# Draft Cybersecurity Incident Response Policy

> Incident response policies for regulated manufacturers fail when the agent drafts a generic template rather than integrating the organisation-specific gap analysis findings, governance mandate, operational runbook, and regulatory guidance into a facility- and product-context-specific policy.

- Skill: `finchipaiorg/draft-cybersecurity-incident-response-policy` (Agent Skill)
- Install (CLI): `npx skillmds@latest add finchipaiorg/draft-cybersecurity-incident-response-policy`
- Raw SKILL.md: https://api.skillmd.com/api/skills/finchipaiorg/draft-cybersecurity-incident-response-policy/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: FinchipAIOrg (https://skillmd.com/u/finchipaiorg)
- Updated: 2026-09-22
- Page: https://skillmd.com/skills/finchipaiorg/draft-cybersecurity-incident-response-policy

---


# Skill: Draft Cybersecurity Incident Response Policy for Public Medical Device Manufacturer

## 1. Subject-matter triage
- Treat the source set as a policy-drafting record, not a template exercise.
- Identify the governing mandate first; it controls scope, authority, escalation, and reporting.
- Pull out the operational state from the runbook and after-action materials before drafting any rule.
- Separate mandatory policy content from implementation notes so the policy reads as a governing instrument, not a memo.
- If the source set contains more than one facility, product line, or business unit, map the policy to each in scope before drafting the final text.
- If the source set contains only one operating context, state that the policy is limited to that context and draft accordingly.

## 2. Failure modes the skill is correcting
- Drafting a generic cybersecurity incident response template that ignores the organisation’s actual gaps, workflows, and governance structure.
- Treating the governing resolution or equivalent authority as background instead of the source of policy authority.
- Missing mandatory elements drawn from regulatory guidance for a regulated medical device manufacturer.
- Failing to align the policy with public-company disclosure obligations where incident materiality may trigger external reporting.
- Omitting coordination points with insurance, privacy, legal, IT, quality, regulatory, and executive functions.
- Producing a companion drafting notes memo that merely summarizes the policy instead of explaining why each provision was selected.
- Leaving open who decides, who escalates, who reports, and when each step occurs.
- Allowing incident handling to remain aspirational rather than operational, measurable, and assignable.

## 3. Legal frameworks / domain conventions that apply
- Medical device cybersecurity lifecycle obligations: the policy should reflect post-market security expectations, incident handling, remediation, and documentation duties applicable to regulated manufacturers.
- Public-company disclosure obligations: include a materiality assessment and escalation path for potential securities-law disclosure decisions under the applicable disclosure regime.
- Privacy and security safeguard requirements: if personal or health information may be involved, include administrative incident-response controls and breach-assessment workflow consistent with the applicable privacy/security rules.
- Recognized cybersecurity incident-response structure: organize the policy around prepare, detect, analyze, contain, eradicate, recover, and review functions, with the operative content centered on response and recovery.
- Insurance coordination rules: if the source materials reference cyber-insurance, capture notice triggers, timing, approval prerequisites, and any restrictions on response spend or vendor use.
- Governance and delegation conventions: policy authority must track the governing body or delegated officer named in the source materials and should not expand beyond that mandate.

## 4. Analytical scaffolds
- Read the governing mandate to extract the policy’s authority, scope, required approvers, escalation hierarchy, and any required board or executive reporting.
- Read the gap analysis to identify each missing or weak control that the policy must cure.
- Read the operational runbook and after-action material to see how incidents are actually handled and where the policy must convert practice into mandatory steps.
- Read the regulatory guidance for any required policy elements, timing expectations, documentation duties, or reporting triggers.
- Read any insurance excerpt for notice requirements, consent restrictions, and coordination obligations.
- Draft the policy as a formal governance document with clear sections for purpose, scope, definitions, roles, classification, detection, escalation, containment, communications, recovery, review, and maintenance.
- Translate every material gap into a specific rule, owner, or timing requirement rather than a general statement of intent.
- Draft the companion notes memo as a drafting rationale document that ties each major provision to a source document and explains the implementation choice.
- Where the sources imply multiple incident categories, roles, facilities, or reporting paths, enumerate them explicitly before drafting the operative rules.
- Use mandatory language for obligations and avoid aspirational phrasing unless the source documents clearly support discretion.

## 5. Vertical / structural / temporal relationships
- Governance mandate sets the ceiling and floor for the policy; the policy implements that authority without altering it.
- The gap analysis identifies what is missing; the policy should close each gap with a concrete requirement.
- Operational practice shows what happens in reality; the policy should formalize, correct, or constrain that practice.
- Regulatory or disclosure windows may run faster than internal approval chains; build escalation and decision points early enough to preserve compliance.
- External notifications, insurer notices, and internal leadership escalation should be sequenced so that one does not block another.
- Recovery and post-incident review should follow containment and remediation, with lessons learned feeding back into policy maintenance.

## 6. Output structure conventions
- Produce two deliverables: the cybersecurity incident response policy and the policy drafting notes memo.
- Draft the policy as the primary deliverable first; only then draft the notes memo.
- Make the policy a standalone instrument with operative provisions, named roles, effective-date logic, and review cycle.
- Make the notes memo concise but specific, with each major drafting choice tied to the source material that drove it.
- Use industry-conventional headings rather than a rubric-shaped list.
- Keep the policy internally usable by operations, legal, quality, and executive stakeholders.
- Ensure the final files are named exactly as instructed by the workflow and contain substantive content, not placeholders.

