What problem does it solve?
This skill eliminates the critical risk of unplanned, uncoordinated incident response that leads to regulatory fines, extended service outages, failed forensic claims, and missed compliance deadlines by providing a complete, NIST SP 800-61r3 / CSF 2.0-aligned framework with pre-built runbooks, on-call wiring, and regulatory clock tracking.
Core Features & Use Cases
- NIST-Aligned IR Lifecycle: Implements the 6 CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) with mandatory artifacts for each phase to ensure full incident response coverage.
- Pre-Built Incident Runbooks: Covers 8 critical incident classes (data breach, ransomware, DDoS, supply chain attacks, credential theft, AI prompt injection, insider threat, physical access) with SLA targets, containment steps, and mandatory evidence preservation procedures.
- Regulatory Deadline Tracking: Built-in cheat sheets and runbook requirements for GDPR 72h DPA notifications, ENISA CRA 24h early warnings, SEC 8-K Item 1.05 4-business-day filings, NIS2, CIRCIA, and HIPAA to avoid costly missed filing windows.
- Blameless Postmortem Templates: Google SRE-aligned templates that enforce role-based actor labels and actionable improvement tracking to drive systemic organizational improvements.
Use case: A SaaS company experiencing a potential data breach can use this skill to immediately access the data-breach runbook, trigger the 72h GDPR notification clock, coordinate with legal and regulator liaison roles, and preserve forensic evidence before remediation steps destroy critical state.
Quick Start
Use the incident-responder skill to audit your .ctoc/operations/runbooks directory for missing incident class runbooks, regulatory wiring gaps, and unexercised game-day records.