Train, verify or stress-test organizational response. Drill builds controlled scenarios, including simulated, real or abstracted cases, to exercise roles, escalation, decisions, evidence and communications when a privacy/cyber event may become a crisis.
New crisis surface: not only people and servers, but agents, token, prompt, connectors, workflows and operational identities that can read, write, send or decide on behalf of humans.
NoteDrill can be used on simulated scenarios, real cases or abstracted real cases to exercise roles, escalation and response capability. It does not replace formal incident handling, forensic reconstruction, legal analysis or organizational procedures.
A Set tabletop / response readiness
1
Start from a controlled scenario
Choose scenario, jurisdiction and intensity. ESR builds controlled pressure to exercise the response without needing to import files.
2
Or load a ready-made or derived scenario
The scenario loads from the catalogue or from a Blindspot seed, without a server. It may represent a simulated, real or properly abstracted case.
Import external files or resume a session
External files
Encrypted vault
Security: use encrypted export/import for transferable dossiers. The local vault is encrypted, requires a passphrase and should be used with one active session at a time. Plain exports remain available only as a conscious choice.
Fictitious example loaded. These minutes are for demo, onboarding or training. For real cases, use only minimized, abstracted or already authorized information within the intervention perimeter.
Guided scenario: if you choose a ready-made case, vector, sector, data and scale are predefined; intensity and facilitation style remain active and the profile is ignored. With “Random”, sector and profile decide. AI mode does not assume science fiction: it simulates cases that are already plausible, such as browser agents, SaaS connectors, note takers, no-code workflows, OAuth tokens and prompts containing personal data or operational credentials. Jurisdiction works across three selectable levels: generic Europe / EU/EEA framework, Switzerland as an autonomous FADP/NCSC framework, or Switzerland ↔ Europe cross-border. The concrete Member State, when needed, remains an element to qualify in the case and is not assumed as the default by the main selection. Vectors start from reusable surfaces — identity, tokens, suppliers, AI, data sharing, continuity — and not from predefined national actors. If you activate the cyber track, the simulator also introduces the cyber-regulatory doubt: privacy breach, significant cyber incident, or both?
B Briefing iniziale
T+00:00
First actions: do not look for the perfect answer, look for control
Contain damage without destroying evidence: isolate, revoke, suspend, block access.
Open an internal incident register: time, source, systems, people, decisions, rationale.
Understand which data and which affected individuals/data subjects are involved, even with a provisional estimate.
Activate privacy/compliance, security/IT/forensics, management, legal, regulatory liaison and supplier, with substitutes if someone is missing.
Assess risk to people, possible authority notification (GDPR 72h or Swiss FADP “as soon as possible”) and possible communication to affected individuals/data subjects.
Time pressure
Under the EU/GDPR framework, the 72-hour window starts from awareness of the breach, if authority notification is required. In Switzerland (FADP) there is no fixed deadline: notification is made “as soon as possible”.
GDPR — authority notification, if required
72h remaining
Cyber — early warning, if applicable
24h remaining
Mind the perimeter: the cyber obligation does not apply to everyone. It applies to entities/infrastructures above certain thresholds and in specific sectors. This module trains that cyber-regulatory doubt instead of assuming the obligation.
Initial decision T+00:00
Write the first concrete decision before seeing the injections: containment, activated roles, requested evidence and main doubt.
B2 Minimum response chain
The facilitator may intentionally leave a role empty: if the team blocks because “that person is missing”, the exercise is already useful. Separating who decides from who executes prevents the crisis from remaining suspended between responsibility and operations.
B3 Event / breach register
Internal documentation training
Fill in even provisional information. The goal is not perfection, but making traceable what you know, what you do not know and why you decide.
B4 High-risk checklist (GDPR / Swiss FADP)
Qualitative risk assessment for people
It is not an automatic calculator. It helps justify whether risk remains low / medium / high. The relevant threshold is “high risk”: under GDPR it also triggers communication to affected individuals/data subjects (Art. 34); under Swiss FADP it is the condition for notification to the FDPIC (Art. 24).
B5 Priority actions 4 / 24 h
First operational measures to verify
Tick only what has actually been decided or started. Missing actions become material for the improvement plan.
FAC Facilitator view — outline and key points
C Injections — one at a time
The facilitator reveals one injection at a time. After each one, the team says aloud what it does, who does it, with what evidence, and writes it in the box.
D Decision summary
Quick review before the final decision: what you decided at each step and how the assessment evolved. It checks the consistency of choices; it is not a score.
E Debriefing — what to take away
Post-exercise improvement plan
The real result is not “we responded well”, but the list of fragilities surfaced.
Gap / vulnerabilityOwnerDue date
Free lessons learned
Unstructured space for what does not fit well into the gap/owner/due-date plan: blocks surfaced, difficult discussions, operational insights, useful errors.
Observation / lessonImpactNote
Transferable encrypted dossier
Requires a started scenario and the same passphrase in both vault fields. Prefer this format when storing the Drill dossier or passing it to Prompt Builder.
External attestation of minutes
After downloading the TXT minutes, you may attest them externally by uploading them to the indicated service. Attestation does not replace legal or privacy assessment: it is an external step to document the existence of the generated file according to the selected service flow.