security-incident-response

Contain, investigate, and recover from security and privacy incidents with evidence-backed response plans.

Updated Aug 22, 2026
One-click install
npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill security-incident-response-fritzgeraldz
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-incident-response
Source: https://github.com/fritzgeraldz/Vibe-Managing/tree/main/skills/security-privacy/security-incident-response
Command: npx skills add https://github.com/fritzgeraldz/Vibe-Managing --skill security-incident-response-fritzgeraldz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? When a security or privacy incident strikes, founders often lack a structured way to triage severity, preserve evidence, contain damage, and meet notification obligations. This Skill turns a suspected incident into a governed response plan with clear owners, approvals, and learning records. ## Core Features & Use Cases - Structured Incident Triage: Classify severity, preserve evidence, and contain safely using an eight-step analysis framework with confidence scoring. - Governed Decision-Making: Rank response options by risk-adjusted value, hard constraints, and reversibility, with explicit human approval gates for external communication and legal obligations. - Use Case: A founder suspects a data breach affecting customer records. The Skill triages the evidence, recommends containment actions within delegated authority, coordinates legal counsel for notification decisions, and tracks containment time, recovery time, and recurrence as KPIs. ## Quick Start Use the security incident response skill to assess a suspected data breach and produce a containment and recovery plan with approval requirements.

Frequently Asked Questions about security-incident-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I respond to a security incident in my business?▼

Follow a structured sequence: triage evidence, classify severity, preserve evidence, contain safely, coordinate specialists, recover and validate, notify per counsel, and learn. Each step produces evidence, confidence, and a decision implication before continuing.

What should a security incident response plan include?▼

A response plan should include a diagnosis with evidence and confidence, ranked containment options, an action plan with owners and approvals, KPIs like containment and recovery time, monitoring cadence, stop conditions, and escalation rules for legal and compliance specialists.

When should a security incident be escalated to legal counsel?▼

Escalate to qualified legal or compliance specialists for any regulated interpretation, breach notification obligations, or privacy determinations. The Skill never makes legal judgments itself and routes such decisions to accountable professionals.

Can an AI agent execute incident response actions autonomously?▼

Only low-risk reversible internal actions within delegated authority, capped at autonomy level L2. External communication, money movement, access changes, and legal commitments always require named human approval before execution.

What KPIs measure security incident response effectiveness?▼

Track containment time, recovery time, evidence integrity, and recurrence, each with baseline, target, actual, trend, confidence, and owner. Also measure recommendation calibration by comparing expected versus actual outcomes.