When it's real, the clock is already running. So are we.

The difference between a contained event and a reportable breach is measured in minutes. When something's wrong, you need a responder who already knows your environment and can move through containment, eradication and recovery without relearning your network from scratch, not a ticket dropped into a queue. Here's what you can hold us to.

Not mid-incident? See our incident response retainer ↓
Three numbers, put in writing SLA
A responder is already moving through the timeline
15 min
Triage Response & Acknowledgement
A responder is on the line, assessing scope.
1 hr
Active engagement
Containment underway, isolating what's affected and protecting what isn't.
4 hr
Full team mobilized
Investigation, recovery and evidence capture running in parallel.
Our SLA for active IR retainer clients
What is incident response?

What is incident response?

Incident response is the process an organization follows to detect, contain, investigate and recover from a cyber attack: ransomware, business email compromise, stolen admin credentials, an exposed server, or an employee who left with more than their coffee mug.

The goal is not just to remove the malware. A proper incident response engagement answers the four questions your executives, your insurer, your regulator and your biggest customer are all going to ask:

01What happened, and how did they get in?
02What did they touch, and did anything leave the building?
03Are they still inside?
04What stops this from happening again?

Answering those questions takes forensic evidence, and evidence is fragile. It is usually destroyed in the first hour by people doing what instinct tells them to do: reboot the server, wipe the laptop, restore from backup.

What incident response services usually include

Use this as a checklist when you compare providers.

CapabilityWhat it means in practice
Planning and readinessBuilding the response plan, defining who decides what, and rehearsing it.
Detection and triageConfirming an alert is a real incident, then sizing severity and business impact.
Containment and eradicationCutting off the attacker, then removing them completely.
Digital forensics (DFIR)Imaging, memory and log analysis, malware analysis, timeline building and attribution.
Notification supportThe factual findings your counsel needs to meet breach notification obligations. Investigative support, not legal advice.
Reporting and hardeningA defensible written record for your board, insurer and regulator, plus root cause and a fix list.
What's included

The incident response process, step by step

Every real incident response engagement runs through the same phases.

01Step 01

Preparation

Everything that happens before the phone rings: the response plan, agreed severity levels, named contacts, a way to communicate when your own email is compromised, and pre-approved access for responders. It is the phase most organizations skip, the cheapest one, and the one that sets the speed of everything after it.

02Step 02

Detection and triage

Something surfaces: an alert, a user report, a ransom note, a call from a customer. Triage confirms whether it is real, how far it reaches, and what severity it carries. Severity drives everything after it, including who gets woken up.

03Step 03

Containment

Stop the bleeding without destroying the evidence: isolate affected hosts, disable compromised accounts and cut off lateral movement. This is where instinct is most dangerous, because wiping a machine feels productive and can erase the only record of how they got in.

04Step 04

Investigation

Digital Forensics and Incident Response (DFIR) includes forensic imaging, memory and log analysis, malware analysis and timeline reconstruction. The output is a defensible answer on how they got in, how long they were there, and whether data was actually taken.

05Step 05

Eradication

Remove the foothold completely: malicious files, scheduled tasks, web shells, rogue accounts, mailbox forwarding rules and harvested credentials. Partial eradication is the most common reason organizations get hit twice by the same group.

06Step 06

Recovery

Restore systems in a controlled order, with monitoring in place to confirm the environment stays clean. That includes validating backups before you trust them, and deciding with evidence rather than hope when the incident is closed.

07Step 07

Review and hardening

The written report with root cause and timeline, a lessons-learned session, and a prioritized fix list. This is also the material your insurer, your auditor and your enterprise customers will ask to see.

Planning ahead

Not in an incident right now? Here's how to be ready for the next one.

Everything below is the incident response retainer: what it is, what it costs, and how it changes the first hour of a breach before it ever happens.

What is an incident response retainer?

What is an incident response retainer?

An incident response retainer is a pre-signed agreement with a specialist response team that guarantees you defined response times, agreed rates and an agreed scope of work, arranged before an incident rather than during one.

It is the difference between having a fire department and looking one up.

Without one, the first few hours of a breach go to paperwork instead of containment: finding a provider with capacity, negotiating a contract, routing it through legal and finance, cutting a purchase order. All while the attacker is still moving. With a retainer, everything slow is already done:

Already handledWhat that means at 2:00 a.m. on a Saturday
Contract and liability termsNo legal review. The engagement starts on the phone call.
RatesAgreed in advance at retainer pricing, not crisis pricing.
Escalation contacts on both sidesWe know who to call. You know who is calling.
Your environmentDocumented during onboarding, so no discovery phase burns your first four hours.
Access and authorizationPre-approved, so responders are working instead of waiting on credentials.

A retainer is not cyber insurance

They solve different problems and you want both. Insurance pays for the damage afterwards. A retainer reduces the damage while it is still happening. The two are increasingly linked: carriers now routinely ask at renewal whether you have a documented response plan and named responders.

