building-malware-incident-communication-template skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Build structured communication templates for malware incidents (ransomware, Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/building-malware-incident-communication-template/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-malware-incident-communication-template, or copy the skill folder into ~/.claude/skills/building-malware-incident-communication-template/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-malware-incident-communication-template/SKILL.md

SKILL.md (verbatim)

name: building-malware-incident-communication-template
description: Build structured communication templates for malware incidents (ransomware,
  wiper, trojan, worm), covering internal stakeholder notifications, executive briefings,
  technical advisories for IT teams, customer notifications, and regulatory disclosures,
  with severity-based escalation procedures. Use when drafting or standardizing incident
  communications and notification workflows for a malware outbreak.
domain: cybersecurity
subdomain: incident-response
tags:
- incident-communication
- malware-response
- stakeholder-notification
- crisis-communication
- executive-briefing
- regulatory-disclosure
mitre_attack:
- T1486
- T1490
- T1657
- T1041
- T1566
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01

Building Malware Incident Communication Template

Overview

Effective communication during malware incidents is critical for coordinated response, stakeholder management, and regulatory compliance. A structured communication framework ensures the right people receive appropriate information at the right time, preventing panic while maintaining transparency. Communication templates should cover internal escalation, executive briefings, technical advisories for IT teams, customer notifications, regulatory disclosures, and media statements. The framework must account for different malware types (ransomware, wiper, trojan, worm) and severity levels that drive escalation speed and audience.

When to Use

  • When deploying or configuring building malware incident communication template capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • Familiarity with incident response concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Communication Framework

Severity Classification

Severity Description Notification Timeline Audience
P1 - Critical Ransomware, wiper, or widespread infection affecting business operations Within 15 minutes CISO, CEO, Legal, Board (if applicable)
P2 - High Targeted malware on critical systems, data exfiltration suspected Within 1 hour CISO, IT Director, Legal
P3 - Medium Contained malware infection, limited spread Within 4 hours Security Manager, IT Director
P4 - Low Single endpoint infection, quickly contained Within 24 hours Security Team Lead

Communication Channels

Channel Use Case Security Level
Out-of-band phone calls Initial critical notifications Highest
Encrypted messaging (Signal) Real-time IR team coordination High
Secure email (encrypted) Formal notifications, documentation High
War room (physical/virtual) Ongoing incident coordination Medium
Incident ticketing system Status tracking and documentation Medium
Company intranet Broad employee communication Standard

Template 1: Initial Incident Notification (Internal)

SUBJECT: [SEVERITY] Malware Incident - Initial Notification - [DATE/TIME UTC]

CLASSIFICATION: CONFIDENTIAL - IR TEAM ONLY

INCIDENT ID: IR-[YEAR]-[NUMBER]
DETECTION TIME: [YYYY-MM-DD HH:MM UTC]
NOTIFICATION TIME: [YYYY-MM-DD HH:MM UTC]
SEVERITY: [P1/P2/P3/P4]

SUMMARY:
A malware incident has been detected affecting [NUMBER] systems in
[DEPARTMENT/LOCATION]. The malware has been identified as [TYPE] with
[KNOWN/UNKNOWN] characteristics.

CURRENT IMPACT:
- Systems affected: [COUNT and DESCRIPTION]
- Business functions impacted: [LIST]
- Data at risk: [DESCRIPTION]
- Current spread status: [CONTAINED/SPREADING/UNKNOWN]

IMMEDIATE ACTIONS TAKEN:
1. [ACTION - e.g., Affected endpoints isolated from network]
2. [ACTION - e.g., EDR containment policies activated]
3. [ACTION - e.g., Security team mobilized]

NEXT STEPS:
1. [PLANNED ACTION with TIMELINE]
2. [PLANNED ACTION with TIMELINE]

INCIDENT COMMANDER: [NAME]
CONTACT: [PHONE/ENCRYPTED CHANNEL]

NEXT UPDATE: [TIME] or sooner if situation changes

---
Do not forward this notification outside the IR team.

