Ransomware attack simulation
A ransomware simulation shows how far a ransomware group would get in your network and whether anyone would stop it. Over 2-4 weeks we go after the same systems real attackers target, but the only files we encrypt are test files prepared for the exercise. Afterward you know whether EDR responded, whether the SOC got an alert and whether your data can be restored from backups.
- Reaching the domain controller, backups and virtualization without encrypting your data
- Controlled encryption of test files to see how EDR and the SOC respond
- Testing backup restores and incident response (IR) readiness
What is a ransomware simulation
A ransomware simulation is a controlled attack in which we replay what a ransomware group does, up to the moment real attackers would start encrypting data. We check whether we can reach the systems your whole company depends on: the domain controller, backups and the virtualization platform. Instead of your data, we encrypt test files on designated hosts to see whether EDR and the SOC respond. We also test restoring your data from backups. CERT Polska recorded 179 ransomware incidents in Poland in 2025, up from 147 the year before. The simulation shows how an incident like that would play out at your company.
When to order a ransomware simulation
- You have EDR or a SOC and want to know whether they respond before someone encrypts your servers
- You back up regularly, but nobody has checked lately whether you could restore your data after an attack
- You have an incident response plan and want to test it in practice, not just on paper
- Your board asks whether the company would recover from a ransomware attack, and you want to answer with test results, not assumptions
If you are looking for a tabletop exercise, this isn't it: we run a ransomware simulation on your systems. If you haven't had penetration tests yet, start with those or with an assumed breach test. In a network where known gaps are still open, a simulation will mostly show what a regular pentest would already have found.
What a ransomware simulation covers
In one operation we test the attack itself and what happens after it. We start either from an agreed point inside your network or from outside, with an attempt to get in. You pick the option closer to your risk. Targets, the hosts for test-file encryption and scope exclusions are agreed before we start.
Reaching ransomware targets
We check whether an attacker can reach the systems ransomware groups go after: the domain controller, backups and the virtualization platform. If we reach a target, we show that access was possible and stop there. We don't encrypt your data.
Controlled encryption of test files
On hosts designated before the start we encrypt test files prepared for the simulation. We check whether EDR blocks the encryption and whether, and when, the SOC gets an alert.
Backup restore and IR readiness
We test whether data can be restored from backups and whether your incident response team knows what to do. You see what works in practice and what exists only in a written procedure. We deliver the results of this part separately, in a standalone document or at a workshop.
How we work together
Scoping call and quote
In a 30-minute call we agree what the simulation should test, which systems matter most to you and what is off limits. You get the scope of work and a quote within 2 business days.
Authorization and rules of engagement
We sign a written authorization and rules of engagement (RoE). We agree on the control team on your side, stop conditions, scope exclusions and the hosts where we will encrypt test files.
The simulation
We try to reach the domain controller, backups and virtualization, encrypt test files on the designated hosts and test backup restores and IR readiness. The control team knows about the operation and can stop it.
Report and workshop
You get a report tailored to your company. We walk your blue team through it in a workshop, step by step, and show every moment when we could have been detected.
Retest after fixes
Once you apply the fixes, we come back and check that they work. One retest is included in the price of the simulation.
Safeguards
- A control team on your side knows about the simulation and can stop it
- Stop conditions and systems excluded from scope are agreed before the start
- We encrypt only test files on designated hosts, never your data
- Every simulation starts with written authorization and signed rules of engagement (RoE)
What you get after the simulation
- A timeline of the attack with the points where the attacker could have been detected
- A MITRE ATT&CK map of the operation showing what your defenses caught
- SIEM and EDR recommendations to help you detect the attacker earlier next time
- A workshop with your blue team, plus one retest after the fixes, included in the price
Frequently asked questions
How is a ransomware simulation different from a tabletop exercise?
A tabletop exercise is a discussion around a table about what your team would do during an attack. A ransomware simulation is a test on your systems. We check whether an attacker reaches the domain controller, backups and virtualization, whether EDR and the SOC respond to test-file encryption and whether data can be restored from backups.
Do you encrypt my data during a ransomware simulation?
No. Even if we reach the domain controller, backups or virtualization, we don't encrypt anything there. In a ransomware simulation we encrypt only test files on hosts designated before the start. That is enough to see whether EDR blocks the encryption and whether the SOC gets an alert.
How long does a ransomware simulation take?
A ransomware simulation usually takes 2-4 weeks. The exact length depends on the scope we agree at the start. For comparison, a typical red team operation takes 4-8 weeks. Once you apply the fixes from the report, we come back for one retest, included in the price.
Is a ransomware simulation safe for production systems?
Yes, because we work only within limits agreed before the start. The simulation runs under written authorization and rules of engagement (RoE). A control team on your side knows about it and can stop it. Systems that must not be touched are excluded from scope, and we encrypt only test files on designated hosts.
How much does a ransomware simulation cost?
The cost of a ransomware simulation depends on scope: the size of your environment, the number of targets and hosts covered and the length of the operation. That is why we don't publish a price list. After a 30-minute call we send the scope of work and a quote within 2 business days.
What do I get after a ransomware simulation?
After a ransomware simulation you get a report tailored to your company: an attack timeline showing where the attacker could have been detected, a MITRE ATT&CK map and SIEM and EDR recommendations. We go through it in a workshop with your security team. Backup restore and IR readiness results are delivered separately. Once you apply the fixes, we come back for one retest, included in the price.
Will my SOC and IT team know about the ransomware simulation?
That's up to you. In a covert simulation only the control team knows, so you see how your SOC and IT really respond. In an overt one the teams know about it, and we check whether EDR, backups and procedures work the way you expect. We pick the option together with the scope.
See how far a ransomware attack would get in your network
Tell us about your environment. After a 30-minute call we'll send the simulation scope and a quote within 2 business days.
Book a call about a ransomware simulation