Skip to content
Buy an exerciseBuy

Free, no signup

Write up your tabletop.

You ran the exercise. The part that counts as evidence is the write-up, and it is the part everyone puts off. Fill this in and download a formatted record you can hand to an auditor. Nothing is uploaded, which matters when what you are typing is an honest account of a bad hour.

What you get is a self-reported record, and it says so on the artifact. That is the honest description of anything written up afterwards, and it is the difference between this and a record captured while the room was running.

The record

What happened.

How to fill this in

Use the actual calendar date the exercise ran. If it ran across two sessions, record the date of each and say so in scope.

Strong
2026-08-19
Weak
Q3 2026

Why the weak one costs you. A quarter is not a date. Annual-testing criteria ask whether a test happened inside a period, and a vague date invites the assessor to ask for the calendar invite, the attendance, and the notes to establish it. Being precise here removes an entire round of questions.

How to fill this in

Name the incident type in plain words. If the exercise was tailored to your environment, say what it touched.

Strong
Ransomware with data exfiltration affecting the Tier 1 customer database
Weak
Security incident

Why the weak one costs you. A generic title cannot be matched to a risk. If your risk register lists ransomware and your exercise says "security incident", nobody can connect them, and the exercise stops being evidence for the risk you actually care about.

How to fill this in

Two or three sentences. Say what the exercise covered, and name at least one thing it deliberately did not.

Strong
Covered detection, severity declaration, containment decisions and customer notification for an encryption event on prod-db-01. Did not include a live restore from backup, and does not evidence that recovery works.
Weak
We tested our incident response process end to end.

Why the weak one costs you. Claiming "end to end" invites the question of whether you tested recovery, and a discussion exercise never does. Stating the limit yourself is the stronger position: it shows you know where the boundary is, and it stops an assessor discovering it and wondering what else was overstated.

How to fill this in

Name each person and their role in the exercise. Record absences honestly, including seats you expected to fill and could not.

Strong
Priya S. | On-call engineering | present
Dana K. | Legal and privacy | absent, no cover
Weak
The security team attended.

Why the weak one costs you. An assessor is checking whether the people who would actually respond took part. A team name proves nothing. And an empty seat is a finding, not an embarrassment: an exercise that discovers Legal is unreachable at 3am has done its job, while a record that hides it is one an assessor may stop trusting elsewhere.

How to fill this in

One line per moment that mattered, with elapsed or clock time. Include the decisions, not just the events.

Strong
02:14 | EDR flagged encryption on prod-db-01; Marcus declared Sev 1 on that evidence
02:41 | Priya chose to snapshot before isolating, accepting the containment delay
Weak
Discussed containment options and agreed next steps.

Why the weak one costs you. Timings are what separate a rehearsal from a meeting. They also let an assessor see how long a decision took, which is often the real finding. Naming who decided is what makes it attributable; a record where every decision is passive was probably written from memory.

How to fill this in

Use the shape: what the plan says, what the room actually did, who owns fixing it, by when. If nothing was found, say why you believe that rather than leaving it blank.

Strong
Plan names Legal as data-exposure owner within 1h; room reached 6h33 with the seat unfilled | Dana K. | 2026-09-30
Weak
Communication could be improved.

Why the weak one costs you. A gap with no expectation, no observation, no owner and no date is a sentiment. "Plan says, room did" is the strongest available format because it compares your own documented commitment against what happened, which is exactly the comparison an assessor is trying to make and usually cannot. Give it to them already made.

Generated in your browser. Nothing is sent anywhere and there is nothing to sign up for.

Preview

What downloads.

Common mistakes

What to leave out.

These get added by people trying to be thorough, and each one makes the record weaker.

Blame
Name roles and decisions, not fault. A record people fear appearing in is a record that gets sanitised next year, and the sanitised version is worthless.
Speculation about a real incident
Keep the exercise fictional and say so. Written guesses about a live or past incident can be discoverable, and your counsel will not thank you.
Customer data or live credentials
Use a fictional org and placeholder systems where you can. The record is a document that gets emailed to auditors.
A verdict
Do not write "we passed" or "control satisfied". You are not the assessor, and asserting the conclusion is the fastest way to have every other line scrutinised.

The limits of a write-up

Two things you cannot reconstruct.

These are left visibly empty in the download rather than quietly dropped, because a record that hides what it is missing is worse than one that admits it.

Attributed contributions
Who said what, when, in their own words. Reconstructing this from memory is how a write-up becomes fiction, so this builder does not ask you to try.
Silence and latency findings
Who did not speak on an inject, and how long a decision took. This is measured while the room is running or not at all.

Where this stops

Two things you cannot write down afterwards.

Attributed contributions and decision latency are measured while the room is running or not at all. That is the whole difference between writing up an exercise and having one instrumented: ControlDrill is in the room, so the record is written by the time you finish, and every answer is already attributed to the person who gave it.