PONOPT FIELD NOTES · Кибербезопасность и закупки

A Municipal Ransomware Tabletop: The First 24 Hours Without Core Systems

A municipal ransomware tabletop that rehearses the first 24 hours without finance, permitting, and records systems: containment, notification, communications, and restore order.

Run a 24-hour, inject-driven tabletop in which a city wakes up with finance, permitting, email, and records systems encrypted and possibly exfiltrated. Decide in sequence: confirm the incident, isolate affected segments, move coordination to an out-of-band channel, notify leadership, law enforcement, and your insurer, then set a restore order. Treat the ransom payment as a governance and policy decision rather than a technical fix, and document every choice for the after-action report.

Key takeaways

  • A tabletop rehearses leadership decisions, not button-pushing: advanced practice is what let one California city detect and contain a real February 2023 attack within the first hour and pay no ransom.
  • Work in sequence — detection, isolation, notification — and shift coordination to an out-of-band channel (phone calls) so attackers monitoring the network do not learn they were discovered and spread further.
  • Restore from a pre-defined critical asset list that puts health-and-safety and revenue services first, using clean, offline, tested backups on a dedicated clean network.
  • Treat payment as a governance question with legal, insurer, and law-enforcement input, not a purely technical decision, because payment offers no guarantee of access or silence.
  • Capture decisions and measurable outcomes in real time so the after-action report drives concrete revisions to plans, contacts, and the next exercise.

Why a municipal tabletop earns its cost

A common mistake is treating a ransomware event as an IT problem. In a city, an attack stops bill payments, permits, records access, and public counters, so the decisions belong to leaders: the manager or mayor, attorneys, public information officers, finance staff, and operations chiefs. A tabletop is a facilitated, discussion-based rehearsal of those decisions against a realistic scenario, not a live technical drill. Its purpose is to expose gaps such as unclear roles, stale contact lists, missing manual procedures, and muddled approval chains.

The City of Modesto, California, demonstrates the payoff. In December 2022 it ran a four-hour tabletop with all department heads, the city manager, the city attorney, and the communications director, plus observers from the FBI and state and regional agencies. Two months later, on February 3, 2023, attackers who had been inside the network for three days preparing and exfiltrating personally identifiable information launched their encryption against key police systems. The city detected and contained the attack within the first hour and paid no ransom, a result its CIO credits to the rehearsed response plan and established relationships.

  • Invite decision-makers, not only IT: leadership, legal, communications, finance, and heads of resident-facing services.
  • Design the exercise around roles and approvals, not network commands, so each participant learns what they decide and whom they call.
  • Include pressure, not just technique: council demands, press questions, and suspected data theft belong in the scenario.

Building the scenario: systems go dark at 06:00

Start with a single, credible trigger: at 06:00 a finance analyst sees files with an encryption extension and a ransom note on the ERP server. By 09:00 the scope widens to the water-billing system, the permitting module, and municipal email, while the 911 dispatch radio and the telephone switchboard — running on separate infrastructure — still work. That detail matters: some critical services may live on isolated networks, and the team must explicitly name them as trusted so staff can keep using them.

Gradual injects build pressure and force decisions under uncertainty. For example, encryption began overnight through a vendor VPN account; yesterday's backup set is encrypted but the set from two days ago is clean; and the note references stolen resident data with a threat to publish it within 72 hours. Each inject tests one decision: when to isolate, what recovery point to accept, how to communicate, and how to weigh payment. A good facilitator introduces injects at scheduled clock times rather than all at once, preserving a realistic sense of pace.

  • Sequence injects over the exercise clock so teams feel the passing of hours, not a pile of simultaneous crises.
  • Have some participants work 'by phone' with staff and vendors, mirroring how coordination actually happens.
  • Include a data-exfiltration element, since extortionists increasingly combine encryption with threats to publish stolen data.

The first 24 hours, in sequence

The opening hours decide the outcome. During detection and analysis, determine which systems are impacted and isolate them immediately. If several subnets are affected, take the network offline at the switch level; for individual devices, unplug the cable or remove them from Wi-Fi. Power devices down only when they cannot otherwise be isolated, because shutting them off destroys evidence in volatile memory that forensics needs. Shift all coordination to an out-of-band channel such as phone calls, because attackers may be watching network traffic and, once they learn they are detected, may move laterally or deploy ransomware widely before the network comes down.

