incident-response-lifecycleIncident response process management following the NIST 800-61 lifecycle. Covers severity classification, escalation matrices, role assignment, communication...
Install via ClawdBot CLI:
clawdbot install vahagn-madatyan/incident-response-lifecycleGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 2, 2026
A company experiences a large-scale DDoS attack causing a P1 outage. The incident commander activates the incident response lifecycle, classifies the severity, coordinates with the network team for mitigation, manages internal and external communications, and schedules a blameless post-mortem.
A bank detects unauthorized access to customer data, classified as P1. The team follows the lifecycle to escalate, assign roles, coordinate forensic investigation, notify regulators and affected customers, and conduct a root cause analysis using 5-whys.
A cloud provider's service degrades due to a configuration error, impacting multiple enterprise customers. The incident response process is used to classify as P2, coordinate across teams, communicate status updates, and drive recovery within SLA timelines.
A hospital's systems are encrypted by ransomware, disrupting patient care. The incident commander declares a P1, assigns roles, isolates affected systems, coordinates with law enforcement and IT, manages communications to staff and patients, and facilitates a post-incident review.
A subscription-based service where a third-party provider offers end-to-end incident response management for clients, including severity classification, escalation, communication, and post-mortem facilitation.
A SaaS platform that provides tools to automate incident tracking, role assignment, communication templates, and post-mortem documentation, integrated with existing ticketing and collaboration systems.
A consultancy that helps organizations develop their incident response procedures, train staff on the NIST lifecycle, and conduct simulated incident exercises.
💬 Integration Tip
Integrate with existing ticketing and communication tools (e.g., Slack, ServiceNow) to automate role assignments and status updates. Ensure contact directories and escalation matrices are up-to-date.
Scored Jun 27, 2026
Design and implement automation workflows to save time and scale operations as a solopreneur. Use when identifying repetitive tasks to automate, building workflows across tools, setting up triggers and actions, or optimizing existing automations. Covers automation opportunity identification, workflow design, tool selection (Zapier, Make, n8n), testing, and maintenance. Trigger on "automate", "automation", "workflow automation", "save time", "reduce manual work", "automate my business", "no-code automation".
Local-first recurring schedule engine for reminders, repeated tasks, and time-based execution plans. Use whenever the user mentions recurring timing, repetit...
Create, list, modify, and remove scheduled cron jobs to automate system tasks using simplified cron syntax and manage output logging.
Manage n8n workflows and automations via API. Use when working with n8n workflows, executions, or automation tasks - listing workflows, activating/deactivating, checking execution status, manually triggering workflows, or debugging automation issues.
Diagnose and triage cron job failures. Checks job states, identifies error patterns, prioritizes by criticality, generates health reports. Triggers on: cron...
Decomposes complex user requests into executable subtasks, identifies required capabilities, searches for existing skills at skills.sh, and creates new skills when no solution exists. This skill should be used when the user submits a complex multi-step request, wants to automate workflows, or needs help breaking down large tasks into manageable pieces.