The difference between a contained event and a reportable breach is measured in minutes. When something's wrong, you need a responder who already knows your environment and can move through containment, eradication and recovery without relearning your network from scratch, not a ticket dropped into a queue. Here's what you can hold us to.
Not mid-incident? See our incident response retainer ↓Incident response is the process an organization follows to detect, contain, investigate and recover from a cyber attack: ransomware, business email compromise, stolen admin credentials, an exposed server, or an employee who left with more than their coffee mug.
The goal is not just to remove the malware. A proper incident response engagement answers the four questions your executives, your insurer, your regulator and your biggest customer are all going to ask:
Answering those questions takes forensic evidence, and evidence is fragile. It is usually destroyed in the first hour by people doing what instinct tells them to do: reboot the server, wipe the laptop, restore from backup.
Use this as a checklist when you compare providers.
| Capability | What it means in practice |
|---|---|
| Planning and readiness | Building the response plan, defining who decides what, and rehearsing it. |
| Detection and triage | Confirming an alert is a real incident, then sizing severity and business impact. |
| Containment and eradication | Cutting off the attacker, then removing them completely. |
| Digital forensics (DFIR) | Imaging, memory and log analysis, malware analysis, timeline building and attribution. |
| Notification support | The factual findings your counsel needs to meet breach notification obligations. Investigative support, not legal advice. |
| Reporting and hardening | A defensible written record for your board, insurer and regulator, plus root cause and a fix list. |
Every real incident response engagement runs through the same phases.
Everything that happens before the phone rings: the response plan, agreed severity levels, named contacts, a way to communicate when your own email is compromised, and pre-approved access for responders. It is the phase most organizations skip, the cheapest one, and the one that sets the speed of everything after it.
Something surfaces: an alert, a user report, a ransom note, a call from a customer. Triage confirms whether it is real, how far it reaches, and what severity it carries. Severity drives everything after it, including who gets woken up.
Stop the bleeding without destroying the evidence: isolate affected hosts, disable compromised accounts and cut off lateral movement. This is where instinct is most dangerous, because wiping a machine feels productive and can erase the only record of how they got in.
Digital Forensics and Incident Response (DFIR) includes forensic imaging, memory and log analysis, malware analysis and timeline reconstruction. The output is a defensible answer on how they got in, how long they were there, and whether data was actually taken.
Remove the foothold completely: malicious files, scheduled tasks, web shells, rogue accounts, mailbox forwarding rules and harvested credentials. Partial eradication is the most common reason organizations get hit twice by the same group.
Restore systems in a controlled order, with monitoring in place to confirm the environment stays clean. That includes validating backups before you trust them, and deciding with evidence rather than hope when the incident is closed.
The written report with root cause and timeline, a lessons-learned session, and a prioritized fix list. This is also the material your insurer, your auditor and your enterprise customers will ask to see.
Everything below is the incident response retainer: what it is, what it costs, and how it changes the first hour of a breach before it ever happens.
An incident response retainer is a pre-signed agreement with a specialist response team that guarantees you defined response times, agreed rates and an agreed scope of work, arranged before an incident rather than during one.
It is the difference between having a fire department and looking one up.
Without one, the first few hours of a breach go to paperwork instead of containment: finding a provider with capacity, negotiating a contract, routing it through legal and finance, cutting a purchase order. All while the attacker is still moving. With a retainer, everything slow is already done:
| Already handled | What that means at 2:00 a.m. on a Saturday |
|---|---|
| Contract and liability terms | No legal review. The engagement starts on the phone call. |
| Rates | Agreed in advance at retainer pricing, not crisis pricing. |
| Escalation contacts on both sides | We know who to call. You know who is calling. |
| Your environment | Documented during onboarding, so no discovery phase burns your first four hours. |
| Access and authorization | Pre-approved, so responders are working instead of waiting on credentials. |
They solve different problems and you want both. Insurance pays for the damage afterwards. A retainer reduces the damage while it is still happening. The two are increasingly linked: carriers now routinely ask at renewal whether you have a documented response plan and named responders.
