1---2name: draft-cybersecurity-incident-response-policy3description: Incident response policies for regulated manufacturers fail when the agent drafts a generic template rather than integrating the organisation-specific gap analysis findings, governance mandate, operational runbook, and regulatory guidance into a facility- and product-context-specific policy.4---56# Skill: Draft Cybersecurity Incident Response Policy for Public Medical Device Manufacturer78## 1. Subject-matter triage9- Treat the source set as a policy-drafting record, not a template exercise.10- Identify the governing mandate first; it controls scope, authority, escalation, and reporting.11- Pull out the operational state from the runbook and after-action materials before drafting any rule.12- Separate mandatory policy content from implementation notes so the policy reads as a governing instrument, not a memo.13- If the source set contains more than one facility, product line, or business unit, map the policy to each in scope before drafting the final text.14- If the source set contains only one operating context, state that the policy is limited to that context and draft accordingly.1516## 2. Failure modes the skill is correcting17- Drafting a generic cybersecurity incident response template that ignores the organisation’s actual gaps, workflows, and governance structure.18- Treating the governing resolution or equivalent authority as background instead of the source of policy authority.19- Missing mandatory elements drawn from regulatory guidance for a regulated medical device manufacturer.20- Failing to align the policy with public-company disclosure obligations where incident materiality may trigger external reporting.21- Omitting coordination points with insurance, privacy, legal, IT, quality, regulatory, and executive functions.22- Producing a companion drafting notes memo that merely summarizes the policy instead of explaining why each provision was selected.23- Leaving open who decides, who escalates, who reports, and when each step occurs.24- Allowing incident handling to remain aspirational rather than operational, measurable, and assignable.2526## 3. Legal frameworks / domain conventions that apply27- Medical device cybersecurity lifecycle obligations: the policy should reflect post-market security expectations, incident handling, remediation, and documentation duties applicable to regulated manufacturers.28- Public-company disclosure obligations: include a materiality assessment and escalation path for potential securities-law disclosure decisions under the applicable disclosure regime.29- Privacy and security safeguard requirements: if personal or health information may be involved, include administrative incident-response controls and breach-assessment workflow consistent with the applicable privacy/security rules.30- Recognized cybersecurity incident-response structure: organize the policy around prepare, detect, analyze, contain, eradicate, recover, and review functions, with the operative content centered on response and recovery.31- Insurance coordination rules: if the source materials reference cyber-insurance, capture notice triggers, timing, approval prerequisites, and any restrictions on response spend or vendor use.32- Governance and delegation conventions: policy authority must track the governing body or delegated officer named in the source materials and should not expand beyond that mandate.3334## 4. Analytical scaffolds35- Read the governing mandate to extract the policy’s authority, scope, required approvers, escalation hierarchy, and any required board or executive reporting.36- Read the gap analysis to identify each missing or weak control that the policy must cure.37- Read the operational runbook and after-action material to see how incidents are actually handled and where the policy must convert practice into mandatory steps.38- Read the regulatory guidance for any required policy elements, timing expectations, documentation duties, or reporting triggers.39- Read any insurance excerpt for notice requirements, consent restrictions, and coordination obligations.40- Draft the policy as a formal governance document with clear sections for purpose, scope, definitions, roles, classification, detection, escalation, containment, communications, recovery, review, and maintenance.41- Translate every material gap into a specific rule, owner, or timing requirement rather than a general statement of intent.42- Draft the companion notes memo as a drafting rationale document that ties each major provision to a source document and explains the implementation choice.43- Where the sources imply multiple incident categories, roles, facilities, or reporting paths, enumerate them explicitly before drafting the operative rules.44- Use mandatory language for obligations and avoid aspirational phrasing unless the source documents clearly support discretion.4546## 5. Vertical / structural / temporal relationships47- Governance mandate sets the ceiling and floor for the policy; the policy implements that authority without altering it.48- The gap analysis identifies what is missing; the policy should close each gap with a concrete requirement.49- Operational practice shows what happens in reality; the policy should formalize, correct, or constrain that practice.50- Regulatory or disclosure windows may run faster than internal approval chains; build escalation and decision points early enough to preserve compliance.51- External notifications, insurer notices, and internal leadership escalation should be sequenced so that one does not block another.52- Recovery and post-incident review should follow containment and remediation, with lessons learned feeding back into policy maintenance.5354## 6. Output structure conventions55- Produce two deliverables: the cybersecurity incident response policy and the policy drafting notes memo.56- Draft the policy as the primary deliverable first; only then draft the notes memo.57- Make the policy a standalone instrument with operative provisions, named roles, effective-date logic, and review cycle.58- Make the notes memo concise but specific, with each major drafting choice tied to the source material that drove it.59- Use industry-conventional headings rather than a rubric-shaped list.60- Keep the policy internally usable by operations, legal, quality, and executive stakeholders.61- Ensure the final files are named exactly as instructed by the workflow and contain substantive content, not placeholders.