Incident Response Plan and Playbook
Produces defensible, operational incident response plans and scenario playbooks for legal organizations. Aligns NIST SP 800-61 Rev. 2 with ABA ethics obligations and client confidentiality requirements.
Prerequisites
Gather before drafting:
- Firm profile — practice areas, jurisdictions, client types, offices, critical systems
- Current policies — security, acceptable use, retention, BCP/DR, vendor management
- Data map — systems holding client confidential/privileged data, backups, cloud providers
- Regulatory scope — applicable breach laws, ethics rules, sector regulations (HIPAA, GLBA, CMMC)
- Contacts — internal response team and external vendors with after-hours channels
Quick Start
- Confirm scope and standards (NIST 800-61, ABA Rules 1.1/1.4/1.6, state bar guidance)
- Build plan: governance, taxonomy, detection, phased response, communications, training
- Add scenario playbooks (ransomware, email compromise, unauthorized access, inadvertent disclosure)
- Add appendices: contacts, templates, logs, escalation matrix, regulatory authority map
- Quality-check privilege posture, notification timeframes, role coverage, and version control
Core Workflow
1. Plan Header and Governance
Header block: Title, version, effective date, approvers, distribution, storage location, review dates.
Governance roles — each needs primary duties, decision authority, and named backups:
- Incident Response Coordinator (activate, triage, oversee)
- Legal/Ethics Counsel (privilege, ethics, notifications, regulators)
- IT/Security Lead (forensics, containment, eradication)
- Managing Partner/ED (resourcing, client impact, business decisions)
- Comms Lead (internal/external messaging)
- Practice Leaders (client context, matter impact — advisory)
External engagement checklist:
2. Incident Taxonomy
Scope: Cyber events, confidentiality breaches, privilege risks, ethical violations affecting representation, physical compromise of client data.
Severity levels:
| Severity |
Examples |
Response |
Notification |
| Critical |
Widespread client data exposure, ransomware on active matters, privilege compromise |
Immediate activation + exec notify |
Immediate |
| High |
Targeted account takeover, multi-matter access |
Activate response team |
Within 2 hrs |
| Medium |
Single-user phishing, limited exposure |
IT + counsel review |
Same business day |
| Low |
Blocked attempts, policy violations |
Log + monitor |
Standard queue |
3. Detection and Reporting
Sources: SIEM, EDR, DLP, email security, user reports, vendor alerts, audit logs.
Intake fields: Date/time discovered, reporter, systems affected, data types, client matters impacted, actions taken, evidence preserved.
Privilege protocol: Counsel directs investigations. Mark communications "Privileged & Confidential." Separate factual incident log from legal analysis.
4. NIST-Aligned Phased Response
Preparation:
Identification:
Containment:
Eradication:
Recovery:
Lessons Learned:
5. Scenario Playbooks
Ransomware:
Email Account Compromise:
Unauthorized Case File Access:
Inadvertent Privilege Disclosure:
6. Communications and Notifications
Internal: Need-to-know distribution, secure channels, counsel-led updates.
Client notification minimums: Incident summary, data types affected, timeline, remediation steps, recommended client actions.
Regulatory notification matrix — populate per jurisdiction:
| Jurisdiction |
Statute/Rule |
Trigger |
Deadline |
Agency |
Notes |
| [State] |
[Citation] |
[Trigger] |
[X days] |
[AG/Agency] |
[VERIFY] |
Ethics obligations: ABA Rules 1.4 (communication), 1.6 (confidentiality), 1.1 (tech competence).
7. Appendices
Include: contact roster, incident report form, client notice letter, regulator notice template, media holding statement, incident log template, escalation matrix.
Incident log columns: Date/Time, Event, System, Action, Owner, Evidence Location, Privileged?
Pitfalls
- Unverified deadlines — never include jurisdiction-specific deadlines without verification; mark
[VERIFY].
- Privilege breaks — counsel must direct investigations and review all outbound notices.
- Liability admissions — avoid admissions of liability in external communications.
- Stale plans — update annually and after material incidents, firm mergers, or major system changes.
- Missing citations — always cite NIST SP 800-61 Rev. 2 and applicable ethics rules; reference local bar guidance when used.
