building-malware-incident-communication-template

Generate severity-based communication templates for malware incident response and regulatory disclosure.

954|172|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/xalgord/xalgorix --skill building-malware-incident-communication-template
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: building-malware-incident-communication-template
Source: https://github.com/xalgord/xalgorix/tree/main/internal/tools/skills/data/incident-response/building-malware-incident-communication-template
Command: npx skills add https://github.com/xalgord/xalgorix --skill building-malware-incident-communication-template

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

During a malware incident, teams often improvise stakeholder notifications under pressure, risking leaked response details, missed regulatory deadlines, and premature public statements. This Skill provides structured, severity-tiered communication templates so the right audience gets the right information through the right channel.

Core Features & Use Cases

  • Severity-Based Escalation: P1-P4 classification matrix mapping malware impact to notification timelines and audiences, from 15-minute CISO calls to 24-hour team updates.
  • Five Ready Templates: Initial incident notification, executive briefing, technical advisory with IOCs, regulatory notification (e.g., GDPR Article 33), and customer/public disclosure.
  • Secure Channel Guidance: Out-of-band communication rules and misconfiguration warnings to prevent tipping off attackers still inside the network.
  • Use Case: A ransomware outbreak is detected at 02:00 UTC. Use the P1 escalation matrix to phone the CISO and Legal, issue the initial IR-team notification, and draft the executive briefing with business impact and decision points before the board meeting.

Quick Start

Generate a P1 initial incident notification and executive briefing for a ransomware incident affecting 40 endpoints detected today.

Frequently Asked Questions about building-malware-incident-communication-template

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I write a malware incident notification for executives?

Use the executive briefing template covering situation summary in business terms, revenue and operational impact, current containment status, key decisions needed, and external communication status. Keep it to 2-3 sentence summaries with a clear timeline and next update time.

What should a regulatory breach notification include under GDPR?

A GDPR Article 33 notification must include the incident summary, types and volume of personal data affected, number of individuals, timeline from occurrence to detection, containment measures, and mitigation steps. It must be submitted within 72 hours of awareness, so anchor the timeline to detection time in UTC.

How do I classify malware incident severity for escalation?

Use the P1-P4 matrix: P1 covers ransomware or wipers affecting operations with 15-minute notification to CISO and CEO, P2 covers targeted malware with suspected exfiltration within 1 hour, P3 covers contained infections within 4 hours, and P4 covers single endpoints within 24 hours.

Why should incident communications avoid corporate email during a breach?

Attackers may already control corporate email, Slack, or Teams, so in-band notifications tip them off and can burn containment efforts. Drive P1 and P2 communications out-of-band via phone calls or encrypted messaging like Signal, and never CC compromised mailboxes.

When should I avoid sharing IOCs in a technical advisory?

Avoid sharing exact detection logic, blocked C2 infrastructure, or live containment actions with broad audiences while the attacker may still be inside, since this lets them pivot or trigger destructive payloads. Keep tactical details TLP:RED and IR-team-only, sharing only remediation asks widely.