Skip to main content

Generating Drill Reports

Audit-ready reports for ISO 27001, Cyber Essentials, and insurance.

After completing a drill, CrownSync Playbooks generates a comprehensive drill report that captures timing data, completion rates, identified gaps, and observer notes. These reports serve as audit-ready evidence that your organisation regularly tests its incident response capabilities.

Report Contents

Each drill report includes the following sections:

Drill Summary

  • Drill name, date, and duration
  • Playbook used for the exercise
  • List of participants and their roles (facilitator, participant, observer)
  • Overall completion rate as a percentage
  • The facilitator's summary observations

Timing Breakdown

  • Total drill duration— The elapsed time from start to completion, excluding any pauses.
  • Phase-by-phase timing— How long the team spent in each of the six phases. This is displayed as both absolute time and as a percentage of the total drill duration.
  • Regulatory deadline performance— If the playbook includes regulatory notification steps, the report shows whether the simulated notification was completed within the required timeframe.
  • Comparison with previous drills— If the same playbook has been used in previous drills, timing trends are shown to demonstrate improvement or highlight regressions.

Completion Rates

  • Overall completion— The percentage of action items that were marked as completed across all phases.
  • Per-phase completion— Completion rates broken down by phase, highlighting which phases had the most gaps.
  • Skipped actions— A list of actions that were explicitly skipped, with any notes explaining why they were not completed.
  • Incomplete actions— Actions that were neither completed nor skipped, indicating areas where the team ran out of time or was unsure of the procedure.

Gap Analysis

The gap analysis section identifies patterns in the drill performance:

  • Consistently missed actions— If certain actions are repeatedly skipped or left incomplete across multiple drills, they are flagged for review.
  • Slow phases— Phases that took disproportionately long compared to expectations or previous drills.
  • Participant notes— Aggregated notes from participants highlighting difficulties, confusion, or suggestions.
  • Observer notes— Independent observations from assigned observers, providing an external perspective on the team's performance.

Continuous improvement tracking

When you run multiple drills with the same playbook over time, the drill report automatically includes trend data showing how completion rates and phase timing have changed. This demonstrates continuous improvement to auditors and insurers.

Exporting Drill Reports as PDF

Drill reports can be exported as signed PDF documents using the same infrastructure as playbook PDF exports. The exported report includes:

  • A title page with the drill name, date, and organisation details
  • All report sections with tables, charts, and gap analysis
  • A verification page with QR code and verification ID
  • Classification markings and watermarks matching your PDF branding settings

To export a drill report:

  1. Navigate to the completed drill from the drills list
  2. Click View Report to review the report on screen
  3. Click Export PDF to generate the signed document

Sharing Drill Reports with Auditors

Drill reports are specifically designed to meet the documentation requirements of common compliance frameworks:

  • ISO 27001— Drill reports provide evidence for control A.5.24 (incident management testing) and support the continual improvement requirements of the ISMS.
  • Cyber Essentials Plus— While CE+ does not mandate drill reports specifically, assessors view regular testing of incident response procedures favourably when evaluating an organisation's security posture.
  • Cyber insurance— Insurers increasingly require evidence that incident response plans are tested. Drill reports with timing data and completion rates provide exactly this evidence, and may be requested during the claims process.
  • Board reporting— The executive summary section of drill reports is suitable for inclusion in board packs to demonstrate ongoing cyber resilience investment.

Build a drill history

Run drills quarterly at minimum and keep all drill reports. Over time, this creates a documented history of testing and improvement that is extremely valuable during audits, insurance renewals, and regulatory inquiries. A series of reports showing improving completion rates and reducing response times tells a compelling story of organisational commitment to cyber resilience.

Was this page helpful?