incident-responder

Coordinate NIST-aligned incident response runbooks with regulatory deadline tracking.

3|2|Updated Jan 23, 2026
One-click install
npx skills add https://github.com/robotijn/ctoc --skill incident-responder-robotijn
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-responder
Source: https://github.com/robotijn/ctoc/tree/main/skills/security/incident-responder
Command: npx skills add https://github.com/robotijn/ctoc --skill incident-responder-robotijn

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill eliminates the critical risk of unplanned, uncoordinated incident response that leads to regulatory fines, extended service outages, failed forensic claims, and missed compliance deadlines by providing a complete, NIST SP 800-61r3 / CSF 2.0-aligned framework with pre-built runbooks, on-call wiring, and regulatory clock tracking.

Core Features & Use Cases

  • NIST-Aligned IR Lifecycle: Implements the 6 CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) with mandatory artifacts for each phase to ensure full incident response coverage.
  • Pre-Built Incident Runbooks: Covers 8 critical incident classes (data breach, ransomware, DDoS, supply chain attacks, credential theft, AI prompt injection, insider threat, physical access) with SLA targets, containment steps, and mandatory evidence preservation procedures.
  • Regulatory Deadline Tracking: Built-in cheat sheets and runbook requirements for GDPR 72h DPA notifications, ENISA CRA 24h early warnings, SEC 8-K Item 1.05 4-business-day filings, NIS2, CIRCIA, and HIPAA to avoid costly missed filing windows.
  • Blameless Postmortem Templates: Google SRE-aligned templates that enforce role-based actor labels and actionable improvement tracking to drive systemic organizational improvements. Use case: A SaaS company experiencing a potential data breach can use this skill to immediately access the data-breach runbook, trigger the 72h GDPR notification clock, coordinate with legal and regulator liaison roles, and preserve forensic evidence before remediation steps destroy critical state.

Quick Start

Use the incident-responder skill to audit your .ctoc/operations/runbooks directory for missing incident class runbooks, regulatory wiring gaps, and unexercised game-day records.

Frequently Asked Questions about incident-responder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build incident response runbooks that satisfy NIST SP 800-61 and GDPR breach notification requirements?

Incident response runbooks aligned with NIST SP 800-61r3 and CSF 2.0 provide pre-built containment steps and evidence preservation procedures. They include regulatory deadline tracking for GDPR 72h notifications to ensure compliant breach responses.

What is the best way to track regulatory compliance deadlines during a security incident?

Tracking regulatory compliance deadlines during a security incident requires built-in cheat sheets for GDPR 72h, ENISA CRA 24h, and SEC 8-K 4-day filings. This prevents missed notification windows by mapping runbook requirements to specific regulatory clocks.

How do I conduct a blameless postmortem after a ransomware attack?

Conducting a blameless postmortem after a ransomware attack uses Google SRE-aligned templates that enforce role-based actor labels. This drives systemic organizational improvements through actionable tracking of remediation steps and evidence preservation.

Does NIST-aligned incident response cover cloud-native SaaS supply chain attacks?

NIST-aligned incident response covers cloud-native SaaS environments through pre-built runbooks for supply chain attacks and other incident classes. It maps the 6 CSF 2.0 functions to mandatory artifacts ensuring full coverage for regulated digital products.

Can I use pre-built runbooks for insider threat and AI prompt injection incidents?

Pre-built runbooks are available for insider threats and AI prompt injection incidents alongside 6 other critical classes. Each runbook provides SLA targets, containment steps, and mandatory evidence preservation procedures required for forensic claims.

What is needed to audit my operations directory for missing incident response runbooks?

Auditing operations directories for missing incident response runbooks requires checking for unexercised game-day records and regulatory wiring gaps. This validates coverage across 8 critical incident classes and identifies missing NIST SP 800-61r3 mandatory artifacts.