skills/legal/incident-response-playbook/SKILL.md
Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.4/1.6 and privilege preservation. Use when creating or updating an incident response plan, breach response policy, ransomware playbook, or regulatory notification checklist. Trigger keywords: incident response, playbook, data breach, ransomware, cybersecurity policy, NIST 800-61.
npx skillsauth add casemark/skills incident-response-playbookInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Produces defensible, operational incident response plans and scenario playbooks for legal organizations. Aligns NIST SP 800-61 Rev. 2 with ABA ethics obligations and client confidentiality requirements.
Gather before drafting:
Header block: Title, version, effective date, approvers, distribution, storage location, review dates.
Governance roles — each needs primary duties, decision authority, and named backups:
External engagement checklist:
Scope: Cyber events, confidentiality breaches, privilege risks, ethical violations affecting representation, physical compromise of client data.
Severity levels:
| Severity | Examples | Response | Notification | |---|---|---|---| | Critical | Widespread client data exposure, ransomware on active matters, privilege compromise | Immediate activation + exec notify | Immediate | | High | Targeted account takeover, multi-matter access | Activate response team | Within 2 hrs | | Medium | Single-user phishing, limited exposure | IT + counsel review | Same business day | | Low | Blocked attempts, policy violations | Log + monitor | Standard queue |
Sources: SIEM, EDR, DLP, email security, user reports, vendor alerts, audit logs.
Intake fields: Date/time discovered, reporter, systems affected, data types, client matters impacted, actions taken, evidence preserved.
Privilege protocol: Counsel directs investigations. Mark communications "Privileged & Confidential." Separate factual incident log from legal analysis.
Preparation:
Identification:
Containment:
Eradication:
Recovery:
Lessons Learned:
Ransomware:
Email Account Compromise:
Unauthorized Case File Access:
Inadvertent Privilege Disclosure:
Internal: Need-to-know distribution, secure channels, counsel-led updates.
Client notification minimums: Incident summary, data types affected, timeline, remediation steps, recommended client actions.
Regulatory notification matrix — populate per jurisdiction:
| Jurisdiction | Statute/Rule | Trigger | Deadline | Agency | Notes | |---|---|---|---|---|---| | [State] | [Citation] | [Trigger] | [X days] | [AG/Agency] | [VERIFY] |
Ethics obligations: ABA Rules 1.4 (communication), 1.6 (confidentiality), 1.1 (tech competence).
Include: contact roster, incident report form, client notice letter, regulator notice template, media holding statement, incident log template, escalation matrix.
Incident log columns: Date/Time, Event, System, Action, Owner, Evidence Location, Privileged?
[VERIFY].Key changes from the original:
tags from frontmatter — not part of the Agent Skills spec (only name and description)development
name: automated-contract-summary language: en description: Generates structured executive summaries of contracts using ML — captures key terms, party obligations, risk allocations, and compliance requirements in a standardized format. Optimized for high-volume review where speed and consistency matter. tags: - summarization - agreement - corporate --- # Automated Contract Summarization Produces standardized executive summaries of contracts using machine learning, capturing essential term
tools
Extracts regulatory obligations from dense regulations across jurisdictions. Breaks down multi-level regulations into clear article-level obligations, classifies applicability to a business, and prioritizes by risk level. Use when translating regulations into actionable compliance requirements.
development
Continuously monitors regulatory landscapes for changes relevant to a specific business. Ingests global regulatory updates, filters by relevance, summarizes impact, and produces an actionable change advisory. Use when tracking regulatory developments affecting a particular product or market.
testing
Compares an organization's existing compliance controls, policies, and procedures against extracted regulatory obligations to identify coverage gaps. Produces a remediation plan with prioritized actions. Use when assessing compliance maturity or preparing for regulatory audits.