Template 2: Executive Briefing

SUBJECT: Executive Briefing - Malware Incident IR-[YEAR]-[NUMBER]

FOR: [CEO / CISO / CIO / Board]
FROM: [Incident Commander]
DATE: [DATE]
UPDATE: [#]

SITUATION SUMMARY:
[2-3 sentences describing the incident in business terms]

BUSINESS IMPACT:
- Revenue impact: [ESTIMATED/NONE/UNDER ASSESSMENT]
- Operational impact: [DESCRIPTION]
- Customer impact: [DESCRIPTION]
- Regulatory implications: [DESCRIPTION]

CURRENT STATUS: [DETECTED / CONTAINED / ERADICATING / RECOVERING]

KEY DECISIONS NEEDED:
1. [DECISION with context and recommendation]
2. [DECISION with context and recommendation]

TIMELINE:
- [TIME]: Incident detected
- [TIME]: Containment initiated
- [TIME]: [MILESTONE]
- [TIME]: Estimated recovery (if known)

EXTERNAL COMMUNICATION STATUS:
- Regulatory notification: [REQUIRED/SUBMITTED/NOT REQUIRED]
- Customer notification: [REQUIRED/PLANNED/NOT REQUIRED]
- Law enforcement: [ENGAGED/PLANNED/NOT APPLICABLE]

RESOURCE REQUIREMENTS:
- [RESOURCE NEED - e.g., External IR firm engagement]
- [RESOURCE NEED - e.g., Additional hardware for rebuild]

NEXT UPDATE: [TIME]

Template 3: Technical Advisory for IT Teams

SUBJECT: TECHNICAL ADVISORY - [MALWARE NAME] - Immediate Action Required

SEVERITY: [CRITICAL/HIGH/MEDIUM]
DATE: [DATE/TIME UTC]
ADVISORY ID: TA-[YEAR]-[NUMBER]

THREAT DESCRIPTION:
[Technical description of the malware, behavior, and indicators]

AFFECTED SYSTEMS:
- Operating Systems: [LIST]
- Applications: [LIST]
- Network segments: [LIST]

INDICATORS OF COMPROMISE (IOCs):
File Hashes:
  MD5: [HASH]
  SHA256: [HASH]

File Names:
  [FILENAME]

Network Indicators:
  C2 Domains: [DOMAIN]
  C2 IPs: [IP ADDRESS]
  User-Agent: [STRING]

Registry Keys:
  [REGISTRY PATH]

DETECTION METHODS:
- EDR: [DETECTION RULE/SIGNATURE]
- SIEM: [CORRELATION RULE]
- Network: [IDS/IPS SIGNATURE]

REQUIRED ACTIONS:
Priority 1 (Immediate):
  [ ] Block IOCs at firewall/proxy
  [ ] Push EDR containment rules
  [ ] Scan all endpoints for IOCs

Priority 2 (Within 4 hours):
  [ ] Apply patches [KB/CVE NUMBER]
  [ ] Update antivirus signatures
  [ ] Review logs for historical indicators

Priority 3 (Within 24 hours):
  [ ] Conduct enterprise-wide hunt
  [ ] Validate backup integrity
  [ ] Update detection rules

CONTACT: SOC - [PHONE] | Security Engineering - [PHONE]

Template 4: Regulatory Notification

[ORGANIZATION LETTERHEAD]

[REGULATORY BODY]
[ADDRESS]

Date: [DATE]

RE: Data Security Incident Notification - [REFERENCE NUMBER]

Dear [TITLE/NAME],

Pursuant to [REGULATION - e.g., GDPR Article 33, State Breach Notification Law],
[ORGANIZATION] is providing notification of a data security incident.

INCIDENT SUMMARY:
On [DATE], [ORGANIZATION] detected a malware incident affecting systems containing
[TYPE OF DATA]. The incident was detected through [DETECTION METHOD].

DATA POTENTIALLY AFFECTED:
- Types of data: [PERSONAL DATA, FINANCIAL, HEALTH, etc.]
- Number of individuals: [COUNT or ESTIMATE]
- Categories of individuals: [CUSTOMERS, EMPLOYEES, etc.]

TIMELINE:
- [DATE]: Incident occurred (estimated)
- [DATE]: Incident detected
- [DATE]: Containment achieved
- [DATE]: This notification

MEASURES TAKEN:
1. [CONTAINMENT ACTION]
2. [INVESTIGATION ACTION]
3. [REMEDIATION ACTION]

MEASURES TO MITIGATE ADVERSE EFFECTS:
1. [MITIGATION - e.g., Credit monitoring offered]
2. [MITIGATION - e.g., Password resets enforced]

CONTACT INFORMATION:
[DPO/PRIVACY OFFICER NAME]
[TITLE]
[EMAIL]
[PHONE]

Respectfully,
[SIGNATORY]
[TITLE]

Template 5: Customer/Public Notification

SUBJECT: Important Security Notice from [ORGANIZATION]

Dear [CUSTOMER/USER],

We are writing to inform you of a security incident that may have affected
your information.

