Agent skill

Breach Simulation

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities.

Apache-2.0Auto-check passedDevOps & Cloud

Install Breach Simulation

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-simulation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-simulation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-simulation .claude/skills/breach-simulation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-simulation
GitHub stars
295
Token cost
~2.9k tokens
SKILL.md length
1,307 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities.

  • Works in 10 steps: Breach awareness determination: When… → Containment vs. evidence preservation:… → Notification timing: Was the 72-hour… → …
  • Tasks that involve Retrospectives
  • SKILL.md covers Overview, Exercise Design Framework, Scenario Design and Participant Roles, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Breach Simulation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in DevOps & Cloud, covering Retrospectives, Security operations and Incident response. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Retrospectives
  • Tasks that involve Security operations
  • Tasks that involve Incident response

Example prompts

  • “Use the breach-simulation skill to design and executes tabletop breach simulation exercises for testing organizational breach response capabilities”
  • “/breach-simulation”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the first numbered list in SKILL.md.

  1. Breach awareness determination: When exactly did the controller "become aware" for Art. 33 clock purposes?
  2. Containment vs. evidence preservation: Did the team balance immediate containment with the need to preserve forensic evidence?
  3. Notification timing: Was the 72-hour deadline tracked and met?
  4. Risk assessment quality: Was the risk assessment methodology applied consistently and documented?
  5. Communication coordination: Were media, customer, and internal communications coordinated and consistent?
  6. Escalation effectiveness: Were the right people involved at the right time?
  7. Cross-functional coordination: Did legal, privacy, IT, and communications work together effectively?
  8. Regulatory coordination: Was the correct supervisory authority identified and notification prepared?
  9. Data subject communication: Was Art. 34 notification considered at the appropriate threshold?
  10. Documentation: Was the decision-making process documented in real-time?

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Simulation loads about 2.9k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 1,307 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,307 words, ~2,895 tokens.

Download SKILL.mdSave it as .claude/skills/breach-simulation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
breach-simulation
description
Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Covers scenario creation with realistic inject timelines, participant role assignment, communication testing across internal and external channels, decision-point evaluation, and after-action report generation. Keywords: tabletop exercise, breach simulation, incident response testing, scenario design, after-action report.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
tabletop-exercise, breach-simulation, incident-response, scenario-design, after-action

Designing Breach Simulation Exercise

Overview

Breach simulation exercises (tabletop exercises) test an organization's ability to detect, respond to, and recover from a personal data breach without the consequences of an actual incident. A well-designed exercise validates the breach response plan, identifies gaps in procedures, communication, and decision-making, and builds institutional muscle memory. This skill covers the end-to-end design process from scenario creation through after-action reporting.

Exercise Design Framework

Exercise Types
TypeDurationParticipantsComplexityPurpose
Tabletop (discussion-based)2-4 hours8-15 senior stakeholdersMediumTest decision-making, communication, and policy application
Functional exercise4-8 hours15-30 cross-functional team membersHighTest operational procedures and tool usage
Full-scale simulation1-3 daysOrganization-wide (50+ participants)Very highTest end-to-end response including technical, legal, communications, and executive functions
Exercise TypeFrequencyAudience
TabletopSemi-annuallyExecutive team, DPO, legal, communications, CISO
FunctionalAnnuallySOC, privacy team, IT operations, HR, customer service
Full-scaleEvery 2 yearsOrganization-wide

Scenario Design

Scenario 1: Ransomware Attack on Customer Database

Complexity: High Duration: 3 hours Primary objectives: Test Art. 33 72-hour notification decision-making, executive communication, and vendor coordination.

Background briefing (distributed 24 hours before exercise): Stellar Payments Group processes payment transactions for 15,230 account holders across 18 EU member states and 12 US states. The production customer database is hosted on a PostgreSQL cluster in AWS eu-west-1. The DPO is Dr. Elena Vasquez. The CISO is Thomas Brenner. Mandiant is the retained incident response firm.

Inject timeline:

TimeInjectExpected Action
T+0 minSOC alert: CrowdStrike detects rapid file encryption on db-prod-eu-west-01. 500+ file renames per second. Known ransomware indicators (LockBit 3.0).SOC initiates incident response. Incident Commander activated.
T+15 minUpdate: Encryption spreading to db-prod-eu-west-02 and 03. Customer portal returning database errors. Customer complaints arriving via support channels.Decision point: Isolate database cluster? Accept service disruption vs. further damage?
T+30 minForensic initial finding: Attack vector appears to be compromised service account (svc-migration-2024). Account authenticated from Tor exit node 3 days prior.Update risk assessment. Determine scope of potentially compromised data.
T+60 minCustomer database confirmed encrypted. 48,720 records across 15,230 data subjects. Backup from 12 hours ago available and verified clean.Decision point: Restore from backup? Art. 33 notification clock — when did we "become aware"?
T+90 minRansom note found: 50 BTC demanded. Threat to publish data on dark web if not paid within 48 hours. Media outlet (Handelsblatt) calls communications team for comment.Decision points: Pay ransom? Engage law enforcement? Media statement?
T+120 minMandiant confirms no evidence of exfiltration but cannot rule it out. Backup restoration is 60% complete. Berliner BfDI opens office in 2 hours.Decision point: File Art. 33 notification now or wait for more information? Prepare Art. 34 data subject notification?
T+150 minSecond media outlet (Bloomberg) publishes story. Social media discussion begins. 50+ customer support calls in past hour. Three enterprise clients demand written assurance.Communications crisis management. Customer and B2B stakeholder communication.
T+180 minExercise conclusion. Facilitator reveals exercise end state and leads debrief discussion.After-action discussion.
Scenario 2: Insider Threat — Employee Data Exfiltration