Notification comes next, in line with the crisis communications plan: engage leadership, departments, your managed security provider, cyber insurer, and law enforcement so each understands how they can help. Reporting requirements for an incident — and especially for a suspected data breach — differ by jurisdiction and change over time, so confirm your obligations with counsel before the exercise rather than during a crisis. In parallel, draft the public statement, but publish only what is verified.

  • Follow the detection → isolation → notification → analysis → recovery sequence recommended in the joint CISA/FBI/NSA/MS-ISAC ransomware guidance.
  • Identify systems that are not impacted and deprioritize them so you return to normal work faster.
  • Before rebuilding, hunt for signs of a precursor compromise — new admin accounts, anomalous VPN logins, or dropper malware — or you may rebuild onto an infected base.

Reporting, the public statement, and the payment question

Communications are the most politically delicate part of a municipal incident. Residents need to know whether they can pay for water, get a permit, and whether their data is safe. Silence creates a vacuum that rumors and journalists fill, but premature statements that turn out wrong erode trust. The practical approach is a short, confirmed message that an incident occurred, services are partly unavailable, and protecting data is the priority, with details released as they are verified. The tabletop should pin down who drafts the statement, who approves it, and how the team separates 'confirmed' from 'suspected' at every hour.

Payment belongs outside the IT team's lane. The decision to pay is a governance question requiring the city attorney's view, the insurer's policy position, and input from law enforcement, who may know whether a decryptor exists for the specific variant. Even when payment is lawful and feasible, it guarantees neither the return of access nor silence about stolen data. The realistic focus is recovery from clean backups and care not to re-infect the clean environment while systems come back online.

  • Agree in advance who is the single authorized voice and who approves public releases.
  • Put pressure on the team with a council member demanding an immediate statement, then assess whether the response separates facts from assumptions.
  • Separately rehearse regulator and affected-resident notification if a breach of personal data is suspected, and confirm the applicable timelines for your jurisdiction.

Restore order, measure success, and record lessons

Recovery proceeds not 'everything at once' but from a pre-defined critical asset list: prioritize systems tied to health and safety and to revenue generation, along with the services they depend on. Restore data from offline, encrypted backups onto a clean network, for example a dedicated recovery VLAN, so you do not re-infect clean systems. Reset credentials on all affected systems, close the vulnerabilities that enabled access, and verify that no persistence mechanisms remain before declaring the incident over.

The exercise's real value shows in the after-action report: which services were restored, how long each critical asset was down, and how many resident inquiries went unanswered. These measurable outcomes turn abstract 'readiness' into concrete edits to plans, contact lists, and manual procedures, and they shape a harder follow-up exercise. Framework profiles such as the NIST Ransomware Risk Management profile built on the Cybersecurity Framework help you align exercise goals with the full practice of governing, identifying, protecting, detecting, responding, and recovering.

Scope and limits: an exercise is not an audit

A tabletop validates readiness to decide; it does not replace a technical audit, live recovery tests, or everyday hygiene such as patching, multi-factor authentication, least-privilege access, and offline backups. The NIST profile stresses that resilience is the product of many practices, and an exercise is one instrument among several. Treat 'we passed the exercise' as a checkpoint, not a certificate of protection.

Reporting deadlines and notification rules for cyber incidents differ across countries and states and are subject to change, so this article offers general guidance, not legal advice. Before running the exercise, reconcile the scenario with the law in your jurisdiction and the terms of your insurance policy. Official exercise packages and materials (for example those from CISA) are updated by their organizers, so confirm current availability on the official site.

  • Do not claim that a completed exercise proves the city is secure; it measures readiness for decisions, not technical immunity.
  • Verify that backups actually restore, not merely that they exist.
  • Prefer official exercise packages and regulator guidance from your country over unverified commercial descriptions.

Facilitator's First-24-Hours Inject and Decision Card

A reusable skeleton for the person running the exercise. Each inject arrives at a clock time and probes who decides, on what evidence, and how the city would actually act. Adjust the times and wording to your municipality and to the architecture of your systems.

