• Menu
  • Skip to right header navigation
  • Skip to main content
  • Skip to secondary navigation
  • Skip to footer

Before Header

Bryghtpath

Business Continuity and Crisis Management Consultants

  • About
        • About Bryghtpath

        • Our Core Values

        • Meet our Team

        • About Bryghtpath
          • Case Studies & Results
          • Certifications and Awards
          • Contact Bryghtpath
          • Contract Vehicles
          • Media & Professional Appearances
          • Our Clients
          • Our Proven Process
          • Security & Compliance
          • Strategic Partners
          • Work with Us
  • Capabilities
        • Our Capabilities
        • We help your organization strategically navigate uncertainty and disruption.

        • Case Studies & Results

        • Business Continuity as a Service

        • Business Continuity
          • Business Continuity - Overview
          • Business Continuity as a Service (BCaaS)
          • Business Continuity Software
          • Coaching
          • IT Disaster Recovery
          • Resiliency Diagnosis®️
        • Crisis Management
          • Crisis Management - Overview
          • Crisis Communications
          • Crisis Exercises
          • Cyber Crisis Exercises
          • Cyber Incident Response Planning
          • Crisis Playbook®️
          • Global Security Operations Center (GSOC)
          • Resiliency Diagnosis®️
        • Other Capabilities
          • Coaching
          • Intelligence & Global Security Consulting
          • Speaking
          • Training
        • Case Studies & Results
        • Industries
  • Insights
  • Products
        • Our Products

          College Classroom - Mature Teacher
        • Crisis Playbook™️

        • Exercise in a Box™️

        • Exercise in a Day™️

        • Books
          • From Panic to Poise: Crisis Management in the Modern World
          • The Continuity Code: Mastering Business Resilience
        • Crisis Playbook™️
          • Overview
          • Active Shooter Plan
          • Emergency Response Guide
          • Fatality
          • Food/Product Recall
          • Protest
          • Violent Attack
        • Maturity Models
          • Overview
          • ASIS Workplace Violence and Active Assailant
          • FFEIC Maturity Model – Business Continuity
          • ISO 22301 – Business Continuity
          • ISO 22361 – Crisis Management
          • ISO 27031 - IT Disaster Recovery
          • NIST 800-53 Contingency Planning Maturity Model
        • Templates & More
          • After-Action Process & Templates
          • Awareness Collateral
          • Business Continuity Plan Templates
          • Crisis Management Plan Templates
          • Disaster Recovery Plan Templates
          • Job Descriptions
  •  

Mobile Menu

  • About
    • About Bryghtpath
      • Case Studies & Results
      • Certifications and Awards
      • Contact Bryghtpath
      • Contract Vehicles
      • Media & Professional Appearances
      • Our Clients
      • Our Proven Process
      • Security & Compliance
      • Strategic Partners
      • Work with Us
  • Capabilities
    • Our Capabilities
    • Business Continuity
      • Business Continuity – Overview
      • Business Continuity as a Service (BCaaS)
      • Business Continuity Software
      • Coaching
      • IT Disaster Recovery
      • Resiliency Diagnosis®️
    • Crisis Management
      • Crisis Management – Overview
      • Crisis Communications
      • Crisis Exercises
      • Cyber Crisis Exercises
      • Cyber Incident Response Planning
      • Crisis Playbook®️
      • Global Security Operations Center (GSOC)
      • Resiliency Diagnosis®️
    • Other Capabilities
      • Coaching
      • Intelligence & Global Security Consulting
      • Speaking
      • Training
    • Case Studies & Results
    • Industries
  • Insights
  • Products
    • Books
      • From Panic to Poise: Crisis Management in the Modern World
      • The Continuity Code: Mastering Business Resilience
    • Crisis Playbook™️
      • Overview
      • Active Shooter Plan
      • Emergency Response Guide
      • Fatality
      • Food/Product Recall
      • Protest
      • Violent Attack
    • Maturity Models
      • Overview
      • ASIS Workplace Violence and Active Assailant
      • FFEIC Maturity Model – Business Continuity
      • ISO 22301 – Business Continuity
      • ISO 22361 – Crisis Management
      • ISO 27031 – IT Disaster Recovery
      • NIST 800-53 Contingency Planning Maturity Model
    • Templates & More
      • After-Action Process & Templates
      • Awareness Collateral
      • Business Continuity Plan Templates
      • Crisis Management Plan Templates
      • Disaster Recovery Plan Templates
      • Job Descriptions
  •  

Developing Ransomware Solutions for a leading Healthcare Technology Provider through Tabletop Exercises

A primary U.S. healthcare technology provider, seeking to develop new solutions to the challenges of ransomware and cyberextortion attacks, retained Bryghtpath to conduct tabletop exercises for their IT & technology product teams.

