
CISO Incident Response Orchestration
Orchestrate incident response with compliance-aware decision trees and templates
What You Can Do
You receive structured guidance through every phase of a security incident—from initial assessment and severity classification through escalation decisions, stakeholder notifications, and post-incident review. The skill maps your incident to regulatory requirements (HIPAA, PCI-DSS, SOC 2, GDPR), generates ready-to-use communication templates tailored to your stakeholders, and provides decision trees that help you prioritize response actions under pressure.
Features
Classify incidents by impact and urgency using industry-standard frameworks
Automatically identify which regulations (HIPAA, PCI-DSS, GDPR, SOC 2) apply to your incident
Interactive workflows that determine who needs to be notified and when based on incident type and severity
Pre-drafted, legally-vetted templates for board notifications, regulatory filings, and customer alerts
Generate timestamped incident response records for compliance audits and legal discovery
Structured approach to determining business function restoration priority
Guided root cause analysis and lessons-learned capture for future preparedness
Example Output
Incident Assessment Output
Incident ID: INC-2024-0847
Initial Classification: Confirmed breach (customer data exposed)
Severity: CRITICAL
Regulatory Trigger: GDPR Article 33, HIPAA Breach Notification Rule, California Consumer Privacy Act
Notification Deadline: 72 hours (GDPR), 60 days (HIPAA), 30 days (CCPA)
Escalation Decision Output
✓ Notify CEO immediately
✓ Engage legal counsel
✓ Alert cyber insurance carrier
✓ Prepare regulatory notification (GDPR)
✓ Schedule all-hands employee communication
✗ No press statement needed at this stage
Communication Template (Board Notification)
To: Board of Directors
Subject: URGENT: Security Incident Response — Customer Data Exposure
We are managing an active security incident involving unauthorized access to customer payment data. All systems have been secured. External forensics firm engaged. Regulatory notifications proceeding per legal guidance. Full briefing in 2 hours.
What's Included
- SKILL.md: Complete incident response orchestration workflow
- Incident Assessment Template: Severity classification matrix and impact assessment checklist
- Regulatory Requirements Matrix: Compliance triggers and notification timelines for GDPR, HIPAA, PCI-DSS, SOC 2, and state privacy laws
- Escalation Decision Trees: Visual workflows for notification prioritization
- Communication Templates: Board notifications, customer alerts, employee announcements, regulatory filings
- Incident Log Format: Timestamped response record for audit compliance
- Post-Incident Review Checklist: Root cause analysis and lessons-learned framework
Who It's For
- Chief Information Security Officers (CISOs) — Need rapid, compliant incident orchestration under pressure
- Security Incident Response Managers — Lead cross-functional response coordination
- Security Operations Center (SOC) Directors — Triage and escalate incidents to executive leadership
- Compliance Officers — Ensure regulatory notification and documentation requirements are met
- Enterprise Security Leaders — Establish incident response playbooks and escalation procedures
Best For
- Immediate incident triage and severity classification — Determine if you have a reportable incident and how critical it is
- Executive escalation decisions — Know exactly who to notify and when
- Regulatory compliance notification — Meet GDPR, HIPAA, PCI-DSS, and state privacy law timelines
- Crisis communication planning — Draft notifications to board, employees, customers, and regulators
- Post-incident root cause analysis and recovery — Structured review to prevent future incidents







