๐Ÿงฉ TTX

๐Ÿงฉ Ransomware

PLANNED
2026-07-30 ยท Facilitator: BW ยท Scenario: Ransomware Attack on City Government

๐Ÿ“‹ Scenario Overview

A sophisticated ransomware attack (PLAY ransomware group) has infiltrated the City of Georgetown's municipal network through a phishing campaign targeting the finance department. The attack encrypts critical servers including tax databases, utility billing systems, permit management, and emergency services dispatch. The ransomware group exfiltrated 2TB of sensitive citizen data before encryption and is now demanding M in Monero. City employees are locked out of email, file shares, and all line-o...

Read full scenario โ†’

๐ŸŽฏ Objectives

  1. Identify all affected systems and determine the scope of the ransomware infection using incident response procedures
  2. Map the attack lifecycle using MITRE ATT&CK to understand the full kill chain from initial access to impact
  3. Determine whether to pay the ransom and establish a decision-making framework for ransom negotiations
  4. Contain the outbreak by isolating affected network segments while maintaining essential city services
  5. Develop a recovery plan prioritizing critical citizen services (emergency dispatch, water, power)
  6. Manage public communication and media relations to maintain citizen trust and provide accurate information
  7. Coordinate with law enforcement (FBI, CISA, Secret Service) for threat intelligence and legal proceedings
  8. Implement enhanced security controls based on MITRE ATT&CK gaps identified during the exercise

๐Ÿ“‹ Exercise Modules

Module 1: MODULE 1: Initial Detection & Triage (15 min) โ€” Assess the alert, determine scope, activate IR team, engage external IR firm
00:00
Module 2: MODULE 2: MITRE ATT&CK Mapping & Analysis (20 min) โ€” Map full attack chain to MITRE ATT&CK, identify security gaps, prioritize containment
00:00
Module 3: MODULE 3: Containment & Eradication (20 min) โ€” Isolate network segments, preserve evidence, remove threat actor access, block C2 infrastructure
00:00
Module 4: MODULE 4: Ransom Decision & Stakeholder Communication (20 min) โ€” Ransom payment decision, legal consultation, public communication strategy
00:00
Module 5: MODULE 5: Recovery & Restoration (15 min) โ€” Prioritize system recovery, validate backups, restore from clean backups, implement security improvements
00:00

๐Ÿ’ฌ Discussion Questions

๐Ÿ“š References

โ† All Exercises