- Home
- Skills
- Legal & Compliance
- data breach response manager
Works with the AI tools you already use
data breach response manager
A structured response manager for personal data breaches, handling triage, timelines, and notification decision support.
$12
data breach response manager
Example session with this skill installed
We discovered an unsecured S3 bucket containing 5,000 UK customer records (names, emails, hashed passwords). T0 was 48 hours ago. We are the controller. Build a triage report and timeline.
- Read your context and instructions
- Compiled the data breach response
I have processed the incident details for the unsecured S3 bucket discovery. The assessment identifies this as a confirmed data breach involving sensitive authentication identifiers and personal contact data.
Breach Triage and Response Record
| Category | Detail | Status/Assessment |
|---|---|---|
| Incident ID | B-2024-001 | Confirmed Data Breach |
| Organization Role | Data Controller | UK GDPR / DPA 2018 |
| T0 (Awareness) | 2024-05-20 09:00 UTC | 48 hours elapsed |
| Data Subjects | ~5,000 UK Customers | High Volume |
| Data Categories | Name, Email, Hashed Passwords | Sensitive/Credential Risk |
| Containment | S3 Bucket permissions restricted | Verified |
| Severity Score | Medium-High | Identity theft & Account takeover risk |
Event Timeline and Deadlines
| Timestamp | Event/Action | Status |
|---|---|---|
| 2024-05-20 09:00 | T0: Discovery of unsecured S3 bucket via security researcher | Logged |
| 2024-05-20 10:30 | Technical containment: Bucket ACLs updated to private | Complete |
| 2024-05-21 14:00 | Initial impact assessment and data subject count verified | Complete |
| 2024-05-23 09:00 | Regulator Notification Deadline (T+72h) | Urgent Action Required |
Notification Decision Support
The breach likely meets the 'risk to rights and freedoms' threshold for ICO notification due to the exposure of credentials (hashed passwords) and contact info, which enables targeted phishing and account takeover.
Next steps
- Escalate to Legal/DPO immediately to approve the ICO notification draft before the 72-hour window closes.
- Initiate a password reset for the 5,000 affected accounts and prepare a data subject notification.
- Review S3 bucket provisioning policies and CloudTrail logs to confirm if exfiltration occurred.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Managing a data breach manually often leads to missed regulatory deadlines, inconsistent evidence logging, and overlooked notification obligations. Privacy teams struggle to coordinate technical facts with legal requirements under high pressure without a structured framework.
What it does
- Generates structured breach response artefacts including triage reports, notifiability decision memos, and executive updates.
- Builds and maintains detailed incident timelines from T0 through discovery to remediation.
- Assesses harm severity from the perspective of affected data subjects to guide notification strategy.
- Drafts factual, plain-language notification content for regulators and individuals for legal review.
- Coordinates multi-stakeholder response plans across legal, IT, DPO, and executive teams.
Why this beats prompting it yourself
This skill enforces strict operating principles like evidence preservation and individual-centric harm assessment that general prompts ignore. It manages the complex interplay between controller and processor roles while ensuring jurisdiction-specific notification triggers are systematically checked.
Use cases
- Executing a tabletop exercise or breach readiness review for a privacy team.
- Drafting a regulatory notification memo after a misdirected email or lost device.
- Building a post-incident review and improvement plan after a confirmed breach.
- Coordinating response actions when a third-party vendor reports a data compromise.
Known limitations
Does not perform technical containment or forensic malware removal. Cannot file regulator notifications directly or provide definitive legal advice.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 17 days ago
- Passed all security checks, Safe to install