| name | incident-response-plan |
| title | Incident Response Plan and Playbook |
| description | Drafts incident response plans and playbooks for legal organizations, adapting NIST SP 800-61 to law firm contexts including privilege preservation, ethics obligations, and state breach notification compliance. Use when creating IR plans, cybersecurity playbooks, breach response policies, or data incident procedures for law firms or legal departments. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/incident-response-plan |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | cybersecurity |
| language | en |
Incident Response Plan and Playbook
Drafts legally defensible IR plans for law firms and legal departments covering cybersecurity incidents, data breaches, privilege preservation, and professional responsibility compliance.
Prerequisites
Gather before drafting:
- Organization profile — firm structure, practice areas, office locations, operating jurisdictions
- Existing policies — infosec policies, business continuity plans, professional responsibility guidelines
- Regulatory landscape — state breach notification statutes, sector overlays (HIPAA, GLBA, CMMC)
- Technology environment — case management systems, DMS, email, backup infrastructure
- Insurance coverage — cyber insurance policy, carrier contact, claim procedures
Quick Start
- Map jurisdictions and applicable breach statutes
- Classify incident types by severity tier
- Define governance roles and escalation chains
- Draft phased response procedures (NIST 800-61 adapted)
- Build scenario-specific playbooks
- Set communication protocols and notification templates
- Establish training/testing cadence
Output Sections
1. Jurisdictional Analysis
Map per operating jurisdiction:
- Breach notification statutes — triggers, timeframes (typically 30–90 days), AG notification
- Professional conduct rules — ABA Model Rules 1.1 (tech competence), 1.4 (communication), 1.6 (confidentiality)
- Sector overlays — HIPAA, GLBA, CMMC, SEC as applicable
- Ethics opinions — relevant state bar opinions on cybersecurity duties
2. Incident Taxonomy
Four severity tiers:
| Tier | Criteria | Response Time |
|---|
| Critical | Widespread client data compromise; privilege breach; mandatory reporting triggered | Immediate (24/7) |
| High | Multi-matter exposure; attorney email compromise | ≤2 hours |
| Medium | Isolated access attempts; contained inadvertent disclosure | ≤4 hours |
| Low | Blocked attempts; policy violations without data exposure |