  1. T+0, 06:00 — A finance analyst reports encrypted files and a ransom note on the ERP server. Probe: who declares the incident, who convenes the crisis team, and on what communication channel?
  2. T+45 min — IT confirms encryption is spreading and suspects it began overnight through a vendor VPN account. Probe: isolate affected segments or take the whole network offline, and what evidence is preserved first?
  3. T+2h — Checks show water billing and the permitting module are down, but 911 dispatch radio and the phone switchboard still work. Probe: which systems live on separate networks and are treated as trusted?
  4. T+3h — Backups from two days ago verify clean, but yesterday's set is encrypted. Probe: what recovery point do you accept, and what is a realistic time-to-restore per critical service?
  5. T+4h — A council member demands an immediate public statement. Probe: who drafts it, who approves it, and what is verifiably known versus suspected at this hour?
  6. T+6h — The note references stolen resident PII and threatens publication in 72 hours. Probe: does this change your regulator and affected-resident notification, and on what timeline?
  7. T+12h — Finance asks whether to pay the ransom to recover invoices before month-end close. Probe: who owns the payment decision, and what input comes from legal, the insurer, and law enforcement?
  8. T+18h — Lines form at service counters as residents switch to paper forms. Probe: which manual workarounds were pre-approved, and how are they kept secure?
  9. T+24h — The team writes a council status update and the after-action brief. Probe: what metrics — restored services, downtime per critical asset, unanswered resident inquiries — show real progress?

Questions people ask

Who should be in the room for a municipal ransomware tabletop?

More than IT leaders: the city manager or mayor, the city attorney, the communications director, finance staff, and heads of resident-facing services such as water, permits, and human resources. These are the people who decide on notification, public statements, restore priorities, and payment. Modesto's experience shows that including every department head plus observers from the FBI and state and regional agencies produced a complete, coordinated response plan with clear owners.

Should we take the whole network offline in the first hour?

It depends on scope. CISA's ransomware guidance says to first determine which systems are impacted and isolate them; if several subnets appear affected, take the network offline at the switch level. For individual devices, unplug the cable or remove them from Wi-Fi, and power down only if you cannot otherwise isolate them, since shutdown destroys volatile-memory evidence. Whether to cut everything or only segments is exactly what the tabletop should debate, because a full shutdown also stops unaffected services.

Do we have to tell residents and the public immediately?

Communicate early but publish only what is verified: what was affected, whether data is safe, and which services remain available. A short, confirmed message that an incident occurred and protecting data is the priority works better than silence, with details added as they are confirmed. The exercise should pin down who approves the statement and how the team distinguishes confirmed facts from assumptions. Breach-notification timelines to regulators and affected residents are set by your jurisdiction's law, so confirm them with counsel in advance.

When should we consider paying the ransom?

Payment is a governance decision, not an IT call. Weigh the city attorney's advice, the insurer's policy position, and law-enforcement input, since investigators may know whether a decryptor exists for the variant. Even after payment, there is no guarantee of restored access or silence about stolen data. The primary path is recovery from clean, offline backups. Modesto paid nothing and recovered, but every situation differs and the decision should be made collectively with legal, insurance, and law-enforcement expertise.

What does a successful first 24 hours actually look like?

Success is measured by outcomes, not by how fast people panicked: the incident was confirmed and contained, coordination moved to an out-of-band channel, leadership and law enforcement were notified, the public statement was verified and approved, and restoration of critical services from clean backups began. Useful metrics include downtime per critical asset, number of services restored, and resident inquiries left unanswered. These feed the after-action report and drive concrete improvements to the plan and the next exercise.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. I've Been Hit By Ransomware! | CISACybersecurity and Infrastructure Security Agency (CISA)
  2. CISA Tabletop Exercise Packages | CISACybersecurity and Infrastructure Security Agency (CISA)
  3. Stop Ransomware | CISACybersecurity and Infrastructure Security Agency (CISA)
  4. NIST IR 8374r1 Ransomware Risk Management: A Cybersecurity Framework 2.0 Community ProfileNational Institute of Standards and Technology (NIST)
  5. The Value of a Cybersecurity Attack Response Tabletop ExerciseMulti-State Information Sharing & Analysis Center (MS-ISAC)
  6. Table-Top Cyber Exercising Resources for Scottish Local AuthoritiesThe Digital Office, Scottish Government