Skip to content
Buy an exerciseBuy

Sample evidence packet

What you hand your auditor.

Below is a representative, clearly illustrative packet for a fictional company (Northwind Systems). It is not a real customer record. Real packets are self-contained HTML produced minutes after your session ends.

Illustrative example · fictional org, people, and findings

Incident-response tabletop · evidence record

IR Tabletop · Ransomware with data exfiltration

Exercise ex_sample_northwind
Org Northwind Systems, Inc. (example)
Duration 58 minutes
Present 5 of 7 invited
Identity magic-link-authenticated session per participant Output self-contained HTML evidence record Status illustrative sample only
01

Objectives & scope

Context

Example ransomware-with-exfiltration scenario tailored for a fictional SaaS org with Tier-1 database prod-db-01 and a customer MSA notification clock.

Out of scope

  • A tabletop is not a DR test and does not replace one.
  • This sample does not certify compliance for any organization.
  • SOC 2
  • ISO 27001:2022
  • PCI DSS
02

Attendance

ParticipantRoleStatus
Marcus T.example Incident commander Present
Priya S.example On-call engineering Present
Dana K.example Security lead Present
Legal seatinvited Legal / privacy Invited but absent

No-shows are recorded honestly; an empty seat can be a finding.

03

What was exercised

+00:00
Inject Detection. EDR alert on prod-db-01 presented to the room. moderator
+02:41
Decision SEV-1 declared; IC and comms owners assigned; 24h Northwind notification clock started. by Marcus T. · confirmed by Dana K.
+04:12
Decision Containment: prod-db-01 isolated; volume snapshotted before restore path discussion. by Priya S.
+06:33
Gap Legal not engaged. Data-exposure classification blocked; notification path stalled. 2 participants flagged · no owner present
+22:50
Gap RTO vs reality. Room could not confirm a restore path meeting the 4h Tier-1 RTO. by Priya S. · confirmed by Wei L.
04

Gaps & remediation owners

High severityGAP-01

Legal escalation had no owner in the room.

Plan says

The escalation matrix names Legal as data-exposure decision owner within 1h.

Room did

Reach +06:33 with the role unfilled and the notification path stalled.

OwnerDana K. (Security Lead) ActionAdd named Legal backup + out-of-hours contact to escalation matrix Due2026-08-21
Medium severityGAP-02

4h Tier-1 RTO could not be substantiated during the exercise.

Plan says

The DR plan commits to a 4h RTO for Tier-1 services.

Room did

No rehearsed restore path; the team could not confirm the commitment is currently achievable.

OwnerWei L. (DevOps) ActionSchedule a restore rehearsal; record actual RTO against the 4h commitment Due2026-09-04
05

Control cross-reference

Controls customers commonly cite this exercise toward, alongside what was observed. Not a judgment about control fit. That determination belongs to your auditor.

Evidence for your auditor, not a compliance verdict.

Each row cites what the exercise surfaced against the control it may bear on. The controls are listed as context, not as an assessment.

This report does not provide a grade of Tested, Partial, or Untested. we do not grade controls
SOC 2
CC7.5
Recovers from identified incidents
Room could not substantiate the 4h Tier-1 RTO the DR plan commits to. Recorded as GAP-02 with owner and remediation date. Refs: timeline +22:50 · GAP-02 · Wei L.
Citation
ISO 27001:2022
A.5.24 to A.5.26
IR planning, assessment, and response
Escalation matrix exercised; a named-owner gap in the Legal path was surfaced and assigned. Refs: GAP-01 · Dana K. · timeline +06:33
Citation
Disclaimer

This sample is illustrative fiction for product education. A real ControlDrill packet is evidence that an exercise occurred and what it found. It is not a compliance attestation, certification, or legal or audit advice. It does not replace a technical failover test.

Your real packet reports what your team did. Your auditor decides what it proves.