Back to skills
SKILL.md
Incident Response
ASecurityRun an incident and learn from it: declare + classify severity, split IC/comms/ops roles, communicate on a cadence, mitigate before root-causing, and write a blameless postmortem with owned, dated action items.
- 7 stars
- 0 votes
- 0 copies
- 0 views
- Added September 23, 2026
Security analysis
100/100npx -y skills add mcorbett51090/RavenClaude --skill incident-response --agent claude-codeAre you the author of Incident Response?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/mcorbett51090-incident-response)---
name: incident-response
description: "Run an incident and learn from it: declare + classify severity, split IC/comms/ops roles, communicate on a cadence, mitigate before root-causing, and write a blameless postmortem with owned, dated action items."
---
# Incident Response
**Purpose:** respond fast, communicate clearly, learn permanently.
## Declare & classify
Lean toward declaring. Severity sets the response size.
## Roles (separate them)
- **IC** — coordinates, decides, does NOT debug.
- **Ops** — fixes.
- **Comms** — updates stakeholders on a cadence.
## Mitigate first
Rollback / failover / flag-off to stop bleeding **before** forensic root-cause.
## Blameless postmortem
Fix the **system** that let the human err. Timeline + contributing factors + **owned, dated** action items tracked to done.
Attribution
Comments
Loading comments…