ControlDrill

Incident-response tabletops

Run an incident drill your auditor will believe.

ControlDrill facilitates a real incident-response tabletop end to end: a scenario built for your context, timed injects, the decisions your team actually made, a remediation list, and an evidence packet you can hand to an auditor. One flat price. No security-sales call. No week of setup.

$299 per exercise

Why a tabletop, and why the evidence matters

Nearly every security framework expects you to test your incident response, not just write a plan and file it. Most teams do one of two things: skip it, or hold a vague meeting that leaves no record. Then an auditor asks for evidence that you actually ran an exercise, and "we talked about it once" is not evidence.

ControlDrill gives you the exercise and the receipt. The point is not to survive a real breach in the room; it is to rehearse the decisions, find the gaps while it is cheap, and walk out with a timestamped record that a plan on a shelf can never produce.

What you get

A scenario, not a template

A ransomware or exfiltration scenario tailored to your stack, with injects that escalate on a timer.

Facilitation that keeps moving

The exercise is guided so the room stays in the scenario instead of stalling. AI assists; it is never required to make a call for you.

Recorded decisions

Every decision, owner, and timestamp is captured as it happens, not reconstructed from memory afterward.

An evidence packet

A clean export of what happened, what was decided, and what to fix, with a control cross-reference. The artifact an auditor asks for.

How it works

  1. Buy the exercise. One flat $299, no call required.
  2. Schedule and invite. Pick a time, name your participants and roles. Everyone gets a personal join link.
  3. Run the drill. Work the scenario and injects together while decisions are recorded live.
  4. Take the evidence. Download the packet and the remediation list.

Inside the exercise

Frameworks this exercise speaks to

SOC 2 CC7.4 / CC7.5 ISO 27001 A.5.24 to A.5.27 PCI DSS 12.10.x HIPAA 164.308(a)(6)

An incident-response exercise is a named expectation in each of these. ControlDrill produces the exercise and the evidence and cross-references it to the relevant controls. Frameworks are the trigger that brings people in; the exercise quality is the product.

Compared to the alternatives

Skip it / ad-hoc meetingConsultant-led tabletopControlDrill
PriceFree, but no evidenceThousands, plus weeks to book$299 flat
When you can run itWhenever, if everScheduled weeks outNow, self-serve
Evidence producedNoneSlides, eventuallyPacket in minutes
Run it again next quarterSame frictionPay againBuy another anytime

Who it is for

Questions

How long does it take?

A focused session, not a day off site. You schedule the time; the facilitation keeps it moving so it does not sprawl.

Is this a real failover or DR test?

No. It is a tabletop: a structured walkthrough of decisions under a scenario. It does not replace live failover or disaster-recovery testing, and we never imply it does.

Do you promise compliance?

No. We produce the exercise and the evidence of it. Whether that satisfies a given control is between you and your auditor. Facts, not a pass.

What exactly do I hand my auditor?

An evidence packet: the scenario, the timed decisions and owners, the remediation list, and a control cross-reference, exported minutes after the session.

Can I run it for my clients?

Yes. vCISOs and MSPs use ControlDrill to deliver exercises without building or scheduling each one from scratch.

We do not sell a compliance verdict. ControlDrill produces the exercise and the evidence of it. Whether that satisfies a given control is between you and your auditor. We report facts, not a pass.
Buy an exercise