
Request a confidential scoping call →If you'd like a copy of this checklist to circulate internally, email hello@crisisstudio.com and I'll send it over.
The Crisis Studio