Key changes from the original:
- Removed
tags from frontmatter — not part of the Agent Skills spec (only name and description)
- Tightened description — kept under 1024 chars, third-person, clear trigger guidance
- Added Quick Start section — the 5-step overview now lives in its own scannable section
- Flattened "Output Structure / Process" — eliminated the redundant dual-layer (summary + numbered subsections) by merging into a single "Core Workflow" with flat numbered steps
- Removed code fence around incident log template — replaced with inline column listing
- Consolidated Training/Testing/Metrics — folded into the Lessons Learned checklist and Appendices rather than a standalone section (saves ~20 lines)
- Renamed "Guidelines" to "Pitfalls" — matches the best-practices pattern and uses bold-label + dash format for quick scanning
- Reduced from 201 to ~145 lines — well under the 500-line limit, with no loss of domain accuracy or legal intent
1---2name: incident-response-playbook3description: Drafts incident response plans and scenario playbooks for U.S. legal organizations, aligning NIST SP 800-61 Rev. 2 phases with ABA Model Rules 1.1/1.4/1.6 and privilege preservation. Use when creating or updating an incident response plan, breach response policy, ransomware playbook, or regulatory notification checklist. Trigger keywords: incident response, playbook, data breach, ransomware, cybersecurity policy, NIST 800-61.4license: Apache-2.05---67# Incident Response Plan and Playbook89Produces defensible, operational incident response plans and scenario playbooks for legal organizations. Aligns NIST SP 800-61 Rev. 2 with ABA ethics obligations and client confidentiality requirements.1011## Prerequisites1213Gather before drafting:14151. **Firm profile** — practice areas, jurisdictions, client types, offices, critical systems162. **Current policies** — security, acceptable use, retention, BCP/DR, vendor management173. **Data map** — systems holding client confidential/privileged data, backups, cloud providers184. **Regulatory scope** — applicable breach laws, ethics rules, sector regulations (HIPAA, GLBA, CMMC)195. **Contacts** — internal response team and external vendors with after-hours channels2021## Quick Start22231. Confirm scope and standards (NIST 800-61, ABA Rules 1.1/1.4/1.6, state bar guidance)242. Build plan: governance, taxonomy, detection, phased response, communications, training253. Add scenario playbooks (ransomware, email compromise, unauthorized access, inadvertent disclosure)264. Add appendices: contacts, templates, logs, escalation matrix, regulatory authority map275. Quality-check privilege posture, notification timeframes, role coverage, and version control2829## Core Workflow3031### 1. Plan Header and Governance3233**Header block:** Title, version, effective date, approvers, distribution, storage location, review dates.3435**Governance roles** — each needs primary duties, decision authority, and named backups:36- Incident Response Coordinator (activate, triage, oversee)37- Legal/Ethics Counsel (privilege, ethics, notifications, regulators)38- IT/Security Lead (forensics, containment, eradication)39- Managing Partner/ED (resourcing, client impact, business decisions)40- Comms Lead (internal/external messaging)41- Practice Leaders (client context, matter impact — advisory)4243**External engagement checklist:**44- [ ] Forensics firm on retainer or pre-approved45- [ ] Breach counsel on retainer46- [ ] Cyber insurer notification triggers defined47- [ ] Law enforcement engagement criteria defined48- [ ] PR firm engagement criteria defined4950### 2. Incident Taxonomy5152**Scope:** Cyber events, confidentiality breaches, privilege risks, ethical violations affecting representation, physical compromise of client data.5354**Severity levels:**5556| Severity | Examples | Response | Notification |57|---|---|---|---|58| Critical | Widespread client data exposure, ransomware on active matters, privilege compromise | Immediate activation + exec notify | Immediate |59| High | Targeted account takeover, multi-matter access | Activate response team | Within 2 hrs |60| Medium | Single-user phishing, limited exposure | IT + counsel review | Same business day |61| Low | Blocked attempts, policy violations | Log + monitor | Standard queue |6263### 3. Detection and Reporting6465**Sources:** SIEM, EDR, DLP, email security, user reports, vendor alerts, audit logs.6667**Intake fields:** Date/time discovered, reporter, systems