Skip it / ad-hoc meeting
- Price
- Free, but no evidence
- Grounded in your plan
- Maybe, if someone brings it
- When you can run it
- Whenever, if ever
- Evidence produced
- None
- Grades your controls
- n/a
Tailored incident-response tabletops
The exercise cites your systems, people, and plan. Generic tabletops talk about "a server" and "a vendor." ControlDrill names your hosts, RTOs, and contractual clocks. Your team decides under a live timer. You leave with an attributed evidence packet, not a slide deck written later.
$299 flat. Self-serve. No sales call.
AI assists; it never makes the call for you.
Illustrative example · fictional org and plan
At 02:14 your EDR flags encryption on prod-db-01 in us-east-1. Your Northwind MSA requires notification within 24h of confirmed exposure. Legal is asleep. Priya is on call. Go.
Tailored from your IR plan v4 · cites prod-db-01, 4h RTO, Northwind MSA
What a consultant, a skip-it meeting, and ControlDrill actually deliver.
| Skip it / ad-hoc meeting | Consultant-led tabletop | ControlDrill | |
|---|---|---|---|
| Price | Free, but no evidence | Thousands, plus weeks to book | $299 flat |
| Grounded in your plan | Maybe, if someone brings it | If the facilitator reads it | Intake + optional plan upload |
| When you can run it | Whenever, if ever | Scheduled weeks out | Now, self-serve |
| Evidence produced | None | Slides, eventually | Packet in minutes |
| Grades your controls | n/a | Sometimes over-claims | Never (deliberate) |
Competitors ship a scenario library and a chatbot. ControlDrill cites the reality you already documented: systems, people on call, recovery targets, and notification obligations.
Enter baseline context in intake. Optionally upload your plan (PDF, Word, .txt, .md, or paste). We tailor so the room hears your commitments back (the hero shows one resulting inject).
What we ground the exercise in
Every inject names your reality: the real host, the person on call, the clock in your contract. Nothing generic.
Minutes after the session ends you get a self-contained HTML evidence record: attendance, timed decisions, gaps with owners, and framework citations as context only.
Where the plan said one thing and the room did another, the packet says so.
Illustrative gap finding · fictional session
Legal escalation had no owner in the room.
Plan says the escalation matrix names Legal as data-exposure decision owner within 1h. Room did reach +06:33 with the role unfilled and the notification path stalled.
You are uploading incident-response material. A security buyer needs the data story up front, not buried in a subprocessor list.
Reading and tailoring happen on the same platform that runs the app. Your plan is never shipped to a third-party AI provider.
Not shared across customers. Never used to train models, ours or anyone else's.
Delete removes your uploaded plan and its extracted text for that purchase. Otherwise held under our stated retention policy (12 months from upload).
We produce the exercise and the evidence of it. A tabletop is not a technical failover or DR test, and we never imply it is.
One flat exercise: tailored scenario, live facilitation, attributed decisions, and the packet an auditor asks for.
Systems, people, RTOs, vendors, and plan language flow into injects that feel like your incident, not a template.
Server-side clock, timed injects, role-targeted prompts. AI assists the moderator; if live generation drops, the prepared script keeps the clock and record going.
Typed, authenticated contributions tied to the inject. Every decision, owner, and timestamp captured as it happens.
Attendance, timeline, gaps, remediation owners, and control cross-references as citations. No fake grade.
An incident-response exercise is a named expectation in each of these. ControlDrill produces the exercise and the evidence and cross-references relevant controls as citations. Frameworks are context for your auditor; they are never a grade from us.
SOC 2 or ISO 27001 in progress. Run a real exercise with evidence, not a meeting invite and a vague write-up.
Client tabletops without the overhead. Deliver credible exercises without building material or booking a facilitator each time.
Find response gaps while it is cheap. See how the team actually responds before anyone is paging you for real.
No. We produce the exercise and the evidence of it. Whether that satisfies a given control is between you and your auditor. Facts, not a pass.
No. It is a tabletop: a structured walkthrough of decisions under a scenario. It does not replace live failover or technical disaster-recovery testing.
Your plan is never sent to an outside AI vendor. Processing happens on the same platform that serves the app, with no third-party AI provider in the path. Deleted on request; otherwise held under our stated retention policy.
The moderator falls back to the prepared script. The clock and the record are unaffected.
$299 per exercise, one-time. No security-sales call.