Below is a representative, clearly illustrative packet for a fictional
company (Northwind Systems). It is not a real customer record. Real packets are
self-contained HTML produced minutes after your session ends.
Illustrative example · fictional org, people, and findings
Incident-response tabletop · evidence record
IR Tabletop · Ransomware with data exfiltration
Exerciseex_sample_northwind OrgNorthwind Systems, Inc. (example) Duration58 minutes Present5 of 7 invited
Identity magic-link-authenticated session per participantOutput self-contained HTML evidence recordStatus illustrative sample only
01
Objectives & scope
Context
Example ransomware-with-exfiltration scenario tailored for a fictional SaaS org
with Tier-1 database prod-db-01 and a customer MSA
notification clock.
Out of scope
A tabletop is not a DR test and does not replace one.
This sample does not certify compliance for any organization.
SOC 2
ISO 27001:2022
PCI DSS
02
Attendance
Participant
Role
Status
Marcus T.example
Incident commander
●Present
Priya S.example
On-call engineering
●Present
Dana K.example
Security lead
●Present
Legal seatinvited
Legal / privacy
◯Invited but absent
No-shows are recorded honestly; an empty seat can be a finding.
03
What was exercised
+00:00
●
InjectDetection. EDR alert on prod-db-01 presented to the room.
moderator
+02:41
◆
DecisionSEV-1 declared; IC and comms owners assigned; 24h Northwind notification clock started.
by Marcus T. · confirmed by Dana K.
+04:12
◆
DecisionContainment: prod-db-01 isolated; volume snapshotted before restore path discussion.
by Priya S.
+06:33
▲
GapLegal not engaged. Data-exposure classification blocked; notification path stalled.
2 participants flagged · no owner present
+22:50
▲
GapRTO vs reality. Room could not confirm a restore path meeting the 4h Tier-1 RTO.
by Priya S. · confirmed by Wei L.
04
Gaps & remediation owners
▲High severityGAP-01
Legal escalation had no owner in the room.
Plan says
The escalation matrix names Legal as data-exposure decision owner within 1h.
Room did
Reach +06:33 with the role unfilled and the notification path stalled.
OwnerDana K. (Security Lead)ActionAdd named Legal backup + out-of-hours contact to escalation matrixDue2026-08-21
●Medium severityGAP-02
4h Tier-1 RTO could not be substantiated during the exercise.
Plan says
The DR plan commits to a 4h RTO for Tier-1 services.
Room did
No rehearsed restore path; the team could not confirm the commitment is currently
achievable.
OwnerWei L. (DevOps)ActionSchedule a restore rehearsal; record actual RTO against the 4h commitmentDue2026-09-04
05
Control cross-reference
Controls customers commonly cite this exercise toward, alongside what
was observed. Not a judgment about control fit. That determination belongs to your auditor.
Evidence for your auditor, not a compliance verdict.
Each row cites what the exercise surfaced against the control it may bear on.
The controls are listed as context, not as an assessment.
This report does not provide a grade of Tested, Partial, or Untested.Tested / Partial / Untestedwe do not grade controls
SOC 2
CC7.5
Recovers from identified incidents
Room could not substantiate the 4h Tier-1 RTO the DR plan commits to.
Recorded as GAP-02 with owner and remediation date.
Refs: timeline +22:50 · GAP-02 · Wei L.
Citation
ISO 27001:2022
A.5.24 to A.5.26
IR planning, assessment, and response
Escalation matrix exercised; a named-owner gap in the Legal path was
surfaced and assigned.
Refs: GAP-01 · Dana K. · timeline +06:33
Citation
Disclaimer
This sample is illustrative fiction for product education. A real
ControlDrill packet is evidence that an exercise occurred and what it found. It is not a
compliance attestation, certification, or legal or audit advice. It does not replace a
technical failover test.
Your real packet reports what your team did. Your auditor decides what it
proves.