Complexity: Medium Duration: 2.5 hours

Inject timeline:

TimeInjectExpected Action
T+0 minDLP alert: HR database export (3,400 employee records) copied to personal OneDrive by departing employee (last day is Friday).Validate alert. Determine whether personal data is involved.
T+20 minRecords include names, home addresses, salaries, bank details, and national ID numbers. Employee's manager confirms the employee submitted resignation 2 weeks ago.Decision point: Confront employee? Preserve evidence? Involve legal?
T+45 minIT confirms the file was synced to the employee's personal laptop. The employee is currently in the office.Decision points: Device seizure? HR involvement? Works Council (Betriebsrat) notification?
T+75 minLegal advises on employee rights under German labor law. Works Council representative requests consultation before any confrontation.Balance breach response urgency against employee rights and Works Council obligations.
T+105 minEmployee is interviewed with Works Council representative present. Claims data was for "reference purposes." Refuses to allow personal laptop examination.Decision point: Law enforcement referral? Court order for device examination? Art. 33 notification?
T+135 minDPO completes risk assessment: 3,400 employees, government IDs + financial data = high risk. Art. 33 and Art. 34 notification recommended.Notification preparation. Employee communication planning (how to tell 3,400 employees their data was compromised by a colleague).
T+150 minExercise conclusion and debrief.After-action discussion.
Show full SKILL.md (589 more words)Show less
Scenario 3: Third-Party Processor Breach

Complexity: Medium Duration: 2 hours

Inject timeline:

TimeInjectExpected Action
T+0 minEmail from cloud payroll processor (PayrollCloud GmbH): "We are writing to inform you of a security incident affecting customer data hosted on our platform." No details provided.Contact processor for details. Review Art. 28 DPA for incident notification obligations.
T+20 minProcessor confirms: SQL injection attack. Unclear which clients affected. Estimated timeline for client-specific impact assessment: 5-7 days.Decision point: Can we wait 5-7 days? How does this affect our 72-hour clock?
T+45 minProcessor provides partial information: "Your organization's data was on the affected server, but we cannot confirm whether it was accessed." 3,400 employee payroll records potentially exposed.Assess when the controller "became aware" for Art. 33 purposes. Begin parallel risk assessment.
T+75 minMedia reports the processor breach. Several of the processor's other clients have publicly acknowledged being affected.Decision point: Proactive disclosure? Wait for confirmed impact?
T+105 minProcessor confirms: Stellar Payments Group data was accessed. 3,400 employee records including names, salaries, bank account numbers, and tax IDs.Art. 33 notification preparation. Employee communication planning. Processor accountability assessment.
T+120 minExercise conclusion and debrief.After-action discussion.

Participant Roles

RoleParticipantResponsibilities During Exercise
Incident CommanderCISO (Thomas Brenner)Overall incident coordination, resource allocation, containment decisions
Privacy LeadDPO (Dr. Elena Vasquez)Notification decisions, risk assessment, data subject communication
Legal CounselGeneral Counsel (Sarah Chen)Legal advice, privilege management, law enforcement coordination, regulatory strategy
Communications LeadCommunications Director (Martin Keller)Media response, customer communication, internal communication
IT OperationsIT Director (Petra Hoffmann)Technical containment, backup restoration, system recovery
Executive SponsorCEO (Marcus Lindqvist)Strategic decisions, board notification, public statements
Customer RelationsVP Customer Success (James Park)Customer communication, B2B client management
HR LeadCHRO (Claudia Richter)Employee communication, Works Council coordination (insider threat scenarios)
Exercise FacilitatorExternal consultant or internal auditScenario delivery, inject timing, discussion facilitation, observation
Observer/RecorderDPO office analystDocument decisions, actions, timelines, and gaps for after-action report

Decision Points to Evaluate

  1. Breach awareness determination: When exactly did the controller "become aware" for Art. 33 clock purposes?
  2. Containment vs. evidence preservation: Did the team balance immediate containment with the need to preserve forensic evidence?
  3. Notification timing: Was the 72-hour deadline tracked and met?
  4. Risk assessment quality: Was the risk assessment methodology applied consistently and documented?
  5. Communication coordination: Were media, customer, and internal communications coordinated and consistent?
  6. Escalation effectiveness: Were the right people involved at the right time?
  7. Cross-functional coordination: Did legal, privacy, IT, and communications work together effectively?
  8. Regulatory coordination: Was the correct supervisory authority identified and notification prepared?
  9. Data subject communication: Was Art. 34 notification considered at the appropriate threshold?
  10. Documentation: Was the decision-making process documented in real-time?

