incident-response-lifecycle

Coordinate six-step incident response from detection to post-mortem.

Updated Mar 15, 2026
One-click install
npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill incident-response-lifecycle
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-response-lifecycle
Source: https://github.com/vahagn-madatyan/netsec-skills-suite/tree/main/skills/incident-response-lifecycle
Command: npx skills add https://github.com/vahagn-madatyan/netsec-skills-suite --skill incident-response-lifecycle

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Incident response process management for network incidents across detection, classification, escalation, coordination, remediation, and blameless post-incident review.

Core Features & Use Cases

  • Severity classification based on standard thresholds (P1–P4) and escalation matrices to guide roles and notifications.
  • Structured six-step workflow that coordinates evidence collection, investigation, communication, recovery, and post-mortem facilitation.
  • Uses templates and RCA framework to document timelines, root causes, and action items; references to incident-response-network for network-level evidence gathering.

Use case: When a major network outage hits production, this skill provides a playbook to assign roles (IC, Tech Lead, Comms Lead, Scribe), coordinate across teams, and produce a post-mortem report.

Quick Start

Load this skill and follow its six-step incident response procedure to manage an event from detection to post-mortem.

Frequently Asked Questions about incident-response-lifecycle

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an incident response lifecycle for managing network outages?

An incident response lifecycle coordinates network incident management across detection, triage, escalation, communication, recovery, and post-mortem. It uses a structured six-step workflow with severity matrices and role assignments to align multiple teams during major outages.

How do I coordinate incident response roles during a production outage?

You coordinate incident response roles by assigning specific functions like Incident Commander, Tech Lead, Comms Lead, and Scribe. The structured workflow provides a playbook to guide team alignment, severity classification, and communication across organizational boundaries.

How do I conduct a blameless post-mortem after a network incident?

Conduct a blameless post-mortem using the provided RCA framework and templates to document timelines, identify root causes, and track action items. This structured reporting process ensures objective analysis of network incidents without assigning individual blame.

What's the best way to classify incident severity for escalation matrices?

Classify incident severity using standard P1 through P4 thresholds to guide escalation matrices. These severity levels determine notification paths, role assignments, and coordination intensity required for managing network incidents across multiple teams.

Does this incident response workflow support cross-team organizational coordination?

Yes, the incident response workflow supports organizational coordination scenarios where multiple teams must align on severity, roles, and communications. It provides structured templates, RCA frameworks, and references for managing network-level incidents across boundaries.

When do I need a structured template for incident response management?

You need a structured template for incident response management when coordinating complex network outages requiring evidence collection, investigation, and recovery. The six-step workflow uses templates to standardize post-incident reporting, root cause analysis, and action item tracking.