• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

About Us | Articles | Free Resources | Podcast | YouTube Channel

Contact Us Subscribe

Bryghtpath

Business Continuity and Crisis Management Consultants

  • Start
        • Start your Resilience Journey

          Moving your organization – or your career – forward on your resilience journey can be a difficult and scary proposition.  Often, we find that prospective clients aren’t quite sure where to start.

          To help you along your journey, we’ve outlined below four curated collections geared towards momentum-building action and advice perfectly paired with your organization’s current stage of resilience.

        • I want to learn more about Resilience

        • We’re just getting started with our resilience program

        • We’re seeking to optimize & mature our resilience program

        • I’m a Resilience Professional seeking to further develop my skills

  • Company
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
  • Courses & Training
        • Courses & Training

          We’ve created a number of free and premium courses that have helped thousands improve their skills, build more resilient organizations, and lead through organizations through difficult critical moments successfully.

        • Coaching
          • 1-on-1 Coaching Call
          • Private Backchannel
          • Private Coaching Program
        • Free Intro Courses
          • Overview
          • Business Continuity 101
          • Crisis Communications 101
          • Crisis Management 101
        • Premium Courses
          • Overview
          • Custom Training
          • 5-Day Business Continuity Accelerator
          • Communicating in the Critical Moment
          • Crisis Management Academy®️
          • Preparing for Careers in Resilience
  • Expertise
        • Our Expertise
        • Here at Bryghtpath, in our core values, we state that we are humbly confident in our resiliency expertise.

          We write, publish, speak, and train others constantly – striving to share our thought leadership publicly to advance our industry and exercise our curiosity by interacting with other leaders in our practice domains.

        • Ultimate Guide to Business Continuity

        • Ultimate Guide to Crisis Management

        • Case Studies & Results

        • Free Resources & Frameworks
          • Overview - Free Resources
          • Bryghtpath Frameworks
            • Bryghtpath Business Continuity Lifecycle
            • Bryghtpath Crisis Management Framework
            • Bryghtpath Exercise Maturity Model
            • Bryghtpath Global Security Framework
            • Bryghtpath Long-Term Recovery Framework
            • Bryghtpath Professional Reading List
            • Bryghtpath Workplace Violence & Threat Management Toolkit
          • Resiliency Professionals Facebook Group
          • Resource Library
          • Webinars & Videos
          • Whitepapers & Reports
        • Our Thoughts & Insights
          • Articles
          • Lead Through Disruption. Stay Ahead with Bryghtpath.
          • Managing Uncertainty Podcast
          • Media & Professional Appearances
          • YouTube Channel
        • Whitepapers & Reports
          • Global Security Operations Centers & Resilience
          • Managing the Whole Crisis: The Ransomware Challenge
          • Mastering Uncertainty: Strengthening Organizational Resilience
          • Social Activism Campaigns
          • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
        • Our Industry Expertise

          Bryghtpath has extensive experience in a number of industries working with clients of all sizes, geographical locations, and business models. As a team, we possess, deep global operating experience on every continent around the world.

        • Industries Overview

        • Case Studies

        • Start your Journey

        • Education

          Education Icon
        • Finance

          Financial Services 800x800
        • Government

          Government Icon
        • Healthcare

          Healthcare Icon 800x800
        • Hospitality & Leisure

          Hospitality & Leisure Industry Icon 800x800
        • Life Sciences

          Life Sciences 800x800
        • Logistics

          Transportation & Logistics Industry Icon 800x800
        • Manufacturing

          Manufacturing Industry Icon 800x800
        • Non-Profits

          Non-Profit Industry Icon 800x800
        • Retail

          Retail Industry Icon 800x800
        • Tech & Media

          Communications Industry Icon 800x800
        • Utilities

          Power & Utilities Icon
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • Start
  • Company
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
  • Courses & Training
    • Coaching
      • 1-on-1 Coaching Call
      • Private Backchannel
      • Private Coaching Program
    • Free Intro Courses
      • Overview
      • Business Continuity 101
      • Crisis Communications 101
      • Crisis Management 101
    • Premium Courses
      • Overview
      • Custom Training
      • 5-Day Business Continuity Accelerator
      • Communicating in the Critical Moment
      • Crisis Management Academy®️
      • Preparing for Careers in Resilience
  • Expertise
    • Our Expertise
    • Our Thoughts & Insights
      • Articles
      • Lead Through Disruption. Stay Ahead with Bryghtpath.
      • Managing Uncertainty Podcast
      • Media & Professional Appearances
      • YouTube Channel
    • Free Resources & Frameworks
      • Overview – Free Resources
      • Bryghtpath Frameworks
        • Bryghtpath Business Continuity Lifecycle
        • Bryghtpath Crisis Management Framework
        • Bryghtpath Exercise Maturity Model
        • Bryghtpath Global Security Framework
        • Bryghtpath Long-Term Recovery Framework
        • Bryghtpath Professional Reading List
        • Bryghtpath Workplace Violence & Threat Management Toolkit
      • Resiliency Professionals Facebook Group
      • Resource Library
      • Webinars & Videos
      • Whitepapers & Reports
    • Whitepapers & Reports
      • Global Security Operations Centers & Resilience
      • Managing the Whole Crisis: The Ransomware Challenge
      • Mastering Uncertainty: Strengthening Organizational Resilience
      • Social Activism Campaigns
      • The Resilience Roadmap: 250 Ways to Fortify your Business against Disruption
  • Industries
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Building your Ransomware Playbook

You are here: Home / Crisis Management / Building your Ransomware Playbook

January 24, 2023 By //  by Bryan Strawser

Reading about the latest ransomware hack feels a lot like watching a bicyclist hurdle head-first over handlebars into a pile of gravel.

