Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    data breach response manager

    1

    A structured response manager for personal data breaches, handling triage, timelines, and notification decision support.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    data breach response manager

    data breach response manager

    Example session with this skill installed

    We discovered an unsecured S3 bucket containing 5,000 UK customer records (names, emails, hashed passwords). T0 was 48 hours ago. We are the controller. Build a triage report and timeline.

    • Read your context and instructions
    • Compiled the data breach response

    I have processed the incident details for the unsecured S3 bucket discovery. The assessment identifies this as a confirmed data breach involving sensitive authentication identifiers and personal contact data.

    Breach Triage and Response Record

    CategoryDetailStatus/Assessment
    Incident IDB-2024-001Confirmed Data Breach
    Organization RoleData ControllerUK GDPR / DPA 2018
    T0 (Awareness)2024-05-20 09:00 UTC48 hours elapsed
    Data Subjects~5,000 UK CustomersHigh Volume
    Data CategoriesName, Email, Hashed PasswordsSensitive/Credential Risk
    ContainmentS3 Bucket permissions restrictedVerified
    Severity ScoreMedium-HighIdentity theft & Account takeover risk

    Event Timeline and Deadlines

    TimestampEvent/ActionStatus
    2024-05-20 09:00T0: Discovery of unsecured S3 bucket via security researcherLogged
    2024-05-20 10:30Technical containment: Bucket ACLs updated to privateComplete
    2024-05-21 14:00Initial impact assessment and data subject count verifiedComplete
    2024-05-23 09:00Regulator Notification Deadline (T+72h)Urgent Action Required

    Notification Decision Support

    The breach likely meets the 'risk to rights and freedoms' threshold for ICO notification due to the exposure of credentials (hashed passwords) and contact info, which enables targeted phishing and account takeover.

    Next steps

    1. Escalate to Legal/DPO immediately to approve the ICO notification draft before the 72-hour window closes.
    2. Initiate a password reset for the 5,000 affected accounts and prepare a data subject notification.
    3. Review S3 bucket provisioning policies and CloudTrail logs to confirm if exfiltration occurred.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate evidence-based breach triage reports and executive incident updates.Track regulatory notification deadlines and mandatory disclosure timelines.Draft plain-language regulator and data subject notification content.Create post-incident reviews to identify control gaps and preventive actions.

    About this skill

    The problem

    Managing a data breach manually often leads to missed regulatory deadlines, inconsistent evidence logging, and overlooked notification obligations. Privacy teams struggle to coordinate technical facts with legal requirements under high pressure without a structured framework.

    What it does

    • Generates structured breach response artefacts including triage reports, notifiability decision memos, and executive updates.
    • Builds and maintains detailed incident timelines from T0 through discovery to remediation.
    • Assesses harm severity from the perspective of affected data subjects to guide notification strategy.
    • Drafts factual, plain-language notification content for regulators and individuals for legal review.
    • Coordinates multi-stakeholder response plans across legal, IT, DPO, and executive teams.

    Why this beats prompting it yourself

    This skill enforces strict operating principles like evidence preservation and individual-centric harm assessment that general prompts ignore. It manages the complex interplay between controller and processor roles while ensuring jurisdiction-specific notification triggers are systematically checked.

    Use cases

    • Executing a tabletop exercise or breach readiness review for a privacy team.
    • Drafting a regulatory notification memo after a misdirected email or lost device.
    • Building a post-incident review and improvement plan after a confirmed breach.
    • Coordinating response actions when a third-party vendor reports a data compromise.

    Known limitations

    Does not perform technical containment or forensic malware removal. Cannot file regulator notifications directly or provide definitive legal advice.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 17 days ago

    • Passed all security checks, Safe to install

    Listed17 days ago

    What's inside

    Frequently Asked Questions