How it works
From your context to an evidence packet in one sitting.
Five concrete steps. You bring the people and the plan; ControlDrill tailors the scenario, runs the room, and hands back the record.
Step 01
Enter your context.
After purchase you complete a short intake: which exercise type to run, company, stack assumptions, people and roles, and the frameworks you may cite later (as citations, never as a grade). The intake baseline is enough to tailor a useful exercise even without uploading a document.
Six exercise types
Each unmet annual-test mandate is a gap until you run it. Many security and AI-governance policies mandate specific annual tabletops (IR plan test, BC/DR tabletop, DSAR-within-IR, AI-incident, AI-provider availability). ControlDrill runs the tabletop and produces the evidence. The BC/DR option does not replace a live failover or backup-restoration test.
Step 02
Optionally upload your IR or BCDR plan.
Paste plan text or attach PDF, Word (.docx), OpenDocument (.odt), .txt, or .md. Optional and high value: the tailor can cite your escalation matrix, RTO commitments, and named systems. PDF and Office files convert to text on the same platform that runs the app. Scanned or image-only PDFs may not extract cleanly; paste the text if that happens.
Your plan is never sent to an outside AI vendor. Reading and tailoring happen on the same platform that runs the app, with no third-party AI provider in the path. Used only to tailor your exercises, never to train models. Deleted on request; otherwise held under our stated retention policy (12 months from upload). See Privacy and DPA.
Step 03
We tailor a scenario
grounded in that reality.
Background prep builds a scenario for the exercise type you chose, with timed injects that name your systems, people, RTOs, and contractual clocks where the context supports it. Prep usually takes about a minute. If tailoring cannot complete, the exercise still runs on the solid base scenario for that type so you are not blocked.
At 02:14 your EDR flags encryption on prod-db-01 in us-east-1. Your Northwind MSA requires notification within 24h of confirmed exposure. Go.
Step 04
Run the timed live exercise
with your team.
Schedule a time and name participants. Everyone joins by personal magic link (no enterprise identity provider required). The shared view holds the clock and the current inject; each person answers in their own pane. The moderator drives phases, fires injects, and escalates on silence.
AI assists; it never makes the call for you. If live generation is briefly unavailable, prompts come from the prepared script. The clock, attribution, and record are unaffected.
Your EDR flags encryption on prod-db-01 in us-east-1. The Northwind MSA requires notification within 24h of confirmed exposure. Legal is asleep. Priya is on call.
Declaring SEV-1. Comms owner is Dana. Starting the 24h Northwind clock now.
prod-db-01 isolated. Snapshot taken before any restore path is touched.
Legal seat is empty. Nobody can confirm the notification threshold.
Step 05
Get the evidence packet
for your auditor.
When the session ends, ControlDrill builds a self-contained HTML evidence packet: attendance (including invited-but-absent), timeline of injects and decisions, gaps with remediation owners, and a control cross-reference as citations only. Your auditor judges the evidence.
The room
Who should attend.
- Incident commander
- The security lead who owns the exercise outcome.
- On-call engineering
- The people who would contain and recover systems.
- Communications
- Whoever would handle external messaging.
- Legal or privacy
- When notification clocks and classification matter. An empty Legal seat is itself a useful finding.
- Observers
- As needed. The record attributes participants who engage.
What you are buying.
We do not sell a compliance verdict. We sell the exercise and the record of it. A tabletop is a decision exercise; a technical disaster-recovery or failover test is a different thing you also need.