skills/legal/incident-response-plan/SKILL.md
Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, ethics obligations, and state breach notification compliance. Use when creating IR plans, cybersecurity playbooks, breach response policies, or data incident procedures for law firms or legal departments.
npx skillsauth add casemark/skills incident-response-planInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.
Gather before drafting:
Map per operating jurisdiction:
Four severity tiers:
| Tier | Criteria | Response Time | |------|----------|---------------| | Critical | Widespread client data compromise; privilege breach; mandatory reporting triggered | Immediate (24/7) | | High | Multi-matter exposure; attorney email compromise | ≤2 hours | | Medium | Isolated access attempts; contained inadvertent disclosure | ≤4 hours | | Low | Blocked attempts; policy violations without data exposure | Next business day |
Legal-specific incident types: inadvertent privilege disclosure, case management unauthorized access, conflicts data exposure, attorney email compromise, DMS ransomware, physical file breach.
| Role | Function | Key Authority | |------|----------|---------------| | IR Coordinator | Activates plan, convenes team | Isolate systems, engage external resources | | General Counsel / Ethics Counsel | Legal/ethical analysis, privilege protection | Direct privileged investigation, approve notifications | | CISO / IT Director | Technical response, forensics | Evidence preservation, restoration | | Managing Partner | Strategic decisions | Expenditures, client relationship decisions | | Communications Director | Internal/external messaging | Media responses (with counsel approval) |
Include after-hours contact roster and escalation chain for unavailable contacts.
Phase 1 — Preparation
Phase 2 — Identification
Phase 3 — Containment
Phase 4 — Eradication
Phase 5 — Recovery
Phase 6 — Lessons Learned (within 14 days)
Ransomware on DMS:
Attorney Email Compromise:
Inadvertent Privilege Disclosure:
[VERIFY]; request return/destruction| Audience | Trigger | Timing | Approval | |----------|---------|--------|----------| | IR Team | Any confirmed incident | Immediate | IR Coordinator | | Senior Leadership | High/Critical | Within 1 hour | IR Coordinator | | Affected Clients | Client data compromised | Per statute + "prompt" ethics notice | GC + Managing Partner | | State AG / Regulators | Statutory threshold met | Per state (30–90 days) | General Counsel | | Law Enforcement | Criminal activity; ransomware | Case-by-case | General Counsel | | Media | Public exposure/inquiry | Reactive only | GC + Communications |
Mark all investigation communications "Privileged & Confidential — Attorney Work Product." Client notifications must satisfy both breach statutes and professional conduct rules.
| Activity | Frequency | |----------|-----------| | Security awareness training | Annual (all personnel) | | IR team specialized training | Annual | | Tabletop exercises | Annual minimum | | Phishing simulations | Quarterly | | Backup restoration tests | Semi-annual | | Plan review and update | Annual + post-incident |
Track: time to detect, contain, eradicate, recover; notification compliance rate.
[VERIFY]tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.