Below is a representative, clearly illustrative packet for a fictional
company (Northwind Systems). It is not a real customer record. Real packets are
self-contained HTML produced minutes after your session ends.
Illustrative example · fictional org, people, and findings
Incident-response tabletop · evidence record
IR Tabletop · Ransomware with data exfiltration
Exerciseex_sample_northwind OrgNorthwind Systems, Inc. (example) Duration58 minutes Present5 of 7 invited
Identity magic-link-authenticated session per participantOutput self-contained HTML evidence recordStatus illustrative sample only
01
Objectives & scope
Context
Example ransomware-with-exfiltration scenario tailored for a fictional SaaS org
with Tier-1 database prod-db-01 and a customer MSA
notification clock.
Out of scope
A tabletop is not a DR test and does not replace one.
This sample does not certify compliance for any organization.
SOC 2
ISO 27001:2022
PCI DSS
02
Attendance
Participant
Role
Status
Marcus T.example
Incident commander
●Present
Priya S.example
On-call engineering
●Present
Dana K.example
Security lead
●Present
Legal seatinvited
Legal / privacy
◯Invited but absent
No-shows are recorded honestly; an empty seat can be a finding.
03
What was exercised
+00:00
●
InjectDetection. EDR alert on prod-db-01 presented to the room.
moderator
+02:41
◆
DecisionSEV-1 declared; IC and comms owners assigned; 24h Northwind notification clock started.
by Marcus T. · confirmed by Dana K.
+04:12
◆
DecisionContainment: prod-db-01 isolated; volume snapshotted before restore path discussion.
by Priya S.
+06:33
▲
GapLegal not engaged. Data-exposure classification blocked; notification path stalled.
2 participants flagged · no owner present
+22:50
▲
GapRTO vs reality. Room could not confirm a restore path meeting the 4h Tier-1 RTO.
by Priya S. · confirmed by Wei L.
04
Gaps & remediation owners
▲High severityGAP-01
Legal escalation had no owner in the room.
Plan says the escalation matrix names Legal as data-exposure
decision owner within 1h.
Room did reach +06:33 with the role unfilled and the
notification path stalled.
OwnerDana K. (Security Lead)ActionAdd named Legal backup + out-of-hours contact to escalation matrixDue2026-08-21
●Medium severityGAP-02
4h Tier-1 RTO could not be substantiated during the exercise.
Plan says the DR plan commits to a 4h RTO for Tier-1 services.
Room did find no rehearsed restore path; the team could not
confirm the commitment is currently achievable.
OwnerWei L. (DevOps)ActionSchedule a restore rehearsal; record actual RTO against the 4h commitmentDue2026-09-04
05
Control cross-reference
Controls customers commonly cite this exercise toward, alongside what
was observed. Not a judgment about control fit. That determination belongs to your auditor.
Evidence for your auditor, not a compliance verdict.
Each row cites what the exercise surfaced against the control it may bear on.
We do not test, pass, or score controls.
This report does not provide a grade of Tested, Partial, or Untested.Tested / Partial / Untestedwe do not grade controls
SOC 2
CC7.5
Recovers from identified incidents
Room could not substantiate the 4h Tier-1 RTO the DR plan commits to.
Recorded as GAP-02 with owner and remediation date.
Refs: timeline +22:50 · GAP-02 · Wei L.
Citation
ISO 27001:2022
A.5.24 to A.5.26
IR planning, assessment, and response
Escalation matrix exercised; a named-owner gap in the Legal path was
surfaced and assigned.
Refs: GAP-01 · Dana K. · timeline +06:33
Citation
Disclaimer
This sample is illustrative fiction for product education. A real
ControlDrill packet is evidence that an exercise occurred and what it found. It is not a
compliance attestation, certification, or legal or audit advice. It does not replace a
technical failover test.
We do not sell a compliance verdict. Your real packet reports what your
team did. Your auditor decides what it proves.