The Cyber Drill Evidence Problem

Cyber drill exercises are a regulatory checkbox that most organizations complete without extracting real value. The typical pattern: the CISO gathers a room of people, presents a scenario ("imagine we have a ransomware incident"), discusses responses for 60 minutes, and produces a one-page summary. SEBI gets a compliance tick. Nobody learns anything. Nobody's response capability actually improves.

In practice, many tabletop exercises produce no actionable findings. The drill reports are generic ("communication needs improvement"), unspecific ("incident response plan should be updated"), and untracked ("action items were identified"). This is compliance theater that satisfies neither regulatory intent nor organizational need.