Scenario library
Tabletop exercise scenarios we actually run.
These are the six scenario families ControlDrill runs, not a generic list. Each one is tailored to your systems, people, and incident response plan before the exercise starts, so the injects name your hosts, your recovery objectives, and your contractual clocks rather than "a server" and "a vendor".
The six families
-
Ransomware with data exfiltration
Classic IR tabletop: encryption plus possible customer-data exfiltration from detection through recovery.
-
Business email compromise and wire fraud
Finance-oriented IR tabletop: vendor bank-detail change, CEO-impersonation wire, recall race, and mailbox compromise.
-
Cloud credential compromise
Identity-focused IR tabletop: leaked long-lived cloud key, blast radius, and containment versus availability.
-
Data subject rights under incident conditions
DSAR surge under pressure, including when a rights request collides with a possible exposure claim.
-
AI incident
In-product assistant cross-tenant disclosure via prompt injection: safety, security, and disclosure decisions.
-
Business continuity: regional outage (tabletop)
Facilitated BC/DR tabletop for a regional cloud outage plus AI-provider degradation. Tabletop, not a live failover test.
What a scenario proves
That your team can make and record decisions against a realistic incident: who took part, what they decided, and when. Running one does not by itself satisfy a control, and proving recovery works is a separate exercise you also need. Your auditor weighs the evidence.
Run one and keep the evidence
Pick a family, give us your context, and run a live exercise with your team. You leave with an attributed evidence packet for $199.