| name | breach-summary |
| title | Cybersecurity Breach Summary |
| description | Summarizes cybersecurity breach incidents into structured legal and compliance records. Trigger when synthesizing incident reports, forensics, logs, or notifications into a defensible chronology, scope-impact analysis, response ledger, or regulatory-risk assessment. Keywords: data breach, incident response, unauthorized access, ransomware, exfiltration, GDPR, CCPA, HIPAA. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/breach-summary |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | cybersecurity |
| language | en |
| tags | ["regulatory","summarization","summary"] |
Cybersecurity Breach Summary
Produces a sourced, fact-based breach summary for counsel, security leadership, and regulator-facing communications. Every assertion is cited and uncertainty is labeled explicitly.
Quick Start
Before drafting, confirm you have:
- Source documents — incident ticket, forensics reports, SOC/SIEM logs, legal notices, board updates, insurance correspondence.
- Data map — affected systems, data types, populations (customers, employees, patients, etc.).
- Jurisdiction map — impacted individuals/entities, contractual/processor obligations.
- Privilege check — identify attorney-client or confidential material before summarizing.
- Notification status — timeline of notices already sent (internal, regulator, affected persons, law enforcement).
Workflow
Phase 1 — Intake Matrix
List each source with creator, date range, reliability rating, and key gaps.
Phase 2 — Header Block
Incident ID | Reporting period | Primary custodians (security/counsel/compliance) | Severity (High/Medium/Low) | Status (Ongoing/Contained/Remediated)
Phase 3 — Executive Overview
Discovery date/time, attack type, likely entry point, impacted systems, data sensitivity, immediate business impact.
Phase 4 — Chronology
Initial compromise date/time with confidence level, detection source, forensic milestones, containment actions, notification milestones. Use consistent, explicit time zones throughout.
Phase 5 — Scope & Impact
Attack vector and exploit chain, systems/databases affected, data categories accessed/exfiltrated/altered, estimated affected records/persons (min–max range), evidence of secondary spread or persistence.
Phase 6 — Response Ledger
Actions taken vs. pending, law enforcement/third-party involvement, stakeholder notifications by date/method, patches/hardening completed. Include owner for every open item.
Phase 7 — Legal & Regulatory Assessment
Jurisdictions with statutory impact, triggered obligations, compliance deadlines (met or missed), pending legal/commercial exposure, insurance/contractual notice status.
Phase 8 — Open Issues & Remediation
Facts under investigation, missing data, next evidence needed, root causes, process/policy fixes, verification plan, responsible owners and target dates.
Regulatory Checklist
| Framework | Checks | Core Evidence |
|---|
|