Incident Report Writing

Write incident communications for the right audience: executive summaries, technical post-incident reports, status updates on a cadence during a live incident, customer and partner notification drafts, regulatory notification checklists (GDPR, SEC 8-K, HIPAA, NIS2, DORA, state laws), and blameless lessons-learned documents, with a normalized UTC timeline built from raw events. Use this whenever someone asks to "write up the incident", "send an update", "brief the exec", "draft the customer notice", "do we have to notify", "build the timeline", "PIR", "post mortem", "retro", or pastes triage notes, chat logs, or a list of timestamps and asks what to tell people. Also reach for it when an incident is being closed and nothing has been written yet.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/incident-report-writing commit 8332ae0ed0

Frequently asked questions

npx skillmds@latest add ftrout/incident-report-writing