incident-response-plan

Guides non-technical teams through security incident response phases from preparation to post-incident review.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill incident-response-plan-yogiex
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: incident-response-plan
Source: https://github.com/yogiex/opencode-cyber-security-skills/tree/main/skills/incident-response-plan
Command: npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill incident-response-plan-yogiex

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? When a security incident strikes, managers, legal, PR, and coordinators often lack a clear process for decision-making and communication. This Skill provides a structured, non-technical incident response framework covering preparation, detection, containment, eradication, recovery, and post-incident learning. ## Core Features & Use Cases - Full IR Lifecycle Framework: Step-by-step guidance across preparation, detection, analysis, containment, eradication, recovery, communication, and post-mortem phases. - Communication Templates: Internal and external communication guidance, including legal notification considerations and public statement drafting. - Incident Classification: Initial severity classification (low, medium, high, critical) and incident type identification (ransomware, phishing, data leak, DDoS, insider misuse). - Use Case: A company discovers a suspected data breach. The incident manager uses this Skill to classify the incident, coordinate containment decisions, communicate with stakeholders, and run a post-mortem meeting within two weeks. ## Quick Start Use the incident-response-plan skill to walk me through responding to a suspected ransomware incident affecting our finance department.

Frequently Asked Questions about incident-response-plan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create an incident response plan for my organization?▼

Start by forming an IR team with an incident manager, communications lead, and technical coordinator. Then define reporting channels, severity classification levels, containment decision authority, and communication templates, and run simulations every six months.

What are the phases of incident response?▼

The standard phases are preparation, detection and reporting, analysis and confirmation, containment, eradication, recovery, and post-incident learning. Each phase has specific decision points and coordination tasks for both technical and non-technical staff.

Who should be on an incident response team?▼

A typical IR team includes an incident manager, a communications representative covering PR and legal, one technical coordinator, and HR when insider issues are involved. Maintain emergency contact lists across multiple channels, not just email.

When should customers be notified about a data breach?▼

Notify customers when their data is confirmed or likely affected, after consulting legal counsel about notification obligations. Prepare a short, honest public statement that avoids disclosing technical details, and never comment publicly without legal and PR approval.

What should a post-incident review meeting cover?▼

Hold a post-mortem within two weeks of incident resolution covering what went well, what went poorly, the root cause, and needed process or training improvements. Produce a blame-free summary report for management and update the IR plan accordingly.