“Oof, that had to hurt.” And, “boy, am I glad that wasn’t me.”

But that’s where the similarity between the two stops.

Because although you can take all the right steps to keep your systems safe, in today’s digital environment, having to deal with a ransomware incident is a “when,” not “if” proposition.  And the stakes are staggering – downtime and lost productivity, recovery costs, legal liabilities, and reputational damage, to name a few.

Businesses big and small, those who are just at the beginning of their business continuity and crisis management journey, and those who have already invested significantly in resiliency all have more questions than they do answers. Like:

  • What kinds of staff, resources, and third parties do we need to have at the table?
  • What tools are we missing?
  • What if paying the ransom is the only good way out of the situation?

Here’s what you need to know if you’re one of them.

Why the Ransomware Threat is Different

Although ransomware is just one of many risks that your crisis management program should address, it’s a particularly complicated threat that stands apart—and demands an equally specific plan—in several ways.

It requires a deep bench of expertise

Many companies make the mistake of focusing solely on the technical aspects of responding to and recovering from a ransomware incident; what systems are affected, how did the perpetrators get in, and how do you recover your systems and get them up and running again?

But managing the technical aspects of a ransomware incident is only a small part of your response.  Typically, less than a third in our experience.  So, while infosec is busy managing the technical piece, you also need an extensive roster of outside experts to manage the rest, including:

  • Communications and reputation management—When millions of healthcare records are exfiltrated by a bad actor, you need to get and stay ahead of the questions.
  • Compliance and reporting obligations, especially if you’re publicly traded and are obligated to report such breaches to regulatory bodies like the SEC
  • Coordinating with government agencies, like DHS and Treasury, to navigate the web of restrictions on paying bribes to a foreign actor
  • Managing the negotiation itself
  • Setting up a payment mechanism for the ransom—Spinning up a $17,000,000 Bitcoin account doesn’t happen overnight

This requires a deep bench of outside help, including counsel, communications consultants, cyber-forensic specialists, and regulatory experts, to name a few. It’s best that these relationships are secured and, ideally, practiced well before you manage an actual incident.

Privilege matters

Cyber-extortion and data breach events expose you to tremendous potential liability. Within the first ten minutes of an event, many decisions at the advice of counsel need to be made on how the situation will be managed to mitigate that liability.

When working with our clients, we usually build the crisis response process to put the incident under attorney-client privilege immediately. We make this a specific step in the crisis management plan and/or ransomware playbook. This includes marking documents as privileged and including counsel in all communications and meetings regarding the incident to ensure the incident remains privileged for as long and as much as possible. It’s a unique aspect of managing a ransomware incident that doesn’t happen in most other threat scenarios but is particularly critical to effectively managing the long-term consequences of a cyber-extortion event.

Your reputation is at stake

Amid any disruption, what you say and when you say it can impact everything from regulatory investigations and consumer claims to whether people decide to continue doing business with your brand, not to mention the trickle-down impacts on shareholder value and your bottom line.

A cyber-extortion event carries an additional set of confounding factors. Bad actors will most likely use the threat of taking the incident public to place pressure on negotiations. They may even leak data despite their demands being met.

While preparing your messaging and communications strategy in advance is important for any type of disruption, it’s especially critical for a ransomware event. When the sensitive healthcare records of thousands, including an inevitable handful of celebrities and political figures, get leaked into the ether, you want to be the one controlling the narrative that unfolds. Not the New York Times, Twitter, or the inadvertent scrupulations of worried employees. Your messaging around an incident needs to be well-thought-out and planned in advance for a multitude of high-stakes scenarios. Those plans must be a part of your ransomware playbook.

Learn how Bryghtpath developed & facilitated a ransomware exercise for a major healthcare technology company

A major U.S. healthcare organization, seeking to practice their recently updated cybersecurity incident response plan, turned to Bryghtpath to conduct a multi-day complex crisis simulation exercise centered on a realistic ransomware incident.

Read the Case Study >>

4 Steps to Ransomware Playbook Readiness

1.   Get an overall crisis management strategy in place (if you don’t already have one)

A ransomware plan is a good first step if you’re just starting your crisis management journey. But it is not meant to be a stand-in for an overarching crisis management strategy. Your ransomware playbook is meant to be just that—a tool to help you navigate the aspects of responding to a ransomware incident and the risks that it presents. Ideally, your organization should have specific playbooks built for the other likely potential disruptions it might face. And these playbooks should be just one small part of an overall crisis management strategy designed to facilitate your organization’s response to a wide range of potential disruptions. That strategy should include things like:

  • Having a process in place to collaborate and communicate during an event
  • Having a plan for managing both long and short-term recovery efforts, and
  • A defined process for capturing lessons learned and improving your preparedness for future disruptions.