WHAT HAPPENED:
On [DATE], we detected unauthorized activity on our systems involving
malicious software. We immediately activated our incident response procedures
and engaged leading cybersecurity experts to investigate.

WHAT INFORMATION WAS INVOLVED:
Based on our investigation, the following types of information may have
been affected: [LIST - e.g., names, email addresses, etc.]

WHAT WE ARE DOING:
- We have contained the incident and removed the malicious software
- We have engaged [FORENSIC FIRM] to conduct a thorough investigation
- We have enhanced our security controls to prevent similar incidents
- We have notified relevant regulatory authorities

WHAT YOU CAN DO:
- Change your password for your [ORGANIZATION] account
- Enable multi-factor authentication if not already active
- Monitor your accounts for unusual activity
- [Additional specific recommendations]

ADDITIONAL RESOURCES:
- [DEDICATED SUPPORT LINE]
- [FAQ PAGE URL]
- [CREDIT MONITORING ENROLLMENT - if applicable]

We sincerely apologize for any concern this may cause and remain committed
to protecting your information.

[SIGNATORY]
[TITLE]

Communication Workflow

Escalation Matrix

Malware Detected
  |
  v
[Classify Severity: P1/P2/P3/P4]
  |
  |-- P1: Notify within 15 min
  |     |-- Incident Commander
  |     |-- CISO (phone call)
  |     |-- CEO (phone call)
  |     |-- Legal Counsel
  |     |-- External IR firm
  |     |-- Law enforcement (if applicable)
  |
  |-- P2: Notify within 1 hour
  |     |-- CISO
  |     |-- IT Director
  |     |-- Legal Counsel
  |
  |-- P3: Notify within 4 hours
  |     |-- Security Manager
  |     |-- IT Director
  |
  |-- P4: Notify within 24 hours
        |-- Security Team Lead

References

  • NIST SP 800-61 Rev 2: Incident Communication Guidelines
  • GDPR Article 33: Data Breach Notification Requirements
  • SANS Incident Handler's Handbook: Communication Best Practices
  • CISA Incident Reporting Guidelines

Other files in this skill

assets/template.md (verbatim)

Malware Incident Communication Tracking Template

Case Information

Field Details
Case ID
Severity P1/P2/P3/P4
Malware Type
Communication Lead

Notification Tracker

Stakeholder Method Time Sent Acknowledged By Whom
CISO Phone
CEO Phone
Legal Email
IT Director Slack
Board Email

Update Log

Update # Time (UTC) Type Recipients Summary
1 Initial
2 Status

Regulatory Notifications

Regulation Required Deadline Sent Confirmed
GDPR (DPA) 72 hours
HIPAA (HHS) 60 days
State Breach Varies
SEC (8-K) 4 bus days

Customer Communication

  • Notification drafted
  • Legal review complete
  • Executive approval
  • Support resources ready
  • Notification sent
  • FAQ published

Media Handling

  • Holding statement prepared
  • Spokesperson designated
  • Media inquiry response approved
  • Social media monitoring active

Lessons Learned (Communication)

  • What worked well:
  • What needs improvement:
  • Template updates needed:

references/api-reference.md (verbatim)

API Reference: Malware Incident Communication Templates

Severity Levels

Level Response Time Escalation Update Frequency
Critical 15 minutes CISO + Legal + CEO 1 hour
High 1 hour CISO + SOC Manager 2 hours
Medium 4 hours SOC Manager 4 hours
Low 24 hours SOC Analyst Daily

Malware Categories

Type Impact Primary Containment
Ransomware Data encryption, ops disruption Isolate hosts, disable shares
Trojan Unauthorized access, exfiltration Block C2, isolate hosts
Wiper Data destruction Immediate isolation
Infostealer Credential/PII theft Block exfiltration channels
Worm Lateral spread Segment network

Incident Response Phases (NIST SP 800-61)

Phase Communication Focus
Detection Initial notification, severity classification
Containment Status updates, scope assessment
Eradication Technical progress, IOC sharing
Recovery Service restoration, monitoring
Post-Incident Lessons learned, executive summary