Why an incident response retainer matters

Why an incident response retainer matters

01

We start the moment you know

You cannot control whether you get attacked. You can control what happens in the first hour. You call one number and we begin working the incident inside the window written into your contract. No proposal, no purchase order, no vendor review. And because we documented your environment during onboarding, we are investigating rather than learning your network.

02

Predictable cost instead of emergency pricing

Emergency, no-contract forensics is billed at crisis rates, and crisis rates are set by the party who knows you have no alternative. A retainer turns an unbudgeted event into a line item you approved in advance, at a rate you negotiated while you still had leverage. IBM puts the average cost of a data breach at USD $4.44 million globally (2025). A retainer is a rounding error against that.

03

You use the hours whether you are breached or not

Unused hours do not evaporate. They become response plan development, a cybersecurity assessment, a penetration test, tabletop exercises or playbook development. If you never have an incident, you still end the year better prepared. There is no version of this purchase where you get nothing.

04

It clears the paperwork that holds up renewals and deals

Your insurance renewal, your next audit and your biggest customer's security questionnaire all ask the same three questions: do you have a documented incident response plan, has it been tested, and do you have qualified responders available? A signed retainer with a tabletop report attached answers all three, with evidence.

05

Your people do not have to be heroes

Your IT director spends the worst week of their career coordinating rather than improvising, making decisions with expert input instead of reading forensics tutorials at three in the morning. That is the difference between a team that stays and a team that quits two months later.

The Cyberwall incident response retainer in practice

The Cyberwall incident response retainer in practice

Our retainer is built around one idea: almost everything that makes a response fast happens before the incident.

Before Onboarding in the first 30 days

A retainer that starts on the day of the incident is a phone number, not a service. Onboarding is what makes the response time real.

During What happens when you call

After What you are left holding

How the prepaid hours model works

How the prepaid hours model works

You buy a block of hours for a twelve-month term and spend them either way: proactively on planning, tabletops and assessments, or reactively when something happens. Incident hours draw down in two-hour increments at your retainer rate. Go past the block and the extra bills at your agreed discount, with no purchase order to wait for. Unused hours partly roll over.

Retainer tiers

EssentialAdvancedNotes
Prepaid IR hours408012-month term
24/7/365 hotlineIncludedIncludedLive responder
Acknowledgement, critical15 minutes15 minutesAny hour, any day
Investigator engaged, critical4 hours2 hoursWorking the incident
Billing increment2 hours2 hoursMinimum draw per call
Response planReviewDevelopment plus playbooksDrawn from hours
Compromise assessmentOptionalAnnualDrawn from hours
Overage rate discount12.5%20%Off standard rate
Unused hour rollover10%20%On renewal
Frequently asked questions

Frequently asked questions

What is an incident response retainer?

A pre-signed agreement with a specialist provider that guarantees defined response times, agreed rates and an agreed scope of work before an incident occurs. It removes the contracting and procurement delays that otherwise consume the first several hours of a breach.

What is included in incident response services?

Planning and readiness, detection and triage, containment, digital forensics, eradication and recovery, notification support, a written record of the investigation, and post-incident hardening. Under a retainer, the planning work is included rather than billed at the worst possible moment.

How much does an incident response retainer cost?

Cost depends on the size of the hour block, the response times you need and the complexity of your environment. Most organizations between 25 and 1,500 employees start with a 40 or 80 hour block on a twelve-month term.

Do I still need a retainer if I already have MDR or a managed SOC?

Yes. Detection and response services find and contain threats at the endpoint and network layer. A retainer covers what happens after: forensic investigation, evidence preservation, working out the real scope, notification support and executive reporting. Most breaches that matter need both.

What happens if my incident needs more hours than I purchased?

Work continues. Extra hours bill at your agreed retainer rate, discounted and written into your contract, not at emergency pricing. You are never left mid-incident waiting on a purchase order.

Do unused incident response hours expire?

Not in practice. Unused hours are meant to be spent proactively on plan development, tabletop exercises and assessments. A portion of anything still unused rolls into the next term when you renew.

How quickly will you respond?

A critical incident is acknowledged within 15 minutes, any hour of any day, and a qualified investigator is working the incident within two to four hours depending on your tier. Both commitments are written into your contract.

Will a retainer satisfy my cyber insurer or auditor?

It addresses the questions they ask most often: whether you have a documented response plan, whether it has been tested, and whether you have qualified responders available.

What do we need in place before signing?

Less than you think. You do not need a mature response program, since building one is what the proactive hours are for. What helps is a named contact, some log retention, and knowing who is empowered to take production offline.

Works with

Pairs naturally with these.

Already in an incident? Don't wait for the form.

Call us and a responder picks up. Not in one right now? Book a preparedness call so a containment plan already exists before you need it.

Under attack? · 24/7
1-888-471-5400

Call us and a responder picks up.