How to Run a One-Hour Ransomware Tabletop With Your Superintendent and Cabinet

Your district has five people in technology. The superintendent has one hour on the calendar between a facilities update and a parent advisory meeting. That is the entire budget for the most important security conversation you will have this year.

Do not spend it explaining what ransomware is. Spend it forcing the cabinet to make the decisions they will have to make at 6:40 a.m. on a Monday when the student information system is encrypted and the phones start ringing.

What the hour is actually for

A one-hour tabletop is not an incident response plan. It is not a compliance artifact. It is a decision-forcing exercise: a structured conversation that surfaces who decides what, what information is missing, and which gaps the tech team can close before the next school calendar milestone.

For a district of 1,000 to 10,000 students, the tech team already knows the technical shape of the problem. CISA describes ransomware as malware designed to encrypt files on a device, rendering files and the systems that rely on them unusable, with actors demanding ransom for decryption. CISA also notes that ransomware incidents can severely impact business processes and leave organizations without the data they need to operate and deliver mission-critical services. Your cabinet does not need a malware lecture. They need to practice the operational calls that only they can make.

The tradeoff is real: one hour is not enough to walk through a full incident timeline, and it is not enough to cover every system. That is fine. Pick the two or three decisions that would stall your response if the cabinet had not already talked about them.

Before the meeting: three things to prepare

1. A one-page scenario. Write it as a hypothetical, clearly labeled. Example: “It is Monday at 6:40 a.m. The help desk line is already ringing. The student information system will not load. Staff cannot log in to the gradebook. The network share where the business office keeps payroll files is inaccessible. A note on a printer in the central office says files will be released for payment.” Do not name a real vendor, a real attacker, or a real dollar figure. The point is the decisions, not the theatrics.

2. A role card for each seat at the table. Superintendent, cabinet lead (assistant superintendent or business manager), tech lead, communications lead, and legal or privacy lead. If your district does not have a dedicated legal or privacy lead, name the person who will call the district’s attorney and the person who will handle student data privacy questions. Write the role on an index card. Hand it to the person at the start of the hour.

3. A blank decision log. One column for the decision, one for who owns it, one for what information was missing. You will fill this in during the hour and use it in the debrief.

The minute-by-minute agenda

Minutes 0–5: Frame the hour. Read the scenario out loud. State the rules: no technical deep dives, no blaming, and every decision gets written down. Say plainly that this is a hypothetical and that the goal is to find gaps, not to predict the exact shape of a future attack.

Minutes 5–20: Immediate decisions. Ask the room: do we shut down network access district-wide, or keep some systems online? Who makes that call, and how quickly? If the student information system is down, do we cancel school, delay start, or run a paper day? Who tells principals, and through what channel? Write down every answer and every “we don’t know yet.”

Minutes 20–35: Communication and legal. Ask: who talks to families, and what do we say before we know the scope? Who talks to staff? Who calls the district’s attorney, and who calls the state education agency if student data is involved? The Future of Privacy Forum notes that education data, particularly student-generated data, are being collected and used, and that this raises concerns about how those data are collected and used. In a ransomware incident, those concerns become immediate: what student data was on the encrypted system, and what obligations follow? If your district has not mapped that, the hour will show you.

Minutes 35–50: Continuity and recovery priorities. Ask: what has to come back first — payroll, transportation routing, food service, gradebook, or email? Who decides the order? CISA advises maintaining offline, encrypted backups of data and regularly testing those backups, and regularly patching and updating software and operating systems. The cabinet does not need to configure backups. They need to know whether the district can restore the student information system from an offline copy, and how long that would take. If the answer is “we think so,” that is a gap worth writing down.

Minutes 50–60: Debrief and next steps. Read the decision log back. Ask three questions: what decisions did we make, what information was missing, and what will the tech team own before the next milestone on the school calendar? Keep the follow-up list to three items. A five-person team cannot close ten gaps in a month.

A hypothetical decision point to practice

Use this in the immediate-decisions block. It is invented for the exercise, not drawn from a real district.

“The tech team believes the encryption started on the central office file server and may have spread to the student information system. The network is still up. The business office needs payroll to run Wednesday. The gradebook is used daily by 400 teachers. Do you shut down the network now, or keep it up while you investigate? Who makes the call, and who do you tell first?”

Let the room argue for five minutes. Then write down the answer. The value is not the answer. The value is discovering that the superintendent and the tech lead have different assumptions about who can order a network shutdown.

What to do with the output

The debrief should produce a short list of tasks the tech team can realistically complete before the next school calendar milestone — a professional development day, a board meeting, the start of a grading period. Examples: confirm that offline backups exist and can be restored; write a one-page call tree for the first 30 minutes; identify who calls the district’s attorney and the state education agency; draft a holding statement for families that does not promise more than the district knows.

CISA advises that victims of ransomware report to federal law enforcement via IC3 or a Secret Service Field Office, and can request technical assistance or provide information to help others by contacting CISA. Put that on the call tree. It is a decision the superintendent should not be making for the first time during an incident.

What this hour will not do

It will not make your district compliant with any specific law or funding requirement. It will not replace a full incident response plan. It will not teach the cabinet how ransomware works. It will not cover every system in your district.

What it will do is give the superintendent and cabinet a shared vocabulary for the first hour of a real incident. For a five-person tech team, that shared vocabulary is worth more than another vulnerability scan.

Frequently asked questions

Should we invite principals? If your district has more than a handful of schools, no. The cabinet hour is for district-level decisions. Principals need a separate, shorter briefing on what they will be told and when.

What if the superintendent wants to skip it? Offer a 30-minute version: scenario framing, immediate decisions, and debrief. The tradeoff is that you lose the communication and continuity blocks. Something is better than nothing, but the communication block is where most districts find their biggest gaps.

Do we need a facilitator from outside the district? Not necessarily. The tech lead can facilitate, but someone else should take notes. If the tech lead is also the person who would be in the server room during a real incident, consider having the cabinet lead facilitate so the tech lead can participate in the decisions.

How often should we run this? Once a year is a reasonable minimum for a small district. Run it before the school year starts, or right after, so the follow-up tasks land before the first grading period. Do not run it in May.

What if we find out our backups are not tested? Write it down and fix it. CISA’s guidance is to maintain offline, encrypted backups and regularly test them. That is a task the tech team can own without cabinet involvement, and it is the single highest-value follow-up from the hour.