You cannot control whether you get attacked. You can control what happens in the first hour. You call one number and we begin working the incident inside the window written into your contract. No proposal, no purchase order, no vendor review. And because we documented your environment during onboarding, we are investigating rather than learning your network.
Emergency, no-contract forensics is billed at crisis rates, and crisis rates are set by the party who knows you have no alternative. A retainer turns an unbudgeted event into a line item you approved in advance, at a rate you negotiated while you still had leverage. IBM puts the average cost of a data breach at USD $4.44 million globally (2025). A retainer is a rounding error against that.
Unused hours do not evaporate. They become response plan development, a cybersecurity assessment, a penetration test, tabletop exercises or playbook development. If you never have an incident, you still end the year better prepared. There is no version of this purchase where you get nothing.
Your insurance renewal, your next audit and your biggest customer's security questionnaire all ask the same three questions: do you have a documented incident response plan, has it been tested, and do you have qualified responders available? A signed retainer with a tabletop report attached answers all three, with evidence.
Your IT director spends the worst week of their career coordinating rather than improvising, making decisions with expert input instead of reading forensics tutorials at three in the morning. That is the difference between a team that stays and a team that quits two months later.
Our retainer is built around one idea: almost everything that makes a response fast happens before the incident.
A retainer that starts on the day of the incident is a phone number, not a service. Onboarding is what makes the response time real.
You buy a block of hours for a twelve-month term and spend them either way: proactively on planning, tabletops and assessments, or reactively when something happens. Incident hours draw down in two-hour increments at your retainer rate. Go past the block and the extra bills at your agreed discount, with no purchase order to wait for. Unused hours partly roll over.
| Essential | Advanced | Notes | |
|---|---|---|---|
| Prepaid IR hours | 40 | 80 | 12-month term |
| 24/7/365 hotline | Included | Included | Live responder |
| Acknowledgement, critical | 15 minutes | 15 minutes | Any hour, any day |
| Investigator engaged, critical | 4 hours | 2 hours | Working the incident |
| Billing increment | 2 hours | 2 hours | Minimum draw per call |
| Response plan | Review | Development plus playbooks | Drawn from hours |
| Compromise assessment | Optional | Annual | Drawn from hours |
| Overage rate discount | 12.5% | 20% | Off standard rate |
| Unused hour rollover | 10% | 20% | On renewal |
A pre-signed agreement with a specialist provider that guarantees defined response times, agreed rates and an agreed scope of work before an incident occurs. It removes the contracting and procurement delays that otherwise consume the first several hours of a breach.
Planning and readiness, detection and triage, containment, digital forensics, eradication and recovery, notification support, a written record of the investigation, and post-incident hardening. Under a retainer, the planning work is included rather than billed at the worst possible moment.
Cost depends on the size of the hour block, the response times you need and the complexity of your environment. Most organizations between 25 and 1,500 employees start with a 40 or 80 hour block on a twelve-month term.
Yes. Detection and response services find and contain threats at the endpoint and network layer. A retainer covers what happens after: forensic investigation, evidence preservation, working out the real scope, notification support and executive reporting. Most breaches that matter need both.
Work continues. Extra hours bill at your agreed retainer rate, discounted and written into your contract, not at emergency pricing. You are never left mid-incident waiting on a purchase order.
Not in practice. Unused hours are meant to be spent proactively on plan development, tabletop exercises and assessments. A portion of anything still unused rolls into the next term when you renew.
A critical incident is acknowledged within 15 minutes, any hour of any day, and a qualified investigator is working the incident within two to four hours depending on your tier. Both commitments are written into your contract.
It addresses the questions they ask most often: whether you have a documented response plan, whether it has been tested, and whether you have qualified responders available.
Less than you think. You do not need a mature response program, since building one is what the proactive hours are for. What helps is a named contact, some log retention, and knowing who is empowered to take production offline.
Call us and a responder picks up. Not in one right now? Book a preparedness call so a containment plan already exists before you need it.