What problem does it solve? When a security incident strikes, managers, legal, PR, and coordinators often lack a clear process for decision-making and communication. This Skill provides a structured, non-technical incident response framework covering preparation, detection, containment, eradication, recovery, and post-incident learning. ## Core Features & Use Cases - Full IR Lifecycle Framework: Step-by-step guidance across preparation, detection, analysis, containment, eradication, recovery, communication, and post-mortem phases. - Communication Templates: Internal and external communication guidance, including legal notification considerations and public statement drafting. - Incident Classification: Initial severity classification (low, medium, high, critical) and incident type identification (ransomware, phishing, data leak, DDoS, insider misuse). - Use Case: A company discovers a suspected data breach. The incident manager uses this Skill to classify the incident, coordinate containment decisions, communicate with stakeholders, and run a post-mortem meeting within two weeks. ## Quick Start Use the incident-response-plan skill to walk me through responding to a suspected ransomware incident affecting our finance department.