After-Action Report Structure

Section 1: Exercise Summary
  • Exercise date, duration, scenario, and participants.
  • Exercise objectives and whether they were met.
Section 2: Timeline Analysis
  • Actual timeline of decisions and actions during the exercise.
  • Comparison against expected/ideal timeline from the breach response plan.
  • Identification of delays and bottlenecks.
Section 3: Findings
  • What worked well (strengths to maintain).
  • What needs improvement (gaps and deficiencies).
  • Severity rating for each finding: Critical, Major, Minor, Observation.
Section 4: Recommendations
  • Specific, actionable remediation recommendations with owners and deadlines.
  • Prioritized by severity.
Section 5: Metrics
  • Time from detection to containment decision.
  • Time from awareness to DPO notification.
  • Time from awareness to notification preparation completion.
  • Communication consistency score (number of conflicting messages identified).
  • Decision quality score (percentage of decisions aligned with policy and regulation).

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-simulation of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Breach Simulation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Simulation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Simulation this skillmukul975/Privacy-Data-Protection-Skills295—~2.9kAutomated safety check: PassApache-2.0
Detecting Network Anomalies With Zeekmukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: NotesApache-2.0
Soc Operationsbriiirussell/cybersecurity-skills413—~2.9kAutomated safety check: PassMIT
Incident ResponseBagelHole/DevOps-Security-Agent-Skills1.1k—~4.5kAutomated safety check: PassMIT
Msp MaintenanceRTFM-IT-Services-LLC/msp-claude-skills113—~2.6kAutomated safety check: PassCustom licence
Implementing Soar Playbook With Palo Alto Xsoarmukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Detecting Network Anomalies With Zeek

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy and configure Zeek (formerly Bro) to passively analyze network traffic, generate structured connection/DNS/HTTP/SSL/file logs, detect anomalous behavior, and write custom scripts for…

    34k GitHub stars~3.6k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Soc Operations

    briiirussell/cybersecurity-skills

    Build, run, and improve a Security Operations Center — alert prioritization, runbook authoring, escalation criteria, on-call structure, alert tuning workflow, MTTD / MTTR / fidelity KPIs, analyst…

    413 GitHub stars~2.9k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~4.5k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Msp Maintenance

    RTFM-IT-Services-LLC/msp-claude-skills

    A skill your agent uses for your MSP's proactive, recurring operations: patching and update cycles, maintenance windows, backup monitoring and test restores, monitoring and alert triage, the on-call…

    113 GitHub stars~2.6k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Implementing Soar Playbook With Palo Alto Xsoar

    mukul975/Anthropic-Cybersecurity-Skills

    Build automated incident response playbooks in Cortex XSOAR (Demisto) using its YAML playbook structure, integration commands, and task types to orchestrate phishing, malware, account-compromise…

    34k GitHub stars~2.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Incident Response

    sickn33/agentic-awesome-skills

    Handle security incidents with IR playbooks and procedures. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 1 repo~3.7k tokens
    DevOps & CloudAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Breach Simulation

What does Breach Simulation do?

Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities. Breach Simulation is an agent skill from mukul975/Privacy-Data-Protection-Skills. Designs and executes tabletop breach simulation exercises for testing organizational breach response capabilities.

When should I use Breach Simulation?

Breach Simulation fits situations like: tasks that involve Retrospectives; tasks that involve Security operations; tasks that involve Incident response.

How do I install Breach Simulation in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-simulation -a claude-code`. Or copy the skill folder (skills/privacy/breach-simulation in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-simulation in your project. Claude Code loads it when a task matches its description.

How do I install Breach Simulation in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-simulation -a codex`. Or copy the skill folder (skills/privacy/breach-simulation in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-simulation in your project. Codex loads it when a task matches its description.

Can I use Breach Simulation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-simulation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-simulation, .gemini/skills/breach-simulation, .github/skills/breach-simulation and .opencode/skills/breach-simulation in your project.

What does Breach Simulation need to run?

Going by SKILL.md and its folder, Breach Simulation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Breach Simulation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Simulation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Breach Simulation use?

Breach Simulation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Simulation use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Breach Simulation?

Skills that share tags, products or a category with Breach Simulation: Detecting Network Anomalies With Zeek (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Soc Operations (briiirussell/cybersecurity-skills, 413 stars), Incident Response (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars) and Msp Maintenance (RTFM-IT-Services-LLC/msp-claude-skills, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Simulation?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.