You are here: Home / Capabilities / Case Studies / Developing Ransomware Solutions for a leading Healthcare Technology Provider through Tabletop Exercises

A primary U.S. healthcare technology provider, seeking to develop new solutions to the challenges of ransomware and cyberextortion attacks, retained Bryghtpath to conduct tabletop exercises for their IT & technology product teams.

The Opportunity

The organization had previously worked with Bryghtpath to develop their business continuity, crisis management, and IT disaster recovery programs along with a detailed Cybersecurity incident response plan. Bryghtpath was retained by the Chief Information Officer (CIO) and Chief Product Officer (CPO) to design a series of discussion-focused tabletop exercises for their technology & product teams to navigate several specific ransomware scenarios impacting their core healthcare technologies.

The company was explicitly interested in detailing through response and recovery challenges, identifying technical obstacles that need to be resolved, and the significant decisions technology leaders would need to work through in such an incident.

Approach and Results

We kicked off  the six-week effort by hosting an initial planning session with executive stakeholders to identify the exercise’s goal and establish an internal team of subject matter experts. We then worked with the internal team of experts to develop specific technical ransomware scenarios that could be used in the exercise.

We facilitated the construction of a detailed timeline for the exercises, detailing the specific ransomware scenarios identified. Each exercise would focus on a particular scenario, with time for problem-solving, identification of technical challenges, resolution of the issue, and capturing lessons learned and action items in a brief “hot wash” following the exercise.

The exercises were facilitated by the Bryghtpath team over a 2-3 hour session for each scenario. The multiple exercises were consolidated into a single after-action report detailing our observations and recommendations for improvement.

The after-action report and recommendations were used by technology leadership to further improve its response & recovery capabilities and justify investments in specific areas of improvement.

Key Activities

  • Review of current technical standard operating procedures (SOPs) for response & recovery
  • Review of current technical standards for backup & recovery
  • Review of current Disaster Recovery Plans
  • Planning sessions with an internal cross-functional team of subject matter experts

Outcomes

  • Successful completion of the exercise
  • Enhancements to technology response & recovery SOPs
  • Improvements to Disaster Recovery Plans
  • After-action report & 20+ recommendations adopted by the client

Download a PDF copy of this Case Study






We can help.

Let the experts at Bryghtpath put their decades of experience to work for your organization

We’ve designed, facilitated, and evaluated exercises for
Fortune 500 organizations around the world.

Our team has the experience, tools, and partnerships to help your organization successfully navigate the rough waters ahead – and ensure your organization is prepared.

I’D LIKE TO TALK TO BRYGHTPATH

Footer

Contact

BRYGHTPATH LLC
+1.612.235.6435

PO Box 131416
Saint Paul, MN 55113
USA


contact@bryghtpath.com

  • Facebook
  • LinkedIn
  • RSS
  • Twitter
  • YouTube

Our Capabilities

  • Business Continuity
    • Business Continuity as a Service (BCaaS)
    • Business Continuity Software
    • Coaching
    • IT Disaster Recovery Consulting Services
    • Resiliency Diagnosis®️
  • Crisis Communications
  • Crisis Management
    • Crisis Exercises
    • Cyber Crisis Exercises
    • Cyber Incident Response Planning
    • Global Security Operations Center (GSOC)
  • Speaking
  • Training

Our Free Courses

Business Continuity 101

Crisis Communications 101

Crisis Management 101

Our Products

After-Action Templates

Books

Business Continuity Plan Templates

Communications & Awareness Collateral Packages

Crisis Plan Templates

Crisis Playbook®

Disaster Recovery Templates

Exercise in a Box®

Exercise in a Day®

Maturity Models

Ready-Made Crisis Plans

Resilience Job Descriptions

Pre-made Processes & Templates

Site Footer

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.


Bryghtpath®, Crisis Management Academy®, Crisis Playbook®, Exercise in a Box®, Exercise in a Day®, Resiliency Diagnosis®, Resilience Operating Model®
and their respective logos are registered trademarks of Bryghtpath LLC in the United States and other countries.


About Bryghtpath LLC | Disclaimer | Privacy | Status Page | Terms of Use

Proudly powered by Mai Theme, the Genesis Framework, and Wordpress.