At Bryghtpath, we look at preparations for a ransomware threat (and every other threat) through a resiliency lens. Resilience–the capabilities you need to solve big problems, continue operations, and protect your assets and your people in an environment of increasing and confounding disruptions – cannot be achieved in a silo. If you aim to respond effectively to your next ransomware event, your best first step is to get a well-defined and overarching crisis management strategy in place first.

2.   Clearly define roles and responsibilities

One of the first steps to building out an effective crisis management plan is determining roles and responsibilities.

  • Who will manage the overall incident response?
  • Who has the authority to make critical decisions, such as approving ransom payments or specific messaging?
  • Who will deploy that messaging and respond to outside inquiries?

If your organization already has a crisis management program, these roles and responsibilities will already be largely established.  However, because of the complexity and high stakes of a ransomware response, you will likely have a subset of additional players whose roles and responsibilities need to be coordinated, including outside counsel, insurers, PR and crisis communications experts, data breach notification providers, and forensic analysts, among others.

Outside counsel is an excellent example of where this is especially important.  Smaller organizations often expect that outside counsel will step in and run the incident from a legal aspect. However, a larger organization might expect its in-house counsel to maintain ultimate control and decision-making authority, with outside counsel supporting those efforts. If there ever was a “too many cooks in the kitchen” problem that you need to avoid, it’s this one. And making sure you clearly define and exercise roles and responsibilities in advance is an excellent way to do it.  All of these roles and responsibilities should be documented in your crisis management plan and/or ransomware playbook.

3.   Have a process

Every crisis incident should be managed within a crisis management lifecycle that includes the key steps of moving the incident from the initial notification and assessment stages through escalation, incident response, deactivation, recovery, and ultimately debriefing and incorporating lessons learned.

Within each of these lifecycle steps, you should have a process detailed for every function; clear and easy to access to tactical instructions and guidance on what to and how to do it. This can include checklists, diagrams, charts, and other clear visuals to help people quickly understand what to do depending on what’s happening. Checklists are also valuable in providing an audit trail in the aftermath of the response.

4.   Prepare your messaging

“There are so many potential scenarios, it’s just not practical or possible to prepare our messaging in advance.”

This is a commonly held belief in many organizations. It’s also one that’s just not true.

Time is typically your most limited resource in responding to a ransomware event. Making your communications plan ahead of time will increase the speed and clarity of your response and ultimately facilitate a better overall ransomware response.

That’s why your communications framework should include messaging tailored to internal and external audiences, including board members, employees, shareholders, clients, local communities, and bad actors. Your framework should also specify which messages to use, when, approval requirements, spokespeople, and the preferred communication channels for each target audience.

If you’re just getting started on your ransomware playbook readiness journey, Bryghtpath can help. And even if you have your crisis management game dialed in, moving from “plan” to “practice” can feel like a big lift. We can help you close the gaps and develop confidence in your capabilities to respond to the next ransomware threat.

Want to work with us to learn more about Ransomware Playbooks and Crisis Management?

  • Our proprietary Resiliency Diagnosis process is the perfect way to advance your crisis management & ransomware capabilities. Our thorough standards-based review culminates in a full report, maturity model scoring, and a clear set of recommendations for improvement.
  • Learn how Bryghtpath has built cybersecurity incident response plans and facilitated ransomware exercises through our case studies of previous client work.
  • Our Crisis Management & Business Continuity services help you rapidly grow and mature your program to ensure your organization is prepared for the storms that lie ahead.
  • Our Ultimate Guide to Crisis Management contains everything you need to know about Crisis Management.
  • Our free Crisis Management 101 Introductory Course may  help you with an introduction to the world of crisis management – and help you prepare your organization for the next disruption.
  • Learn about our Free Resources, including articles, a resource library, white papers, reports, free introductory courses, webinars, and more.
  • Learn more about our healthcare industry experience
  • Set up an initial call with us to chat further about how we might be able to work together.

Category: Crisis Management, CybersecurityTag: Bryan Strawser, bryghtpath, bryghtpath llc, crisis management, crisis management consultant, cybersecurity, information security, ransomware, ransomware playbook

About Bryan Strawser

Bryan Strawser is Founder, Principal, and Chief Executive at Bryghtpath LLC, a strategic advisory firm he founded in 2014. He has more than twenty-five years of experience in the areas of, business continuity, disaster recovery, crisis management, enterprise risk, intelligence, and crisis communications.

At Bryghtpath, Bryan leads a team of experts that offer strategic counsel and support to the world’s leading brands, public sector agencies, and nonprofit organizations to strategically navigate uncertainty and disruption.

Learn more about Bryan at this link.

Previous Post: « Business Continuity Planning in Healthcare
Next Post: Help! My Business Continuity Program is Stuck! »

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Premium Courses

5-Day Business Continuity Accelerator

Communicating in the Critical Moment

Crisis Management Academy®️

Preparing for Careers in Resilience

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model™
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.