Regulatory Notification Deadlines

Regulation Deadline Authority
GDPR 72 hours Data Protection Authority
HIPAA 60 days HHS OCR
PCI DSS Immediate Card brands + acquirer
CCPA Without unreasonable delay CA Attorney General
NIS2 24h early warning + 72h full CSIRT

Communication Template Fields

Field Required Description
incident_id Yes Unique incident identifier
severity Yes critical/high/medium/low
subject Yes Email/notification subject line
timestamp Yes ISO 8601 format
affected_systems Yes List of impacted assets
actions_taken Yes Completed response actions
next_steps Yes Planned response actions

VERIS Framework Mapping

VERIS Field Maps To
action.malware.variety malware_type
attribute.integrity impact
timeline.incident detection timestamp
asset.assets affected_systems

references/standards.md (verbatim)

Standards for Incident Communication

NIST SP 800-61 Rev 2

  • Incident communication guidelines and templates
  • Stakeholder notification requirements
  • Media handling procedures

GDPR Article 33 and 34

  • 72-hour notification to supervisory authority
  • Communication to affected data subjects
  • Required content for breach notifications

HIPAA Breach Notification Rule

  • 60-day notification to HHS for breaches affecting 500+ individuals
  • Individual notification requirements
  • Media notification for large breaches

PCI DSS Incident Response

  • Card brand notification requirements
  • Forensic investigation reporting
  • Merchant and service provider obligations

SEC Cybersecurity Disclosure Rules (2024)

  • Material cybersecurity incident disclosure within 4 business days
  • Annual reporting on cybersecurity risk management
  • Board oversight disclosure requirements

CISA Incident Reporting

  • CIRCIA mandatory reporting requirements
  • Federal agency notification procedures
  • Voluntary reporting guidelines

ISO 27035 - Information Security Incident Management

  • Communication planning requirements
  • Stakeholder identification and notification
  • Post-incident communication review

references/workflows.md (verbatim)

Malware Incident Communication Workflows

Workflow 1: Initial Notification Chain

START: Malware Incident Confirmed
  |
  v
[Classify Severity]
  |-- P1: Critical (ransomware, wiper, widespread)
  |-- P2: High (targeted, data exfiltration)
  |-- P3: Medium (contained infection)
  |-- P4: Low (single endpoint, quickly resolved)
  |
  v
[Send Initial Notification]
  |-- Use appropriate template for severity
  |-- Send via secure out-of-band channel for P1/P2
  |-- Include: What happened, current impact, actions taken
  |
  v
[Establish Communication Cadence]
  |-- P1: Every 2 hours or on significant changes
  |-- P2: Every 4 hours
  |-- P3: Every 8 hours
  |-- P4: Daily summary
  |
  v
[Track Notifications Sent]
  |-- Log all communications
  |-- Record recipients and timestamps
  |-- Document approval chain
  |
  v
END: Communication Cadence Established

Workflow 2: Regulatory Notification Decision

START: Incident Scope Determined
  |
  v
[Personal Data Involved?]
  |-- No --> Document decision, continue monitoring
  |-- Yes --> Assess regulatory requirements
  |
  v
[Determine Applicable Regulations]
  |-- GDPR: EU resident data?
  |-- HIPAA: Protected health information?
  |-- PCI DSS: Payment card data?
  |-- State laws: US state breach notification?
  |-- SEC: Material to publicly traded company?
  |
  v
[Prepare Regulatory Notification]
  |-- Legal review of notification content
  |-- Determine notification timeline
  |-- Identify regulatory contact points
  |
  v
[Submit Notification]
  |-- Send within required timeframe
  |-- Document submission confirmation
  |-- Track response from regulators
  |
  v
END: Regulatory Obligations Met

Workflow 3: Customer Communication

START: Customer Notification Required
  |
  v
[Draft Customer Notification]
  |-- Use customer notification template
  |-- Include: What, when, impact, actions, resources
  |-- Avoid technical jargon
  |
  v
[Legal and PR Review]
  |-- Legal counsel approval
  |-- PR/Communications review
  |-- Executive sign-off
  |
  v
[Prepare Support Resources]
  |-- Set up dedicated hotline
  |-- Create FAQ page
  |-- Brief customer support team
  |-- Prepare credit monitoring (if applicable)
  |
  v
[Send Notification]
  |-- Email to affected customers
  |-- Website notice
  |-- Media statement (if needed)
  |
  v
END: Customer Notification Complete

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.