Hospitals · ransomware readiness before the incident
Ransomware Readiness & Executive Tabletops for Hospitals, before the incident
A ransomware attack on a hospital is a patient-safety question, not just an IT one. We prepare the executive board, crisis team and CISO before the worst case: executive tabletops, IR playbooks, recovery prioritisation and reporting drills. We do not run an in-house SOC and we do not perform live incident response. We make you response-capable and connect you with your external IR provider and cyber insurer.
legally led (Dr. iur., CIPP/E)pre-incident, no SOC, no live IRDE · FR · EN
In a hospital, ransomware is a patient-safety topic
When systems go down, it is not first about data, but about the emergency department, OR scheduling, laboratory and medication. That is exactly why ransomware readiness belongs on the executive agenda, before anything happens.
Healthcare providers are among the most frequently affected by ransomware worldwide. Statistics show long downtimes, postponed procedures, patient diversions and ransom demands in the millions, and in many cases a recovery that takes weeks rather than days.
The most expensive mistake is inventing the response only once the incident hits. Anyone who has not rehearsed decision paths, escalation levels and recovery priorities in advance loses, in the first hours, exactly the time that determines patient safety and the scale of the damage.
We do not name specific affected hospitals. We work with anonymised scenarios based on real attack patterns and turn them into an exercise tailored to your organisation.
What we do before the incident, and what we don't
Our mandate is readiness, not deployment. We build the preparation that makes your crisis team capable in the worst case, and we are honest about the boundary of our scope.
We facilitate executive tabletop exercises for the board and crisis team in which a realistic ransomware scenario is played through: who decides what, when to escalate, when to report, how to communicate internally and to patients. From that we develop concrete IR playbooks, a recovery prioritisation of the clinically critical systems and reporting drills for the BACS 24h reporting duty.
Before the worst case we prepare interfaces and escalation paths to a named external IR provider and to your cyber insurer: contact chains, retainer templates, data-exchange routes and decision triggers are defined and tested in the exercise, so that nobody has to start from zero in an emergency.
Clearly delimited: SIDD does not operate a 24/7 SOC and does not perform live incident response. We do not coordinate the ongoing response during an incident and do not take on technical containment, forensics or live recovery. Those roles sit with your named IR provider. We ensure that the handover to them is prepared, rehearsed and contractually sound.
How a readiness mandate runs
1 · Readiness assessment
We capture your starting point: backup and recovery assumptions, clinically critical systems, existing plans, insurance and IR contracts, and reporting responsibilities.
2 · Scenario & playbooks
We design a tailored, anonymised attack scenario and create or sharpen your IR playbooks, escalation matrix and recovery prioritisation.
3 · Executive tabletop
We facilitate the exercise with the board and crisis team, including a BACS 24h reporting drill and a rehearsed handover to your external IR provider and insurer.
4 · Debrief & measures
You receive a board-ready debrief report with prioritised gaps, recommendations and a roadmap, as a basis for vCISO support or an ISMS.
Why SIDD for ransomware readiness
Readiness in a hospital is governance, law and technology at once. That is exactly the combination we bring, independent, because we do not sell an in-house SOC.
vCISO governance
Our vCISO service anchors ransomware readiness in your governance: roles, responsibilities, reporting lines to the board and an exercise and maintenance rhythm, so playbooks do not go stale in a drawer.
Swiss confidentiality
Where a SIDD lawyer advises in a legal capacity, your information may be covered by professional secrecy under Art. 321 of the Swiss Criminal Code, valuable when sensitive weaknesses and incident assumptions must be analysed openly. We clarify the exact scope per mandate.
Validate recovery assumptions
With penetration tests and vulnerability scans we check whether your recovery assumptions hold: are backups truly isolated and restorable, are critical paths segmented, does the architecture withstand the scenario. This keeps the tabletop from becoming wishful thinking.
Bridge to ISO 27001 / ISMS
Readiness is not a one-off: we embed exercises, playbooks and lessons learned into an ISO 27001-aligned ISMS, with audit-ready evidence that holds up in audits and regulator requests.
Legally led
Reporting duties, the data-protection consequences of a data exfiltration, contracts with IR provider and insurer, board responsibility, all of that is first a legal question. Our mandate is led by doctorate-level lawyers with CIPP/E, backed by an in-house technical team.
Multilingual & independent
We facilitate tabletops in German, French and English, relevant for French-speaking Switzerland, cantonal hospital groups and EU parent companies. Because we do not sell an in-house SOC or IR mandates, our recommendation on providers and insurers stays independent.
Ransomware tabletop & readiness assessment
Executive ransomware tabletop
Fixed fee
A facilitated crisis simulation for the board and crisis team, before the incident, in a single day.
Tailored, anonymised ransomware scenario
Facilitated exercise with board and crisis team
BACS 24h reporting drill played through
Rehearsed handover to external IR provider and insurer
Board-ready debrief report with prioritised measures
Readiness assessment & playbooks
Fixed fee
The solid groundwork: baseline assessment, playbooks and recovery prioritisation as the basis for the tabletop.
Baseline assessment of ransomware readiness
IR playbooks and escalation matrix created or sharpened
Recovery prioritisation of clinically critical systems
Prepared interfaces to IR provider and cyber insurer
Optional validation with pentest and vulnerability scan
Ongoing vCISO support
on request
Readiness as a continuous task: recurring exercises, maintained playbooks and reporting to the board.
Annual exercise and maintenance rhythm for playbooks
Embedding into an ISO 27001-aligned ISMS
Reporting and risk posture for the board
Support of IT-security workshops for staff
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the BACS 24h reporting drill and the IR playbooks, concretely: LexCommand backs reporting duty, threshold and deadline with the version of the Swiss and EU rules valid on the reference date and an exact source for each, so your escalation matrix rests on verifiable obligations rather than assumptions.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Are you a 24/7 SOC or do you perform live incident response?
No. SIDD does not operate a 24/7 SOC and does not perform live incident response. We work exclusively before the incident: readiness assessment, executive tabletops, IR playbooks, recovery prioritisation and reporting drills. In an emergency, containment, forensics and recovery sit with your named external IR provider. We prepare the interfaces and escalation paths to them and to your cyber insurer in advance and rehearse the handover.
What exactly is an executive tabletop?
A facilitated crisis simulation at the table: with your board and crisis team we play through a realistic ransomware scenario and make real-time decisions on escalation, reporting, communication and recovery. No real code is involved and nothing is changed on your systems. What is exercised is decision paths, roles and collaboration.
Do you make the BACS report for us in an emergency?
We prepare and rehearse the 24-hour report: we clarify who is obliged to report, which threshold applies, what content is required and who in your organisation owns the report, and we provide templates. The actual report in an emergency is your responsibility or that of your mandated provider. We make you capable of it. We verify exact thresholds and deadlines case by case.
Who is the tabletop for?
For hospital CISOs and IT leads, crisis teams, executive boards, cantonal hospital groups and nursing homes, wherever a system outage endangers patient care. We adapt scenario, participants and depth to your size and maturity.
Can you test our backup and recovery assumptions?
Yes, optionally. With penetration tests and vulnerability scans we check whether backups are isolated and restorable, whether critical paths are segmented and whether the architecture withstands the scenario. This way the tabletop rests on robust assumptions rather than hope.
Prepare your hospital, before it gets serious
We start with a readiness assessment and an executive tabletop at a fixed fee, with a board-ready report and prioritised measures.