MCP Server

incidentoracle

io.tooloracle/incidentoracle
Business & Operations Legal & Compliance Public & reachable MCP 2026-07-28

What this MCP does

Manages ICT incidents through DORA classification, incident logging, deadline tracking, regulatory notifications, interim reports, final reports, and reclassification.

classify_incident
Classify an incident against the 6 DORA criteria (RTS 2024/1772). Determines if MAJOR (triggers 4h/72h/1m reporting) or NON-MAJOR.
Input schema
{'type': 'object', 'required': ['incident_id'], 'properties': {'data_losses': {'type': 'boolean', 'description': 'Confidential/personal data affected?'}, 'incident_id': {'type': 'string'}, 'duration_hours': {'type': 'number'}, 'clients_affected': {'type': 'number', 'description': '% of clients affected'}, 'geographic_spread': {'type': 'integer', 'description': 'Number of EU member states'}, 'economic_impact_eur': {'type': 'number'}, 'criticality_of_services': {'type': 'boolean', 'description': 'Critical functions affected?'}}, 'additionalProperties': False}
cyber_threat_notify
Voluntary notification of a significant cyber threat (Art. 19(2)). Uses ITS 2025/302 Annex III template.
Input schema
{'type': 'object', 'required': ['title'], 'properties': {'iocs': {'type': 'string'}, 'ttps': {'type': 'string'}, 'title': {'type': 'string'}, 'source': {'type': 'string'}, 'mitigation': {'type': 'string'}, 'description': {'type': 'string'}, 'threat_type': {'type': 'string'}, 'affected_systems': {'type': 'string'}}, 'additionalProperties': False}
deadline_tracker
Track all active MAJOR incident reporting deadlines. Shows overdue and upcoming.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
final_report
Generate the 1-month final report with root cause analysis and lessons learned.
Input schema
{'type': 'object', 'required': ['incident_id'], 'properties': {'incident_id': {'type': 'string'}, 'resolved_at': {'type': 'string'}, 'total_cost_eur': {'type': 'number'}, 'lessons_learned': {'type': 'string'}, 'recovery_actions': {'type': 'string'}, 'root_cause_final': {'type': 'string'}, 'preventive_measures': {'type': 'string'}, 'client_communication': {'type': 'string'}}, 'additionalProperties': False}
health_check
Server status.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
incident_log
Full incident register with filters (status, classification, severity, search).
Input schema
{'type': 'object', 'properties': {'search': {'type': 'string'}, 'status': {'enum': ['detected', 'classified', 'notified', 'investigating', 'contained', 'resolved', 'closed'], 'type': 'string'}, 'severity': {'enum': ['critical', 'high', 'medium', 'low'], 'type': 'string'}, 'classification': {'enum': ['MAJOR', 'NON-MAJOR'], 'type': 'string'}}, 'additionalProperties': False}
incident_stats
Dashboard: total/open/major incidents, overdue deadlines, by severity/status.
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
initial_notification
Generate the 4h initial notification for a MAJOR incident (ITS 2025/302 Annex I). Must be submitted within 4h of classification, max 24h after detection.
Input schema
{'type': 'object', 'required': ['incident_id'], 'properties': {'authority': {'type': 'string', 'description': 'Competent authority (e.g., BaFin, FMA)'}, 'entity_lei': {'type': 'string'}, 'entity_name': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'affected_states': {'type': 'string', 'description': 'Comma-separated EU member states'}, 'discovery_method': {'enum': ['internal_monitoring', 'user_report', 'third_party', 'regulator', 'other'], 'type': 'string'}}, 'additionalProperties': False}
intermediate_report
Generate the 72h intermediate report for a MAJOR incident (ITS 2025/302). Must include action plan if incident is not yet resolved.
Input schema
{'type': 'object', 'required': ['incident_id'], 'properties': {'root_cause': {'type': 'string'}, 'action_plan': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'recovery_status': {'type': 'string'}, 'description_update': {'type': 'string'}, 'containment_actions': {'type': 'string'}, 'expected_resolution': {'type': 'string'}}, 'additionalProperties': False}
log_incident
Log a new ICT-related incident. First step in the DORA incident management process (Art. 17).
Input schema
{'type': 'object', 'required': ['title'], 'properties': {'team': {'type': 'string'}, 'notes': {'type': 'string'}, 'owner': {'type': 'string'}, 'title': {'type': 'string'}, 'severity': {'enum': ['critical', 'high', 'medium', 'low'], 'type': 'string'}, 'data_losses': {'type': 'boolean'}, 'description': {'type': 'string'}, 'detected_at': {'type': 'string', 'description': 'ISO datetime of detection'}, 'incident_id': {'type': 'string'}, 'bcm_activated': {'type': 'boolean'}, 'duration_hours': {'type': 'number'}, 'affected_systems': {'type': 'string'}, 'clients_affected': {'type': 'number', 'description': 'Percentage of clients affected'}, 'affected_services': {'type': 'string'}, 'geographic_spread': {'type': 'integer'}, 'economic_impact_eur': {'type': 'number'}, 'criticality_of_services': {'type': 'boolean'}}, 'additionalProperties': False}
major_incident_check
Quick check: would these criteria values classify as a MAJOR incident? No incident record needed — use for pre-assessment.
Input schema
{'type': 'object', 'properties': {'data_losses': {'type': 'boolean'}, 'duration_hours': {'type': 'number'}, 'clients_affected': {'type': 'number'}, 'geographic_spread': {'type': 'integer'}, 'economic_impact_eur': {'type': 'number'}, 'criticality_of_services': {'type': 'boolean'}}, 'additionalProperties': False}
reclassify
Reclassify an incident (MAJOR to NON-MAJOR or vice versa). Competent authority must be notified of reclassification.
Input schema
{'type': 'object', 'required': ['incident_id', 'new_classification'], 'properties': {'reason': {'type': 'string'}, 'incident_id': {'type': 'string'}, 'new_classification': {'enum': ['MAJOR', 'NON-MAJOR'], 'type': 'string'}}, 'additionalProperties': False}
Added
health_check
Sept. 17, 2026, 12:53 p.m.
Added
incident_log
Sept. 17, 2026, 12:53 p.m.
Added
cyber_threat_notify
Sept. 17, 2026, 12:53 p.m.
Added
incident_stats
Sept. 17, 2026, 12:53 p.m.
Added
reclassify
Sept. 17, 2026, 12:53 p.m.
Added
deadline_tracker
Sept. 17, 2026, 12:53 p.m.
Added
final_report
Sept. 17, 2026, 12:53 p.m.
Added
intermediate_report
Sept. 17, 2026, 12:53 p.m.
Added
initial_notification
Sept. 17, 2026, 12:53 p.m.
Added
major_incident_check
Sept. 17, 2026, 12:53 p.m.
Added
classify_incident
Sept. 17, 2026, 12:53 p.m.
Added
log_incident
Sept. 17, 2026, 12:53 p.m.