skills/legal/incident-response-playbook/SKILL.md
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.4/1.6 and privilege preservation. Use when creating or updating an incident response plan, breach response policy, ransomware playbook, or regulatory notification checklist. Trigger keywords: incident response, playbook, data breach, ransomware, cybersecurity policy, NIST 800-61.
npx skillsauth add casemark/skills incident-response-playbookInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces defensible, operational incident response plans and scenario playbooks for legal organizations. Aligns NIST SP 800-61 Rev. 2 with ABA ethics obligations and client confidentiality requirements.
Gather before drafting:
Header block: Title, version, effective date, approvers, distribution, storage location, review dates.
Governance roles — each needs primary duties, decision authority, and named backups:
External engagement checklist:
Scope: Cyber events, confidentiality breaches, privilege risks, ethical violations affecting representation, physical compromise of client data.
Severity levels:
| Severity | Examples | Response | Notification | |---|---|---|---| | Critical | Widespread client data exposure, ransomware on active matters, privilege compromise | Immediate activation + exec notify | Immediate | | High | Targeted account takeover, multi-matter access | Activate response team | Within 2 hrs | | Medium | Single-user phishing, limited exposure | IT + counsel review | Same business day | | Low | Blocked attempts, policy violations | Log + monitor | Standard queue |
Sources: SIEM, EDR, DLP, email security, user reports, vendor alerts, audit logs.
Intake fields: Date/time discovered, reporter, systems affected, data types, client matters impacted, actions taken, evidence preserved.
Privilege protocol: Counsel directs investigations. Mark communications "Privileged & Confidential." Separate factual incident log from legal analysis.
Preparation:
Identification:
Containment:
Eradication:
Recovery:
Lessons Learned:
Ransomware:
Email Account Compromise:
Unauthorized Case File Access:
Inadvertent Privilege Disclosure:
Internal: Need-to-know distribution, secure channels, counsel-led updates.
Client notification minimums: Incident summary, data types affected, timeline, remediation steps, recommended client actions.
Regulatory notification matrix — populate per jurisdiction:
| Jurisdiction | Statute/Rule | Trigger | Deadline | Agency | Notes | |---|---|---|---|---|---| | [State] | [Citation] | [Trigger] | [X days] | [AG/Agency] | [VERIFY] |
Ethics obligations: ABA Rules 1.4 (communication), 1.6 (confidentiality), 1.1 (tech competence).
Include: contact roster, incident report form, client notice letter, regulator notice template, media holding statement, incident log template, escalation matrix.
Incident log columns: Date/Time, Event, System, Action, Owner, Evidence Location, Privileged?
[VERIFY].Key changes from the original:
tags from frontmatter — not part of the Agent Skills spec (only name and description)tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.