Coordinate legal and operational response to suspected personal-data breaches, including containment, evidence preservation, fact development, role analysis, harm assessment, regulator and individual notification decisions, contractual notices, communications, remediation, and post-incident review.
Scanned 9/4/2026
Install to Claude Code
npx -y skills add Cancellationperiplocagraeca503/legal-ai-skills --skill breach-response-planner --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Breach Response Planner?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cancellationperiplocagraeca503-breach-response-planner)More formats (shields.io, HTML) on the badges page.
---
name: breach-response-planner
description: >-
Coordinate legal and operational response to suspected personal-data breaches,
including containment, evidence preservation, fact development, role analysis,
harm assessment, regulator and individual notification decisions, contractual
notices, communications, remediation, and post-incident review.
---
# Breach Response Planner
Run an evidence-led response without delaying containment. Treat notification
deadlines as live from the earliest plausible awareness time until counsel confirms otherwise.
## Immediate intake
Obtain detection and awareness times, reporter, incident owner, affected systems,
data and people, jurisdictions, entities and roles, vendors, attack or error
vector, access and exfiltration indicators, containment status, encryption and
keys, logs, contracts, insurance, law-enforcement contact, prior incidents, and
regulatory or sector obligations.
## Response method
1. Establish a cross-functional incident team, decision authority, secure
communication channel, privilege position, action log, and reporting cadence.
2. Protect people and systems, contain ongoing exposure, preserve forensic
evidence and logs, and avoid destructive remediation before capture.
3. Build a fact chronology and distinguish confirmed, likely, possible, disputed,
and unknown facts. Record when each relevant entity became aware.
4. Determine whether the event affected confidentiality, integrity, or
availability of personal data and whether it meets each applicable legal definition.
5. Map controller, processor, fiduciary, joint, service-provider, employer,
regulated-entity, and contractual roles for every data flow.
6. Assess affected categories, sensitivity, volume, identifiability, people,
duration, actors, encryption, misuse, reversibility, vulnerability, and likely
physical, financial, identity, discrimination, confidentiality, or other harm.
7. Build a jurisdiction-by-jurisdiction notification matrix covering threshold,
recipient, deadline, content, form, language, authority, phased updates, and records.
8. Prepare consistent regulator, individual, customer, insurer, board, partner,
employee, and public communications; separate known facts from investigation.
9. Address support such as credential resets, monitoring, contact channels,
accessibility, child or vulnerable-person measures, and complaint handling.
10. Track eradication, recovery, validation, root cause, control improvements,
vendor accountability, evidence retention, lessons, and closure approval.
## Output
Provide the incident chronology, data and role map, harm assessment, notification
matrix, decision log, draft notices, communication plan, remediation tracker, and
post-incident report.
## Guardrails
Do not conceal, speculate, destroy evidence, promise no harm, or delay escalation
while waiting for perfect facts. Do not use one jurisdiction's deadline globally.
Protect privilege without obstructing duties and obtain qualified forensic,
privacy, sector, employment, and local-law support where needed.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!