Blog
Blog
-
SOC 2 incident-response tabletops: what an auditor actually expects
What SOC 2 asks for on incident response readiness, what evidence looks like, and what a tabletop proves (and does not prove) when you hand the packet to an auditor.
-
How to run an annual AI-incident tabletop (and why your policy may now require one)
AI governance policies increasingly call for annual incident exercises. What an AI-incident tabletop covers, how to run one, and why it is not adversarial or pen testing.
-
A tabletop is not a DR test: what each one proves
Honest distinction between a BC/DR tabletop and a live failover or restore test: what each proves, where each helps, and why you still need both in a serious program.
ControlDrill records facilitated tabletop exercises and produces evidence. We never assert a compliance outcome. RSS