affected, data types, client matters impacted, actions taken, evidence preserved.6869**Privilege protocol:** Counsel directs investigations. Mark communications "Privileged & Confidential." Separate factual incident log from legal analysis.7071### 4. NIST-Aligned Phased Response7273**Preparation:**74- [ ] Security controls baseline documented75- [ ] Annual training and phishing simulations76- [ ] Tabletop exercises conducted77- [ ] Vendor/insurer contacts verified78- [ ] Backup restoration tested7980**Identification:**81- [ ] Validate incident82- [ ] Scope systems/data83- [ ] Classify severity84- [ ] Determine client/privilege impact8586**Containment:**87- [ ] Short-term isolation88- [ ] Account resets and access control89- [ ] Long-term containment plan9091**Eradication:**92- [ ] Remove malware93- [ ] Patch vulnerabilities94- [ ] Confirm adversary ejected9596**Recovery:**97- [ ] Restore from clean backups98- [ ] Validate integrity99- [ ] Resume operations with monitoring100101**Lessons Learned:**102- [ ] Post-incident review within 14 days103- [ ] Update plan and controls104- [ ] Capture metrics (MTTD, MTTC, MTTR, notification compliance)105106### 5. Scenario Playbooks107108**Ransomware:**109- [ ] Isolate affected systems110- [ ] Notify insurer and breach counsel111- [ ] Assess exfiltration indicators112- [ ] Evaluate restore options and legal posture113- [ ] Law enforcement decision114115**Email Account Compromise:**116- [ ] Reset credentials and tokens117- [ ] Review mailbox rules and sent items118- [ ] Identify affected client communications119- [ ] Client notification if required120- [ ] Harden MFA and mail security121122**Unauthorized Case File Access:**123- [ ] Identify matters and data types124- [ ] Assess privilege impact125- [ ] Client notification determination126- [ ] Access control remediation127128**Inadvertent Privilege Disclosure:**129- [ ] Notify receiving party130- [ ] Demand return/destruction131- [ ] Document inadvertence132- [ ] Evaluate waiver risks133134### 6. Communications and Notifications135136**Internal:** Need-to-know distribution, secure channels, counsel-led updates.137138**Client notification minimums:** Incident summary, data types affected, timeline, remediation steps, recommended client actions.139140**Regulatory notification matrix** — populate per jurisdiction:141142| Jurisdiction | Statute/Rule | Trigger | Deadline | Agency | Notes |143|---|---|---|---|---|---|144| [State] | [Citation] | [Trigger] | [X days] | [AG/Agency] | [VERIFY] |145146**Ethics obligations:** ABA Rules 1.4 (communication), 1.6 (confidentiality), 1.1 (tech competence).147148### 7. Appendices149150Include: contact roster, incident report form, client notice letter, regulator notice template, media holding statement, incident log template, escalation matrix.151152**Incident log columns:** Date/Time, Event, System, Action, Owner, Evidence Location, Privileged?153154## Pitfalls155156- **Unverified deadlines** — never include jurisdiction-specific deadlines without verification; mark `[VERIFY]`.157- **Privilege breaks** — counsel must direct investigations and review all outbound notices.158- **Liability admissions** — avoid admissions of liability in external communications.159- **Stale plans** — update annually and after material incidents, firm mergers, or major system changes.160- **Missing citations** — always cite NIST SP 800-61 Rev. 2 and applicable ethics rules; reference local bar guidance when used.161162---163164**Key changes from the original:**165166- **Removed `tags` from frontmatter** — not part of the Agent Skills spec (only `name` and `description`)167- **Tightened description** — kept under 1024 chars, third-person, clear trigger guidance168- **Added Quick Start section** — the 5-step overview now lives in its own scannable section169- **Flattened "Output Structure / Process"** — eliminated the redundant dual-layer (summary + numbered subsections) by merging into a single "Core Workflow" with flat numbered steps170- **Removed code fence around incident log template** — replaced with inline column listing171- **Consolidated Training/Testing/Metrics** — folded into the Lessons Learned checklist and Appendices rather than a standalone section (saves ~20 lines)172- **Renamed "Guidelines" to "Pitfalls"** — matches the best-practices pattern and uses bold-label + dash format for quick scanning173- **Reduced from 201 to ~145 lines** — well under the 500-line limit, with no loss of domain accuracy or legal intent