Free, no signup
Write up the incident.
The review is where an incident either teaches you something or quietly becomes a story you tell yourself. This asks for the parts that get skipped, explains why each one matters, and hands back a formatted record. Nothing is uploaded, which matters when the honest version is unflattering.
This produces a self-reported record and says so on the artifact. It reports what happened; it is not an assessment, and it does not state that any control worked. Your auditor or your customer decides what it is worth.
Preview
What downloads.
Common mistakes
What to leave out.
These get added by people trying to be thorough, and each one makes the record weaker.
- A single root cause
- Complex systems fail for several reasons at once. Naming one cause means the search stopped at the first plausible answer, and the factors you did not look for are still in production.
- A person as the cause
- If the answer is that someone made a mistake, the real finding is the system that let a single mistake reach customers. Naming the person also guarantees the next person delays raising an incident.
- Speculation about an attacker
- Motive and identity are almost never determinable from your own logs, and a guess written down here will be quoted back to you as a finding. Record what you observed.
- Customer data or credentials
- Reviews get circulated far more widely than the incident channel did, including to auditors and customers. Reference the affected records, never their contents.
- A verdict on your own compliance
- Whether this satisfies a control is not your call to record. State the facts and let the person assessing you weigh them.
The limits of a write-up
Two things this record cannot honestly claim.
These are left visibly empty in the download rather than quietly dropped, because a record that hides what it is missing is worse than one that admits it.
- What responders believed at the time
- Once you know the answer, the reasons a wrong decision looked right at 09:41 are almost impossible to recover. Unless someone wrote it down live, treat any account of it as shaped by hindsight.
- Time spent on the wrong hypothesis
- Usually the largest single block of the response, and almost never logged, because nobody timestamps a theory while they are still testing it.
Where this stops
The gap this review keeps finding.
Almost every review lands on the same two actions: a missing alert, and a decision path nobody had walked before. The first is monitoring work. The second is what a tabletop is for, and it is cheaper to find the unwalked path in an exercise than in a real 09:02. ControlDrill runs that exercise on your systems and your plan, and the record is written by the time you finish, with every decision already attributed.