• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to primary sidebar
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity Software
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Resilience as a Service
          • Business Continuity as a Service (BCaaS)
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • Book – From Panic to Poise: Crisis Management in the Modern World
          • Book – The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity Software
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Resilience as a Service
      • Business Continuity as a Service (BCaaS)
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • Book – From Panic to Poise: Crisis Management in the Modern World
      • Book – The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Deciding Under Fire: An Executive Cyber-Extortion Exercise for a Major Health Insurer

A major U.S. health insurer partnered with Bryghtpath to put its executive leadership team through a cyber-extortion simulation, testing how its most senior leaders would make a high-stakes ransom decision while protecting members, meeting regulators, and engaging the board.

You are here: Home / Capabilities / Case Studies / Deciding Under Fire: An Executive Cyber-Extortion Exercise for a Major Health Insurer

A major U.S. health insurer partnered with Bryghtpath to put its executive leadership team through a cyber-extortion simulation, testing how its most senior leaders would make a high-stakes ransom decision while protecting members, meeting regulators, and engaging the board.

The Opportunity

A major U.S. health insurer needed to know whether its most senior leaders could make the hardest calls in a ransomware crisis. A real cyber-extortion event would force the executive team to weigh a ransom payment, member notification, regulatory obligations, and board engagement at speed, with member services and claims on the line.

The insurer engaged Bryghtpath to design, facilitate, and evaluate an executive-level tabletop exercise based on a realistic cyber-extortion scenario, extending an earlier crisis-team exercise to the executive leadership team.

Approach and Results

Bryghtpath built the exercise around a realistic cyber-extortion event: a well-known ransomware group encrypted the insurer’s core claims processing system and issued a $18 million ransom demand, which was negotiated down to $8 million through a third-party firm. The scenario advanced through discovery, containment, negotiation, and decision phases, extending an earlier crisis-team tabletop exercise to the executive leadership team so the organization could test the escalation from the crisis team to its most senior leaders.

In the session, the executive team made real-time decisions on whether to pay, how and when to notify members and regulators, when to engage the board, and how to manage public messaging, all while weighing the impact on claims, pharmacy, prior authorization, and provider payments. Outside counsel played their real-life role advising the executives throughout the exercise.

The team engaged deeply and reached a decisive outcome on the ransom question. The exercise also surfaced the highest-value next steps: a crisis communications playbook, a ransom-payment decision framework, and stronger executive access to business continuity impact data. Bryghtpath delivered a prioritized after-action report to guide them.

Key Activities

  • Designed a cyber-extortion scenario built on a current, real-world ransomware threat group.
  • Advanced the scenario through discovery, containment, ransom negotiation, and decision phases.
  • Facilitated an executive tabletop on the pay/no-pay decision, member notification, and board engagement.
  • Engaged advisors from communications, public affairs, information security, and resilience, with outside counsel.
  • Evaluated the response and delivered an after-action report with prioritized recommendations.

Outcomes

  • Gave senior executives realistic practice in making high-stakes ransom decisions under pressure.
  • Tested escalation from the crisis management team to the executive leadership team.
  • Validated strong executive engagement and decisive decision-making under uncertainty.
  • Identified the need for a crisis communications playbook and a ransom-payment decision framework.
  • Delivered a prioritized after-action report to mature executive crisis readiness.

We can help.

Let the experts at Bryghtpath put their decades of experience to work for your organization

Our team has the experience, tools, and partnerships to help your organization successfully navigate the rough waters ahead – and ensure your organization is prepared.

I’D LIKE TO TALK TO BRYGHTPATH

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Resilience as a Service
    • Business Continuity as a Service (BCaaS)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.